Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3991 EXPLOITDB text VERIFIED
phpMyChat 0.14.6 - Cross-Site Scripting via Medium or From Parameter
Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.
by Louis Wang
CVE-2005-3972 EXPLOITDB text VERIFIED
Extreme Search Corporate Edition <= 6.0 - Cross-Site Scripting via Search Parameter
Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
by r0t
CVE-2005-3980 EXPLOITDB text VERIFIED
Trac 0.9 - SQL Injection via Ticket Query Group Parameter
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.
by David Maciejak
CVE-2005-3963 EXPLOITDB text VERIFIED
DotClear - SQL Injection via dc_xd Cookie Parameter
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.
by Siegfried
CVE-2005-3939 EXPLOITDB text VERIFIED
WSN Knowledge Base < 1.2.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
by r0t
CVE-2005-3939 EXPLOITDB text VERIFIED
WSN Knowledge Base < 1.2.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
by r0t
CVE-2005-3939 EXPLOITDB text VERIFIED
WSN Knowledge Base < 1.2.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.
by r0t
CVE-2005-3938 EXPLOITDB text VERIFIED
Softbiz FAQ Script < 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
by r0t
CVE-2005-3938 EXPLOITDB text VERIFIED
Softbiz FAQ Script < 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
by r0t
CVE-2005-3938 EXPLOITDB text VERIFIED
Softbiz FAQ Script < 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
by r0t
CVE-2005-3938 EXPLOITDB text VERIFIED
Softbiz FAQ Script < 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
by r0t
CVE-2005-3938 EXPLOITDB text VERIFIED
Softbiz FAQ Script < 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
by r0t
CVE-2005-3937 EXPLOITDB text VERIFIED
Softbiz B2B Trading Marketplace Script < 1.1 - SQL Injection via cid Parameter
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
by r0t
CVE-2005-3937 EXPLOITDB text VERIFIED
Softbiz B2B Trading Marketplace Script < 1.1 - SQL Injection via cid Parameter
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
by r0t
CVE-2005-3937 EXPLOITDB text VERIFIED
Softbiz B2B Trading Marketplace Script < 1.1 - SQL Injection via cid Parameter
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
by r0t
CVE-2005-3937 EXPLOITDB text VERIFIED
Softbiz B2B Trading Marketplace Script < 1.1 - SQL Injection via cid Parameter
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.
by r0t
CVE-2005-3935 EXPLOITDB text VERIFIED
socketkb < 1.1.0 - SQL Injection via node or art_id Parameters
SQL injection vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) node and (2) art_id parameters.
by r0t
CVE-2005-3948 EXPLOITDB text VERIFIED
phpalbum < 0.2.3 - Directory Traversal via cmd or var1 Parameters
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.
by r0t3d3Vil
CVE-2005-3932 EXPLOITDB text VERIFIED
O-Kiraku Nikki <= 1.3 - SQL Injection via day_id Parameter
SQL injection vulnerability in okiraku.php in O-Kiraku Nikki 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the day_id parameter.
by r0t
CVE-2005-3986 EXPLOITDB text VERIFIED
Instant Photo Gallery < 1 - SQL Injection via cat_id or cid Parameter
Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.
by r0t
CVE-2005-3986 EXPLOITDB text VERIFIED
Instant Photo Gallery < 1 - SQL Injection via cat_id or cid Parameter
Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.
by r0t
CVE-2005-3882 EXPLOITDB text VERIFIED
FAQSystems FAQRing Knowledge Base Software < 3.0 - SQL Injection via answer.php id Parameter
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by r0t
CVE-2005-3933 EXPLOITDB text VERIFIED
88script Event Calendar 2.0 - SQL Injection via m Parameter
SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
by r0t
CVE-2005-3944 EXPLOITDB text VERIFIED
faq_system < 1.1 - SQL Injection via SURVEY_ID Parameter
SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.
by r0t
CVE-2005-3909 EXPLOITDB text VERIFIED
Post Affiliate Pro < 2.0.4 - SQL Injection via Sortorder Parameter
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.
by r0t