Exploitdb Exploits
31,394 exploits tracked across all sources.
PHP Download Manager 1.1.3 - SQL Injection via Cat Parameter
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by ksa_ksa82
APBoard - SQL Injection via Thread Start Parameter
SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter.
by ksa_ksa82
Advanced Poll < 2.0.3 - Cross-Site Scripting via poll_ident Parameter
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.
by [GB]
Apache Struts 1.2.7 - Cross-Site Scripting via Query String in Error Message
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
by Irene Abezgauz
Inkscape 0.41-0.42.2 - Buffer Overflow in SVG Importer Style Property Handling
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
by Joxean Koret
PHP-Fusion 4.0/5.0/6.0 - 'options.php?/ viewforum.php' SQL Injection
by Robin Verton
LiteSpeed Web Server 2.1.5 - Cross-Site Scripting via m Parameter
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
by Gama Sec
Qualcomm WorldMail IMAP Server - Path Traversal
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.
by FistFuXXer
Revize CMS - Cross-Site Scripting via HTTPTranslatorServlet Parameters
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly involving setWebSpace.jsp.
by Lostmon
Idetix Software Systems Revize CMS - Info Disclosure
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information.
by Lostmon
Revize CMS - SQL Injection via Debug Query Results Page
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter.
by Lostmon
phpwcms 1.2.5 - Cross-Site Scripting via i and text Parameters
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.
by Stefan Lochbihler
phpwcms 1.2.5 - Directory Traversal via form_lang or imgdir Parameter
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.
by Stefan Lochbihler
phpwcms 1.2.5 - Directory Traversal via form_lang or imgdir Parameter
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.
by Stefan Lochbihler
PEARLINGER Pearl Forums <2.4 - SQL Injection
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by abducter_minds@yahoo.com
PEARLINGER Pearl Forums <2.4 - Path Traversal
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by abducter_minds@yahoo.com
ekinboard 1.0.3 - Cross-Site Scripting via Profile ID Parameter and Post Titles
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.
by trueend5
AlstraSoft Template Seller Pro 3.25 - RCE
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.
by Robin Verton
Walla TeleSite <3.0 - Info Disclosure
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
by Rafi Nahum
Walla TeleSite < 3.0 - SQL Injection via ts.exe sug Parameter
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
by Rafi Nahum
Walla TeleSite < 3.0 - Cross-Site Scripting via ts.exe sug Parameter
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.
by Rafi Nahum
Walla TeleSite <3.0 - Path Traversal
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.
by Rafi Nahum
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.
by HACKERS PAL
Wizz Forum 1.20 - SQL Injection via AuthID TopicID Parameters
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.
by HACKERS PAL
Help Center Live < 2.0.2 - Remote File Inclusion via osTicket File Parameter
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.
by HACKERS PAL
By Source