Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3769 EXPLOITDB text VERIFIED
PHP Download Manager 1.1.3 - SQL Injection via Cat Parameter
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by ksa_ksa82
CVE-2005-3746 EXPLOITDB text VERIFIED
APBoard - SQL Injection via Thread Start Parameter
SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter.
by ksa_ksa82
CVE-2005-3742 EXPLOITDB text VERIFIED
Advanced Poll < 2.0.3 - Cross-Site Scripting via poll_ident Parameter
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.
by [GB]
CVE-2005-3745 EXPLOITDB text VERIFIED
Apache Struts 1.2.7 - Cross-Site Scripting via Query String in Error Message
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
by Irene Abezgauz
CVE-2005-3737 EXPLOITDB text VERIFIED
Inkscape 0.41-0.42.2 - Buffer Overflow in SVG Importer Style Property Handling
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
by Joxean Koret
EIP-2026-110803 EXPLOITDB text VERIFIED
PHP-Fusion 4.0/5.0/6.0 - 'options.php?/ viewforum.php' SQL Injection
by Robin Verton
CVE-2005-3695 EXPLOITDB text VERIFIED
LiteSpeed Web Server 2.1.5 - Cross-Site Scripting via m Parameter
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
by Gama Sec
CVE-2005-3189 EXPLOITDB text VERIFIED
Qualcomm WorldMail IMAP Server - Path Traversal
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.
by FistFuXXer
CVE-2005-3730 EXPLOITDB text VERIFIED
Revize CMS - Cross-Site Scripting via HTTPTranslatorServlet Parameters
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly involving setWebSpace.jsp.
by Lostmon
CVE-2005-3728 EXPLOITDB text VERIFIED
Idetix Software Systems Revize CMS - Info Disclosure
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information.
by Lostmon
CVE-2005-3727 EXPLOITDB text VERIFIED
Revize CMS - SQL Injection via Debug Query Results Page
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter.
by Lostmon
CVE-2005-3790 EXPLOITDB text VERIFIED
phpwcms 1.2.5 - Cross-Site Scripting via i and text Parameters
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.
by Stefan Lochbihler
CVE-2005-3789 EXPLOITDB text VERIFIED
phpwcms 1.2.5 - Directory Traversal via form_lang or imgdir Parameter
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.
by Stefan Lochbihler
CVE-2005-3789 EXPLOITDB text VERIFIED
phpwcms 1.2.5 - Directory Traversal via form_lang or imgdir Parameter
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.
by Stefan Lochbihler
CVE-2005-4647 EXPLOITDB text VERIFIED
PEARLINGER Pearl Forums <2.4 - SQL Injection
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by abducter_minds@yahoo.com
CVE-2005-4646 EXPLOITDB text VERIFIED
PEARLINGER Pearl Forums <2.4 - Path Traversal
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by abducter_minds@yahoo.com
CVE-2005-3638 EXPLOITDB text VERIFIED
ekinboard 1.0.3 - Cross-Site Scripting via Profile ID Parameter and Post Titles
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.
by trueend5
CVE-2005-3797 EXPLOITDB text VERIFIED
AlstraSoft Template Seller Pro 3.25 - RCE
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.
by Robin Verton
CVE-2005-3576 EXPLOITDB text VERIFIED
Walla TeleSite <3.0 - Info Disclosure
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
by Rafi Nahum
CVE-2005-3578 EXPLOITDB text VERIFIED
Walla TeleSite < 3.0 - SQL Injection via ts.exe sug Parameter
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
by Rafi Nahum
CVE-2005-3577 EXPLOITDB text VERIFIED
Walla TeleSite < 3.0 - Cross-Site Scripting via ts.exe sug Parameter
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.
by Rafi Nahum
CVE-2005-3579 EXPLOITDB text VERIFIED
Walla TeleSite <3.0 - Path Traversal
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.
by Rafi Nahum
CVE-2005-3682 EXPLOITDB text VERIFIED
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.
by HACKERS PAL
CVE-2005-3682 EXPLOITDB text VERIFIED
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.
by HACKERS PAL
CVE-2005-3639 EXPLOITDB text VERIFIED
Help Center Live < 2.0.2 - Remote File Inclusion via osTicket File Parameter
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.
by HACKERS PAL