Exploitdb Exploits
31,394 exploits tracked across all sources.
ShockBoard 3.0 and 4.0 - SQL Injection via Topic Offset Parameter
SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
by r0t
SearchSolutions 1.2/1.3 (Multiple Products) - Cross-Site Scripting
by r0t
Randshop - SQL Injection via kategorieid or katid Parameter
SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.
by liz0
phpWordPress PHP News and Article Manager 3.0 - SQL Injection via Poll, Category, or Archive Parameters
SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.
by r0t
PHP Web Statistik 1.4 - Content Injection
by Francesco Ongaro
PHP Doc System < 1.5.1 - Directory Traversal via Show Parameter
Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.
by r0t
netzbrett < 1.5.1 - SQL Injection via p_entry Parameter
SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.
by r0t
K-Search < 1.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.
by r0t
Central Manchester CLC Helpdesk Issue Manager <= 0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
by r0t3d3Vil
Central Manchester CLC Helpdesk Issue Manager <= 0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
by r0t3d3Vil
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
GuppY <= 4.5.9 - Directory Traversal and Arbitrary File Inclusion via meskin or lng Parameter
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.
by retrogod@aliceposta.it
FreeWebStat 1.0 rev37 - Cross-Site Scripting via site, jsref, jsres, jscolor, and search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.
by Francesco Ongaro
Enterprise Connector < 1.0.2 - SQL Injection via MessageID Parameter
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
by r0t
Enterprise Connector < 1.0.2 - SQL Injection via MessageID Parameter
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
by r0t
edmobbs < 0.9 - SQL Injection via table or messageID Parameter
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.
by r0t
SourceWell < 1.1.2 - SQL Injection via cnt Parameter
SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affected version is 1.1.3, but as of 2005-11-29, the most recent version appears to be 1.1.2.
by r0t
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
Bedeng PSP 1.1 - SQL Injection via cwhere or ckode Parameter
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.
by r0t
Babe Logger 2 - SQL Injection via gal or id Parameter
SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.
by r0t
By Source