Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3545 EXPLOITDB text VERIFIED
ibproarcade < 2.5.2 - SQL Injection via Report Module User Parameter
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.
by B~HFH
CVE-2005-4016 EXPLOITDB text VERIFIED
Widget Property 1.1.19 - SQL Injection via property_id Parameter
SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php.
by r0t3d3Vil
CVE-2005-3509 EXPLOITDB text VERIFIED
JPortal Web Portal - SQL Injection via Banner.php or ID Parameter
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.
by Mousehack
CVE-2005-3509 EXPLOITDB text VERIFIED
JPortal Web Portal - SQL Injection via Banner.php or ID Parameter
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.
by Mousehack
CVE-2005-4657 EXPLOITDB text VERIFIED
Ocean12 Calendar Manager Pro 1.01 - Auth Bypass
Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by syst3m_f4ult
CVE-2005-1939 EXPLOITDB text VERIFIED
Ipswitch WhatsUp Small Business 2004 - Directory Traversal via Report Service
Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).
by Dennis Rand
EIP-2026-110706 EXPLOITDB text VERIFIED
PHP Handicapper (2005) - 'Process_signup.php' HTTP Response Splitting
by BiPi_HaCk
CVE-2005-3584 EXPLOITDB text VERIFIED
phpwebthings 1.4.4 - Cross-Site Scripting via Forum Parameter
Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.
by Linux_Drox
CVE-2005-3469 EXPLOITDB text VERIFIED
News2Net 3.0.0.0 - SQL Injection via Category Parameter
SQL injection vulnerability in index.php in News2Net 3.0.0.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
by Mousehack
CVE-2005-3507 EXPLOITDB text VERIFIED
CuteNews < 1.4.1 - Directory Traversal and Remote Code Execution via Template Parameter
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
by retrogod@aliceposta.it
CVE-2005-3507 EXPLOITDB text VERIFIED
CuteNews < 1.4.1 - Directory Traversal and Remote Code Execution via Template Parameter
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
by retrogod@aliceposta.it
CVE-2005-3473 EXPLOITDB text VERIFIED
Simple PHP Blog <= 0.4.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
by enji@infosys.tuwien.ac.at
CVE-2005-3473 EXPLOITDB text VERIFIED
Simple PHP Blog <= 0.4.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
by enji@infosys.tuwien.ac.at
CVE-2005-3473 EXPLOITDB text VERIFIED
Simple PHP Blog <= 0.4.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
by enji@infosys.tuwien.ac.at
CVE-2005-4717 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6.0 - DoS
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
by ad@class101.org
EIP-2026-114441 EXPLOITDB text VERIFIED
XMB Forum 1.9.3 - 'post.php' SQL Injection
by almaster
CVE-2005-3512 EXPLOITDB text VERIFIED
VUBB alpha rc1 - Cross-Site Scripting via t Parameter in newreply Action
Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.
by Alireza Hassani
CVE-2005-4769 EXPLOITDB text VERIFIED
Belchior Foundry vCard PRO 3.1 - SQL Injection
SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
CVE-2006-1803 EXPLOITDB text VERIFIED
phpMyAdmin < 2.8.0.3 - Cross-Site Scripting via sql_query Parameter
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.
by p0w3r
CVE-2005-3478 EXPLOITDB text VERIFIED
PHPCafe.net Tutorials Manager 1.0 Beta 2 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in PHPCafe.net Tutorials Manager 1.0 Beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by almaster
CVE-2005-3388 EXPLOITDB text VERIFIED
PHP 4.4.0 and 5.0.5 phpinfo - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."
by Stefan Esser
CVE-2005-3394 EXPLOITDB text VERIFIED
oaboard forum 1.0 - SQL Injection via Channel or Topic Parameter
Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.
by abducter_minds@yahoo.com
CVE-2005-3395 EXPLOITDB text VERIFIED
Invision Gallery 2.0.3 - SQL Injection via st Parameter
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
by almaster
CVE-2005-3411 EXPLOITDB text VERIFIED
Snitz Forums 2000 3.4.05 - Cross-Site Scripting via Type Parameter in Post.asp
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.
by h4xorcrew
CVE-2005-3397 EXPLOITDB text VERIFIED
Comersus BackOffice - Cross-Site Scripting via Support Error Parameter
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.
by _6mO_HaCk