Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3920 EXPLOITDB text VERIFIED
Babe Logger 2 - SQL Injection via gal or id Parameter
SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.
by r0t
CVE-2005-3865 EXPLOITDB text VERIFIED
AllWeb search 3.0 - SQL Injection via Search Parameter
SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.
by r0t
CVE-2000-0751 EXPLOITDB text VERIFIED
NetBSD and OpenBSD - Remote Code Execution via Format String Injection in mopd
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
by r0t
CVE-2005-3859 EXPLOITDB text VERIFIED
Q-News 2.0 - Remote Code Execution via id Parameter
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
by [GB]
CVE-2005-3861 EXPLOITDB text VERIFIED
phpgreetz < 0.99 - Remote Code Execution via content.php content Parameter
PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
by [GB]
CVE-2005-3919 EXPLOITDB text VERIFIED
PBLang 4.65 - Cross-Site Scripting via UCP.php and SendPm.php
Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.
by r0xes
CVE-2005-3860 EXPLOITDB text VERIFIED
Oliver May Athena PHP Website Administration 0.1a - Remote Code Execution via athena_dir Parameter
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.
by [GB]
CVE-2005-3838 EXPLOITDB text VERIFIED
IsolSoft Support Center <= 2.2 - SQL Injection via search.php Parameters
Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.
by r0t3d3Vil
CVE-2005-4170 EXPLOITDB text VERIFIED
efiction 1.1 - SQL Injection via viewuser.php uid Parameter
SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.
by retrogod@aliceposta.it
CVE-2005-4168 EXPLOITDB text VERIFIED
eFiction 1.0, 1.1, 2.0 - SQL Injection via Let Parameter or Username
Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.
by retrogod@aliceposta.it
CVE-2005-4167 EXPLOITDB text VERIFIED
efiction 1.0 and 1.1 - Cross-Site Scripting via let Parameter
Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.
by retrogod@aliceposta.it
CVE-2005-4169 EXPLOITDB text VERIFIED
eFiction 1.0 - SQL Injection via Authors Viewlist or Viewstory Parameters
Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php.
by retrogod@aliceposta.it
CVE-2005-3827 EXPLOITDB text VERIFIED
agilebill < 1.4.92 - SQL Injection via product_cat id Parameter
SQL injection vulnerability in product_cat in AgileBill 1.4.92 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by r0t
CVE-2005-3818 EXPLOITDB text VERIFIED
vtiger CRM < 4.2 - Cross-Site Scripting via Multiple Input Fields
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
by Christopher Kunz
CVE-2005-3818 EXPLOITDB text VERIFIED
vtiger CRM < 4.2 - Cross-Site Scripting via Multiple Input Fields
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
by Christopher Kunz
CVE-2005-3819 EXPLOITDB text VERIFIED
vtiger CRM < 4.2 - SQL Injection via HelpDesk user_name and date Parameters
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.
by Christopher Kunz
CVE-2005-3817 EXPLOITDB text VERIFIED
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
by r0t
CVE-2005-3817 EXPLOITDB text VERIFIED
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
by r0t
CVE-2005-3817 EXPLOITDB text VERIFIED
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
by r0t
CVE-2005-3817 EXPLOITDB text VERIFIED
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
by r0t
CVE-2005-3918 EXPLOITDB text VERIFIED
OvBB 0.08a - SQL Injection via Thread ID or User ID Parameter
Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial.
by r0t3d3Vil
CVE-2005-3918 EXPLOITDB text VERIFIED
OvBB 0.08a - SQL Injection via Thread ID or User ID Parameter
Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial.
by r0t3d3Vil
CVE-2005-3815 EXPLOITDB text VERIFIED
Orca Forum < 4.3b - SQL Injection via msg Parameter
SQL injection vulnerability in forum.php in Orca Forum 4.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.
by r0t3d3Vil
CVE-2005-3825 EXPLOITDB text VERIFIED
Comdev Vote Caster < 3.1 - SQL Injection via campaign_id Parameter
SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action.
by r0t
CVE-2005-3813 EXPLOITDB text VERIFIED
MailEnable Professional 1.7 and Enterprise 1.1 - Authenticated Denial of Service via IMAP RENAME Command
IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.
by Josh Zlatin-Amishav