Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3873 EXPLOITDB text VERIFIED
ShockBoard 3.0 and 4.0 - SQL Injection via Topic Offset Parameter
SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
by r0t
EIP-2026-111962 EXPLOITDB text VERIFIED
SearchSolutions 1.2/1.3 (Multiple Products) - Cross-Site Scripting
by r0t
CVE-2005-3924 EXPLOITDB text VERIFIED
Randshop - SQL Injection via kategorieid or katid Parameter
SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.
by liz0
CVE-2005-3844 EXPLOITDB text VERIFIED
phpWordPress PHP News and Article Manager 3.0 - SQL Injection via Poll, Category, or Archive Parameters
SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.
by r0t
EIP-2026-110788 EXPLOITDB text VERIFIED
PHP Web Statistik 1.4 - Content Injection
by Francesco Ongaro
CVE-2005-3878 EXPLOITDB text VERIFIED
PHP Doc System < 1.5.1 - Directory Traversal via Show Parameter
Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.
by r0t
EIP-2026-110529 EXPLOITDB text VERIFIED
PDJK-support Suite 1.1 - Multiple SQL Injections
by r0t
CVE-2005-3874 EXPLOITDB text VERIFIED
netzbrett < 1.5.1 - SQL Injection via p_entry Parameter
SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.
by r0t
EIP-2026-109851 EXPLOITDB text VERIFIED
Nelogic Nephp Publisher 4.5.2 - SQL Injection
by r0t
CVE-2005-3868 EXPLOITDB text VERIFIED
K-Search < 1.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.
by r0t
CVE-2005-3925 EXPLOITDB text VERIFIED
Central Manchester CLC Helpdesk Issue Manager <= 0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
by r0t3d3Vil
CVE-2005-3925 EXPLOITDB text VERIFIED
Central Manchester CLC Helpdesk Issue Manager <= 0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
by r0t3d3Vil
CVE-2005-3927 EXPLOITDB text VERIFIED
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
CVE-2005-3927 EXPLOITDB text VERIFIED
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
CVE-2005-3927 EXPLOITDB text VERIFIED
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
CVE-2005-3927 EXPLOITDB text VERIFIED
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
CVE-2005-3959 EXPLOITDB text VERIFIED
FreeWebStat 1.0 rev37 - Cross-Site Scripting via site, jsref, jsres, jscolor, and search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.
by Francesco Ongaro
CVE-2005-3875 EXPLOITDB text VERIFIED
Enterprise Connector < 1.0.2 - SQL Injection via MessageID Parameter
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
by r0t
CVE-2005-3875 EXPLOITDB text VERIFIED
Enterprise Connector < 1.0.2 - SQL Injection via MessageID Parameter
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
by r0t
CVE-2005-3870 EXPLOITDB text VERIFIED
edmobbs < 0.9 - SQL Injection via table or messageID Parameter
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.
by r0t
CVE-2005-3864 EXPLOITDB text VERIFIED
SourceWell < 1.1.2 - SQL Injection via cnt Parameter
SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affected version is 1.1.3, but as of 2005-11-29, the most recent version appears to be 1.1.2.
by r0t
CVE-2005-3953 EXPLOITDB text VERIFIED
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
CVE-2005-3953 EXPLOITDB text VERIFIED
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
CVE-2005-3953 EXPLOITDB text VERIFIED
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
CVE-2005-3920 EXPLOITDB text VERIFIED
Babe Logger 2 - SQL Injection via gal or id Parameter
SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.
by r0t