Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4075 EXPLOITDB text VERIFIED
cf_nuke < 4.6 - Cross-Site Scripting via Topic, Newsid, or Cat Parameter
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.
by r0t
CVE-2005-4139 EXPLOITDB text VERIFIED
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
CVE-2005-4139 EXPLOITDB text VERIFIED
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
CVE-2005-4139 EXPLOITDB text VERIFIED
ThWboard < 3 Beta 2.84 - SQL Injection via Calendar Year Parameter
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.
by trueend5
CVE-2005-4136 EXPLOITDB text VERIFIED
DRZES HMS 3.2 - Cross-Site Scripting via login.php customerEmailAddress Parameter
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
by Vipsta
CVE-2005-4093 EXPLOITDB text VERIFIED
Check Point VPN-1 SecureClient NG - Security Policy Bypass via Local Policy File Modification
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.
by Viktor Steinmann
EIP-2026-100784 EXPLOITDB text VERIFIED
Dell TrueMobile 2300 - Remote Credential Reset
by TNull
CVE-2005-4141 EXPLOITDB text VERIFIED
ASPMForum - SQL Injection via harf or baslik Parameter
Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.
by dj_eyes2005
CVE-2005-4141 EXPLOITDB text VERIFIED
ASPMForum - SQL Injection via harf or baslik Parameter
Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.
by dj_eyes2005
CVE-2005-4054 EXPLOITDB text VERIFIED
PluggedOut Blog <= 1.9.5 - SQL Injection via index.php Parameters
SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.
by r0t
EIP-2026-106487 EXPLOITDB text VERIFIED
DoceboLms 2.0.x - 'connector.php' Directory Traversal
by rgod
CVE-2005-4055 EXPLOITDB text VERIFIED
Cars Portal < 1.1 - SQL Injection via Page or Car Parameter
SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.
by r0t
CVE-2005-4060 EXPLOITDB text VERIFIED
rwAuction Pro 4.0 and 5.0 - Cross-Site Scripting via searchtxt Parameter
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.
by r0t
CVE-2005-4063 EXPLOITDB text VERIFIED
netauctionhelp < 3.0 - Cross-Site Scripting via search.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.
by r0t
CVE-2005-4047 EXPLOITDB text VERIFIED
IISWorks ASPKnowledgeBase 2.0 - Cross-Site Scripting via kb.asp a Parameter
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.
by r0t
CVE-2005-4166 EXPLOITDB text VERIFIED
DUWare DUportal Pro 3.4.3 - Cross-Site Scripting via password.asp result Parameter
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
by Dj_Eyes
CVE-2005-4064 EXPLOITDB text VERIFIED
A-FAQ 1.0 - SQL Injection via faqid or catcode Parameter
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
by r0t
CVE-2005-4064 EXPLOITDB text VERIFIED
A-FAQ 1.0 - SQL Injection via faqid or catcode Parameter
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
by r0t
EIP-2026-113231 EXPLOITDB text VERIFIED
Web4Future Portal Solutions - 'Comentarii.php' SQL Injection
by r0t
CVE-2005-4039 EXPLOITDB text VERIFIED
Web4Future Portal Solutions News Portal - Directory Traversal via arhiva.php dir Parameter
Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.
by r0t
CVE-2005-4034 EXPLOITDB text VERIFIED
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
CVE-2005-4034 EXPLOITDB text VERIFIED
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
CVE-2005-4034 EXPLOITDB text VERIFIED
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
CVE-2005-4034 EXPLOITDB text VERIFIED
Web4Future eDating Professional 5 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
by r0t
CVE-2005-4035 EXPLOITDB text VERIFIED
Web4Future eCommerce Enterprise Edition <2.1 - SQL Injection
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
by r0t3d3Vil