Exploitdb Exploits
31,394 exploits tracked across all sources.
Mozilla Firefox <= 1.0.7 - Denial of Service via IFRAME WIDTH Attribute
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the stack.
by Tom Ferris
PluggedOut CMS 0.4.8 - 'contenttypeid' SQL Injection
by FalconDeOro
PluggedOut CMS 0.4.8 - 'admin.php' Cross-Site Scripting
by FalconDeOro
MERAK Mail Server 8.2.4r - Path Traversal
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.
by ShineShadow
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
MERAK Mail Server 8.2.4r-Icewarp Web Mail 5.5.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
by ss_contacts
EasyGuppy 4.5.4/4.5.5 - 'Printfaq.php' Directory Traversal
by Josh Zlatin-Amishav
NateOn Messenger 3.0 - Arbitrary File Download / Buffer Overflow
by saintlinu
Address Add Plugin 1.9 and 2.0 for Squirrelmail - Cross-Site Scripting via IMG Tag
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
by anonymous
lucidcms 1.0.11 - SQL Injection via Login Field
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
by rgod
TWiki 02-Sep-2004 and earlier - Remote Code Execution via Rev Parameter Shell Metacharacter Injection
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
by JChristophFuchs
CubeCart 3.0.3 - Cross-Site Scripting via redir or searchStr Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.
by Lostmon
CubeCart 3.0.3 - Cross-Site Scripting via redir or searchStr Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.
by Lostmon
Novell GroupWise 6.5.3 - Denial of Service via Large TCP/IP Port in Registry Key
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
by Francisco Amato
lucidcms 1.0.11 - Cross-Site Scripting via Query String
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
by X1ngBox
CMS Made Simple 0.10 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by X1ngBox
PHPMyFAQ 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
PHP Advanced Transfer Manager 1.30 - Multiple Directory Traversal Vulnerabilities
by rgod
PHP Advanced Transfer Manager 1.30 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
Helpdesk Software Hesk - Auth Bypass
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.
by Rajesh Sethumadhavan
Firefox 1.0.6-Mozilla 1.7.10 - Command Injection
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
by eter Zelezny
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org
By Source