Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-2953 EXPLOITDB text VERIFIED
MIVA Merchant 5 - Cross-Site Scripting via Customer_Login Parameter
Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.
by admin@hyperconx.com
CVE-2005-2952 EXPLOITDB text VERIFIED
Subscribe Me Pro <2.044.09P - Path Traversal
Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
by h4cky0u
CVE-2005-4821 EXPLOITDB text VERIFIED
Land Down Under <v801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
by GroundZero Security Research
CVE-2005-4821 EXPLOITDB text VERIFIED
Land Down Under <v801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
by GroundZero Security Research
EIP-2026-109747 EXPLOITDB text VERIFIED
MyBulletinBoard (MyBB) 1.0 - 'RateThread.php' SQL Injection
by stranger-killer
CVE-2005-2896 EXPLOITDB text VERIFIED
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
CVE-2005-2896 EXPLOITDB text VERIFIED
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
CVE-2005-2896 EXPLOITDB text VERIFIED
WEB//NEWS 1.4 - SQL Injection via wn_userpw Parameter
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
by onkel_fisch
EIP-2026-105160 EXPLOITDB text VERIFIED
AMember Pro 2.3.4 - Remote File Inclusion
by NewAngels Team
EIP-2026-111025 EXPLOITDB text VERIFIED
phpCommunityCalendar 4.0 - Multiple SQL Injections
by rgod
EIP-2026-111024 EXPLOITDB text VERIFIED
phpCommunityCalendar 4.0 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
CVE-2005-2892 EXPLOITDB text VERIFIED
PBLang 4.65 - Directory Traversal via setcookie.php u Parameter
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) in the u parameter.
by rgod
CVE-2005-2841 EXPLOITDB text VERIFIED
Cisco IOS 12.2ZH, 12.2ZL, 12.3, 12.3T, 12.4, 12.4T - Buffer Overflow in Firewall Authentication Proxy
Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication credentials.
by Markus
CVE-2005-2855 EXPLOITDB text VERIFIED
Unclassified NewsBoard 1.5.3 - Stored Cross-Site Scripting via Description Field
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.
by retrogod@aliceposta.it
EIP-2026-109748 EXPLOITDB text VERIFIED
MyBulletinBoard (MyBB) 1.0 - Multiple SQL Injections
by stranger-killer
EIP-2026-109358 EXPLOITDB text VERIFIED
MAXdev MD-Pro 1.0.73 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
CVE-2005-2885 EXPLOITDB text VERIFIED
MAXdev MD-Pro 1.0.73 - Remote Command Execution via Incomplete File Extension Blacklist Bypass
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.
by rgod
EIP-2026-109061 EXPLOITDB text VERIFIED
Land Down Under 601/602/700/701/800/801 - 'events.php' HTML Injection
by conor.e.buckley
EIP-2026-119086 EXPLOITDB text VERIFIED
Rediff Bol 7.0 Instant Messenger - ActiveX Control Information Disclosure
by Gregory R. Panakkal
EIP-2026-118794 EXPLOITDB text VERIFIED
Microsoft IIS 5.1 - WebDAV HTTP Request Source Code Disclosure
by Inge Henriksen
CVE-2005-2807 EXPLOITDB text VERIFIED
frox 0.7.18 - Unauthenticated Arbitrary File Read via Configuration File Privilege Escalation
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
by rotor
CVE-2005-2844 EXPLOITDB text VERIFIED
Indiatimes Messenger 6.0 - Buffer Overflow
Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument to the RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object.
by ViPeR
CVE-2005-2814 EXPLOITDB text VERIFIED
FlatNuke 2.5.6 - Cross-Site Scripting via usr Parameter in vis_reg Operation
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
by rgod
CVE-2005-2813 EXPLOITDB text VERIFIED
FlatNuke 2.5.6 - Directory Traversal via id Parameter
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
by rgod
CVE-2005-2792 EXPLOITDB text VERIFIED
phpLDAPadmin <0.9.8 - Path Traversal
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.
by rgod