Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4720 EXPLOITDB text VERIFIED
Mozilla Firefox <= 1.0.7 - Denial of Service via IFRAME WIDTH Attribute
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the stack.
by Tom Ferris
EIP-2026-111364 EXPLOITDB text VERIFIED
PluggedOut CMS 0.4.8 - 'contenttypeid' SQL Injection
by FalconDeOro
EIP-2026-111363 EXPLOITDB text VERIFIED
PluggedOut CMS 0.4.8 - 'admin.php' Cross-Site Scripting
by FalconDeOro
CVE-2005-3133 EXPLOITDB text VERIFIED
MERAK Mail Server 8.2.4r - Path Traversal
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.
by ShineShadow
CVE-2005-3131 EXPLOITDB text VERIFIED
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
CVE-2005-3131 EXPLOITDB text VERIFIED
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
CVE-2005-3131 EXPLOITDB text VERIFIED
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
CVE-2005-3131 EXPLOITDB text VERIFIED
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
EIP-2026-106716 EXPLOITDB text VERIFIED
EasyGuppy 4.5.4/4.5.5 - 'Printfaq.php' Directory Traversal
by Josh Zlatin-Amishav
EIP-2026-118942 EXPLOITDB text VERIFIED
NateOn Messenger 3.0 - Arbitrary File Download / Buffer Overflow
by saintlinu
CVE-2005-3128 EXPLOITDB text VERIFIED
Address Add Plugin 1.9 and 2.0 for Squirrelmail - Cross-Site Scripting via IMG Tag
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
by anonymous
CVE-2005-3130 EXPLOITDB text VERIFIED
lucidcms 1.0.11 - SQL Injection via Login Field
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
by rgod
CVE-2005-2877 EXPLOITDB text VERIFIED
TWiki 02-Sep-2004 and earlier - Remote Code Execution via Rev Parameter Shell Metacharacter Injection
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
by JChristophFuchs
CVE-2005-3152 EXPLOITDB text VERIFIED
CubeCart 3.0.3 - Cross-Site Scripting via redir or searchStr Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.
by Lostmon
CVE-2005-3152 EXPLOITDB text VERIFIED
CubeCart 3.0.3 - Cross-Site Scripting via redir or searchStr Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.
by Lostmon
CVE-2005-2804 EXPLOITDB text VERIFIED
Novell GroupWise 6.5.3 - Denial of Service via Large TCP/IP Port in Registry Key
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
by Francisco Amato
CVE-2005-3127 EXPLOITDB text VERIFIED
lucidcms 1.0.11 - Cross-Site Scripting via Query String
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
by X1ngBox
CVE-2005-3083 EXPLOITDB text VERIFIED
CMS Made Simple 0.10 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by X1ngBox
EIP-2026-111162 EXPLOITDB text VERIFIED
PHPMyFAQ 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
EIP-2026-110643 EXPLOITDB text VERIFIED
PHP Advanced Transfer Manager 1.30 - Multiple Directory Traversal Vulnerabilities
by rgod
EIP-2026-110642 EXPLOITDB text VERIFIED
PHP Advanced Transfer Manager 1.30 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
CVE-2005-3005 EXPLOITDB text VERIFIED
Helpdesk Software Hesk - Auth Bypass
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.
by Rajesh Sethumadhavan
CVE-2005-2968 EXPLOITDB text VERIFIED
Firefox 1.0.6-Mozilla 1.7.10 - Command Injection
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
by eter Zelezny
CVE-2005-3019 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org
CVE-2005-3019 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org