Exploitdb Exploits
31,394 exploits tracked across all sources.
MIVA Merchant 5 - Cross-Site Scripting via Customer_Login Parameter
Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.
by admin@hyperconx.com
Subscribe Me Pro <2.044.09P - Path Traversal
Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
by h4cky0u
Land Down Under <v801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
by GroundZero Security Research
Land Down Under <v801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
by GroundZero Security Research
MyBulletinBoard (MyBB) 1.0 - 'RateThread.php' SQL Injection
by stranger-killer
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
phpCommunityCalendar 4.0 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
PBLang 4.65 - Directory Traversal via setcookie.php u Parameter
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) in the u parameter.
by rgod
Cisco IOS 12.2ZH, 12.2ZL, 12.3, 12.3T, 12.4, 12.4T - Buffer Overflow in Firewall Authentication Proxy
Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication credentials.
by Markus
Unclassified NewsBoard 1.5.3 - Stored Cross-Site Scripting via Description Field
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.
by retrogod@aliceposta.it
MyBulletinBoard (MyBB) 1.0 - Multiple SQL Injections
by stranger-killer
MAXdev MD-Pro 1.0.73 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
MAXdev MD-Pro 1.0.73 - Remote Command Execution via Incomplete File Extension Blacklist Bypass
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.
by rgod
Land Down Under 601/602/700/701/800/801 - 'events.php' HTML Injection
by conor.e.buckley
Rediff Bol 7.0 Instant Messenger - ActiveX Control Information Disclosure
by Gregory R. Panakkal
Microsoft IIS 5.1 - WebDAV HTTP Request Source Code Disclosure
by Inge Henriksen
frox 0.7.18 - Unauthenticated Arbitrary File Read via Configuration File Privilege Escalation
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
by rotor
Indiatimes Messenger 6.0 - Buffer Overflow
Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument to the RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object.
by ViPeR
FlatNuke 2.5.6 - Cross-Site Scripting via usr Parameter in vis_reg Operation
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
by rgod
FlatNuke 2.5.6 - Directory Traversal via id Parameter
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
by rgod
phpLDAPadmin <0.9.8 - Path Traversal
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.
by rgod
By Source