Exploitdb Exploits
31,394 exploits tracked across all sources.
cf_nuke < 4.6 - Cross-Site Scripting via Topic, Newsid, or Cat Parameter
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.
by r0t
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
DRZES HMS 3.2 - Cross-Site Scripting via login.php customerEmailAddress Parameter
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
by Vipsta
Check Point VPN-1 SecureClient NG - Security Policy Bypass via Local Policy File Modification
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.
by Viktor Steinmann
ASPMForum - SQL Injection via harf or baslik Parameter
Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.
by dj_eyes2005
ASPMForum - SQL Injection via harf or baslik Parameter
Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.
by dj_eyes2005
PluggedOut Blog <= 1.9.5 - SQL Injection via index.php Parameters
SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.
by r0t
DoceboLms 2.0.x - 'connector.php' Directory Traversal
by rgod
Cars Portal < 1.1 - SQL Injection via Page or Car Parameter
SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.
by r0t
rwAuction Pro 4.0 and 5.0 - Cross-Site Scripting via searchtxt Parameter
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.
by r0t
netauctionhelp < 3.0 - Cross-Site Scripting via search.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.
by r0t
IISWorks ASPKnowledgeBase 2.0 - Cross-Site Scripting via kb.asp a Parameter
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.
by r0t
DUWare DUportal Pro 3.4.3 - Cross-Site Scripting via password.asp result Parameter
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
by Dj_Eyes
A-FAQ 1.0 - SQL Injection via faqid or catcode Parameter
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
by r0t
A-FAQ 1.0 - SQL Injection via faqid or catcode Parameter
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
by r0t
Web4Future Portal Solutions - 'Comentarii.php' SQL Injection
by r0t
Web4Future Portal Solutions News Portal - Directory Traversal via arhiva.php dir Parameter
Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.
by r0t
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
Web4Future eCommerce Enterprise Edition <2.1 - SQL Injection
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
by r0t3d3Vil
By Source