Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4238 EXPLOITDB text VERIFIED
Mantis <= 1.0.0rc3 - Cross-Site Scripting via view_filters_page.php target_field Parameter
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.
by r0t
CVE-2005-4234 EXPLOITDB text VERIFIED
EncapsGallery < 1.0.0 - SQL Injection via Gallery ID Parameter
SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by r0t3d3Vil
CVE-2005-4229 EXPLOITDB text VERIFIED
EveryAuction <= 1.53 - Cross-Site Scripting via Search String Parameter
Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction 1.53 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources and independently verified using source code inspection.
by $um$id
CVE-2005-4202 EXPLOITDB text VERIFIED
LogiSphere 0.9.9j - Directory Traversal via URL and Parameter Manipulation
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (triple dot), and (3) "..//" sequences in the URL, (4) "../" sequences in the source parameter to viewsource.jsp, or (5) "..\" (dot dot backslash) sequences in the NS-query-pat parameter to the search URL. URL.
by dr_insane
CVE-2005-4202 EXPLOITDB text VERIFIED
LogiSphere 0.9.9j - Directory Traversal via URL and Parameter Manipulation
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (triple dot), and (3) "..//" sequences in the URL, (4) "../" sequences in the source parameter to viewsource.jsp, or (5) "..\" (dot dot backslash) sequences in the NS-query-pat parameter to the search URL. URL.
by dr_insane
CVE-2005-4202 EXPLOITDB text VERIFIED
LogiSphere 0.9.9j - Directory Traversal via URL and Parameter Manipulation
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (triple dot), and (3) "..//" sequences in the URL, (4) "../" sequences in the source parameter to viewsource.jsp, or (5) "..\" (dot dot backslash) sequences in the NS-query-pat parameter to the search URL. URL.
by dr_insane
CVE-2005-4194 EXPLOITDB text VERIFIED
Sights 'n Sounds Streaming Media Server < 2.0.3.a - Denial of Service via Long Query String
Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (application crash) via a long query string.
by dr_insane
CVE-2005-4209 EXPLOITDB text VERIFIED
WorldClient webmail in Alt-N MDaemon 8.1.3 - Denial of Service via Subject Header Script Injection
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.
by dr_insane
CVE-2005-4195 EXPLOITDB text VERIFIED
Scout Portal Toolkit <= 1.3.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.php, (2) ResourceId parameter in SPT--FullRecord.php, (3) ResourceOffset parameter in SPT--Home.php, and (4) F_UserName and (5) F_Password in SPT--UserLogin.php. NOTE: it was later reported that vector 1 is also present in 1.4.0.
by Preddy
CVE-2005-4196 EXPLOITDB text VERIFIED
Scout Portal Toolkit < 1.3.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php; (4) ResourceOffset parameter in SPT--Home.php, (5) F_SearchString parameter in SPT--QuickSearch.php; (6) F_UserName and (7) F_Password parameters in SPT--UserLogin.php; (8) F_SearchCat1, (9) F_TextField1, (10) F_SearchCat2, (11) F_TextField2, (12) F_SearchCat3, (13) F_TextField3, (14) F_SearchCat4, (15) F_TextField4, (16) ResourceType, (17) Language, (18) Audience, (19) Format parameters in SPT--AdvancedSearch.php.
by Preddy
CVE-2005-4196 EXPLOITDB text VERIFIED
Scout Portal Toolkit < 1.3.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php; (4) ResourceOffset parameter in SPT--Home.php, (5) F_SearchString parameter in SPT--QuickSearch.php; (6) F_UserName and (7) F_Password parameters in SPT--UserLogin.php; (8) F_SearchCat1, (9) F_TextField1, (10) F_SearchCat2, (11) F_TextField2, (12) F_SearchCat3, (13) F_TextField3, (14) F_SearchCat4, (15) F_TextField4, (16) ResourceType, (17) Language, (18) Audience, (19) Format parameters in SPT--AdvancedSearch.php.
by Preddy
CVE-2005-4196 EXPLOITDB text VERIFIED
Scout Portal Toolkit < 1.3.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php; (4) ResourceOffset parameter in SPT--Home.php, (5) F_SearchString parameter in SPT--QuickSearch.php; (6) F_UserName and (7) F_Password parameters in SPT--UserLogin.php; (8) F_SearchCat1, (9) F_TextField1, (10) F_SearchCat2, (11) F_TextField2, (12) F_SearchCat3, (13) F_TextField3, (14) F_SearchCat4, (15) F_TextField4, (16) ResourceType, (17) Language, (18) Audience, (19) Format parameters in SPT--AdvancedSearch.php.
by Preddy
CVE-2005-4207 EXPLOITDB text VERIFIED
BTGrup Admin WebController Script - SQL Injection via Username and Password Fields
SQL injection vulnerability in BTGrup Admin WebController Script allows remote attackers to execute SQL commands via the (1) Username and (2) Password fields.
by khc@bsdmail.org
CVE-2005-4221 EXPLOITDB text VERIFIED
Arab Portal System 2 Beta 2 - SQL Injection via PHPSESSID or REQUEST_URI
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).
by stranger-killer
CVE-2005-4206 EXPLOITDB MEDIUM text VERIFIED
Blackboard Academic Suite < 6.0.0.0 - URL Redirection via frameset.jsp url Parameter
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.
by dr_insane
CVSS 6.1
CVE-2005-4177 EXPLOITDB text VERIFIED
Magic Book Personal and Professional 2.0 - Cross-Site Scripting via StartRow Parameter
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter.
by r0t
CVE-2005-4205 EXPLOITDB text VERIFIED
locazolist_classifieds < 1.03c - Cross-Site Scripting via searchdb.asp q Parameter
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
by r0t3d3Vil
CVE-2005-4131 EXPLOITDB text VERIFIED
Microsoft Excel 2000, 2002, and 2003 - Remote Code Execution via Malformed Range
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
by fearwall
CVE-2005-4161 EXPLOITDB text VERIFIED
milliscripts 1.4 - Cross-Site Scripting via Domainname Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML via the domainname parameter to register.php, and other unspecified vectors. NOTE: the vendor has disputed this issue, stating "No invalid input can reach the script.
by Security Nation
CVE-2005-4197 EXPLOITDB text VERIFIED
Nortel SSL VPN 4.2.1.6 - Command Injection
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
by Daniel Fabian
EIP-2026-100713 EXPLOITDB text VERIFIED
ACME Perl-Cal 2.99 - Cal_make.pl Cross-Site Scripting
by $um$id
CVE-2005-4073 EXPLOITDB text VERIFIED
CFMagic Magic List Pro < 2.5 - SQL Injection via ListID Parameter
SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.
by r0t
CVE-2005-4071 EXPLOITDB text VERIFIED
CFMagic Magic Forum Personal < 2.5 - SQL Injection via ForumID or ThreadID Parameter
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.
by r0t
CVE-2005-4071 EXPLOITDB text VERIFIED
CFMagic Magic Forum Personal < 2.5 - SQL Injection via ForumID or ThreadID Parameter
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.
by r0t
CVE-2005-4074 EXPLOITDB text VERIFIED
CF_Nuke <= 4.6 - Directory Traversal via Sector or Page Parameter
Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. (dot dot) in the (1) sector or (2) page parameters.
by r0t