Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-3019 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
CVE-2005-3019 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
CVE-2005-3020 EXPLOITDB text VERIFIED
vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.
by deluxe@security-project.org
EIP-2026-109957 EXPLOITDB text VERIFIED
NooToplist 1.0 - 'index.php' Multiple SQL Injections
by David Sopas Ferreira
CVE-2005-3004 EXPLOITDB text VERIFIED
Interakt MX Shop 3.2.0 - SQL Injection
SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php.
by David Sopas Ferreira
CVE-2005-3026 EXPLOITDB text VERIFIED
Alstrasoft Epay Pro <2.0 - Path Traversal
Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.
by h4cky0u
CVE-2005-3018 EXPLOITDB text VERIFIED
Apple Safari - Denial of Service via Crafted data:// URL
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
by Jonathan Rockway
EIP-2026-106146 EXPLOITDB text VERIFIED
Content2Web 1.0.1 - Multiple Input Validation Vulnerabilities
by Security Tester
EIP-2026-106449 EXPLOITDB text VERIFIED
Digital Scribe 1.4 - Login SQL Injection
by rgod
CVE-2005-2989 EXPLOITDB text VERIFIED
DeluxeBB 1.0 and 1.0.5 - SQL Injection via tid uid or fid Parameter
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
by abducter
CVE-2005-2989 EXPLOITDB text VERIFIED
DeluxeBB 1.0 and 1.0.5 - SQL Injection via tid uid or fid Parameter
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
by abducter
CVE-2005-2989 EXPLOITDB text VERIFIED
DeluxeBB 1.0 and 1.0.5 - SQL Injection via tid uid or fid Parameter
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
by abducter
CVE-2005-2989 EXPLOITDB text VERIFIED
DeluxeBB 1.0 and 1.0.5 - SQL Injection via tid uid or fid Parameter
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
by abducter
CVE-2005-2989 EXPLOITDB text VERIFIED
DeluxeBB 1.0 and 1.0.5 - SQL Injection via tid uid or fid Parameter
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.
by abducter
CVE-2005-2985 EXPLOITDB text VERIFIED
AEwebworks aeDating Script <4.0 - SQL Injection
SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter.
by alexsrb
CVE-2005-2877 EXPLOITDB text VERIFIED
TWiki 02-Sep-2004 and earlier - Remote Code Execution via Rev Parameter Shell Metacharacter Injection
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.
by B4dP4nd4
CVE-2005-2980 EXPLOITDB text VERIFIED
phpoutsourcing Noah's classifieds <1.3 - XSS
Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.
by trueend5
CVE-2005-2979 EXPLOITDB text VERIFIED
phpoutsourcing Noah's classifieds - SQL Injection
SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.
by trueend5
CVE-2005-2956 EXPLOITDB text VERIFIED
ATutor 1.5.1 - Unauthenticated Sensitive Information Exposure via Predictable Chat Log Filenames
ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.
by rgod
CVE-2005-2954 EXPLOITDB text VERIFIED
ATutor - SQL Injection via Password Reminder Email Field
SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.
by rgod