Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3916 EXPLOITDB text VERIFIED
WSN Forum 1.21 - SQL Injection via Memberlist Profile ID Parameter
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.
by r0t
CVE-2005-3833 EXPLOITDB text VERIFIED
Tunez <= 1.21 - SQL Injection via song_id Parameter
SQL injection vulnerability in songinfo.php in Tunez 1.21 and earlier allows remote attackers to execute arbitrary SQL commands via the song_id parameter.
by r0t3d3Vil
CVE-2005-3834 EXPLOITDB text VERIFIED
Tunez 1.21 - Cross-Site Scripting via searchFor Parameter
Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter.
by r0t3d3Vil
EIP-2026-110714 EXPLOITDB text VERIFIED
PHP Labs Survey Wizard - SQL Injection
by r0t
EIP-2026-110036 EXPLOITDB text VERIFIED
OmnistarLive 5.2 - Multiple SQL Injections
by r0t
CVE-2005-3816 EXPLOITDB text VERIFIED
freeForum < 1.1 - SQL Injection via Cat or Thread Parameter
Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.
by r0t3d3Vil
CVE-2005-3826 EXPLOITDB text VERIFIED
ezyhelpdesk 1.0 - SQL Injection via edit_id, faq_id, c_id, and Search Parameters
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
by r0t
EIP-2026-106082 EXPLOITDB text VERIFIED
CommodityRentals 2.0 - SQL Injection
by r0t3d3Vil
CVE-2005-3955 EXPLOITDB text VERIFIED
blogBuddies 0.3 - Cross-Site Scripting via url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
by gb.network
CVE-2005-3955 EXPLOITDB text VERIFIED
blogBuddies 0.3 - Cross-Site Scripting via url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
by gb.network
CVE-2005-3954 EXPLOITDB text VERIFIED
blogbuddies 0.3 - Cross-Site Scripting via u Parameter
Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.
by gb.network
CVE-2005-3914 EXPLOITDB text VERIFIED
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
CVE-2005-3914 EXPLOITDB text VERIFIED
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
CVE-2005-3914 EXPLOITDB text VERIFIED
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
CVE-2005-3855 EXPLOITDB text VERIFIED
1-2-3 music store - SQL Injection via AlbumID Parameter
SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.
by r0t
CVE-2005-3902 EXPLOITDB text VERIFIED
Virtual Hosting Control System 2.2.0-2.4.6.2 - Cross-Site Scripting via Error Message Query String
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
by Moritz Naumann
CVE-2005-4160 EXPLOITDB text VERIFIED
Torrential 1.2 - Directory Traversal via getdox.php Query String
Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.
by Shell
CVE-2005-3849 EXPLOITDB text VERIFIED
PmWiki < 2.0.12 - Cross-Site Scripting via Search Module q Parameter
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
by Moritz Naumann
CVE-2005-3893 EXPLOITDB text VERIFIED
OTRS 1.0.0-1.3.2 & 2.0.0-2.0.3 SQL Injection via Login & Authenticated Parameters
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
by Moritz Naumann
CVE-2005-3893 EXPLOITDB text VERIFIED
OTRS 1.0.0-1.3.2 & 2.0.0-2.0.3 SQL Injection via Login & Authenticated Parameters
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
by Moritz Naumann
CVE-2005-3894 EXPLOITDB text VERIFIED
OTRS 1.0.0-1.3.2 and 2.0.0-2.0.3 - Authenticated Cross-Site Scripting via QueueID and Action Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.
by Moritz Naumann
CVE-2005-3748 EXPLOITDB text VERIFIED
Tru-Zone Nuke ET 3.2 - SQL Injection via Search Module Query Parameter
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.
by Lostmon
CVE-2005-3743 EXPLOITDB text VERIFIED
SimplePoll - SQL Injection via PollID Parameter
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
by stranger-killer
CVE-2005-3770 EXPLOITDB text VERIFIED
Phppost - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.
by trueend5
CVE-2005-3770 EXPLOITDB text VERIFIED
Phppost - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.
by trueend5