Exploitdb Exploits
31,394 exploits tracked across all sources.
WSN Forum 1.21 - SQL Injection via Memberlist Profile ID Parameter
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.
by r0t
Tunez <= 1.21 - SQL Injection via song_id Parameter
SQL injection vulnerability in songinfo.php in Tunez 1.21 and earlier allows remote attackers to execute arbitrary SQL commands via the song_id parameter.
by r0t3d3Vil
Tunez 1.21 - Cross-Site Scripting via searchFor Parameter
Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter.
by r0t3d3Vil
freeForum < 1.1 - SQL Injection via Cat or Thread Parameter
Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.
by r0t3d3Vil
ezyhelpdesk 1.0 - SQL Injection via edit_id, faq_id, c_id, and Search Parameters
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
by r0t
blogBuddies 0.3 - Cross-Site Scripting via url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
by gb.network
blogBuddies 0.3 - Cross-Site Scripting via url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
by gb.network
blogbuddies 0.3 - Cross-Site Scripting via u Parameter
Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.
by gb.network
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
AFFcommerce 1.1.4 - SQL Injection via cl Parameter and item_id Parameter
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
by r0t3d3Vil
1-2-3 music store - SQL Injection via AlbumID Parameter
SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.
by r0t
Virtual Hosting Control System 2.2.0-2.4.6.2 - Cross-Site Scripting via Error Message Query String
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
by Moritz Naumann
Torrential 1.2 - Directory Traversal via getdox.php Query String
Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.
by Shell
PmWiki < 2.0.12 - Cross-Site Scripting via Search Module q Parameter
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
by Moritz Naumann
OTRS 1.0.0-1.3.2 & 2.0.0-2.0.3 SQL Injection via Login & Authenticated Parameters
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
by Moritz Naumann
OTRS 1.0.0-1.3.2 & 2.0.0-2.0.3 SQL Injection via Login & Authenticated Parameters
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
by Moritz Naumann
OTRS 1.0.0-1.3.2 and 2.0.0-2.0.3 - Authenticated Cross-Site Scripting via QueueID and Action Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.
by Moritz Naumann
Tru-Zone Nuke ET 3.2 - SQL Injection via Search Module Query Parameter
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.
by Lostmon
SimplePoll - SQL Injection via PollID Parameter
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
by stranger-killer
Phppost - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.
by trueend5
Phppost - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.
by trueend5
By Source