Exploitdb Exploits
31,394 exploits tracked across all sources.
SqWebMail 5.0.4 - Cross-Site Scripting via Malformed HTML Email Tags
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
by Jakob Balle
phpWebNotes 2.0.0 - Remote Code Execution via t_path_core Parameter
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.
by nf2@scheinwelt.at
PHP-Fusion <= 6.00.107 - Cross-Site Scripting via Nested URL BBCode Tags
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
by slacker4ever_1
Land Down Under 800 - SQL Injection
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter to list.php, (7) m parameter to journal.php, (8) x or (9) n parameter to forums.php, or (10) w parameter to links.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.
by matrix_killer
Land Down Under <801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.
by matrix_killer
Land Down Under <801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.
by matrix_killer
AutoLinks Pro 2.1 - Remote File Inclusion via alpath Parameter FTP URL Bypass
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
by 4Degrees
BFCommand & Control Server Manager <1.22_A - DoS
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.
by Luigi Auriemma
phpMyAdmin < 2.6.4 - Cross-Site Scripting via Username or Error Parameter
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
by Michal Cihar
Astaro Security Linux 6.0 - Unauthenticated Firewall Bypass via HTTP CONNECT Request
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
by Oliver Karow
BEA WebLogic 7.0/8.1 - Administration Console Cross-Site Scripting
by GomoR
LeapFTP - Buffer Overflow via Long Host String in Site Queue File
Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file.
by Sowhat
Foojan PHP Weblog - Cross-Site Scripting via HTTP Referer Header
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.
by ali202
QNX RTOS 6.1.0 and 6.3 - Arbitrary File Read via inputtrap Utility
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.
by Julio Cesar Fort
SaveWebPortal 3.4 - Multiple Directory Traversal Vulnerabilities
by rgod
SaveWebPortal 3.4 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
PHPMyFAQ 1.5.1 - 'Password.php' SQL Injection
by retrogod@aliceposta.it
RunCMS 1.1/1.2 Module Newbb_plus/Messages - SQL Injection
by GulfTech Security
PostNuke 0.760-RC4b - Cross-Site Scripting via Comments Moderate Parameter or User HTML Text
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
by Maksymilian Arciemowicz
PostNuke 0.760-RC4b - Cross-Site Scripting via Comments Moderate Parameter or User HTML Text
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
by Maksymilian Arciemowicz
By Source