Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-2769 EXPLOITDB text VERIFIED
SqWebMail 5.0.4 - Cross-Site Scripting via Malformed HTML Email Tags
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
by Jakob Balle
CVE-2005-2775 EXPLOITDB text VERIFIED
phpWebNotes 2.0.0 - Remote Code Execution via t_path_core Parameter
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.
by nf2@scheinwelt.at
CVE-2005-2783 EXPLOITDB text VERIFIED
PHP-Fusion <= 6.00.107 - Cross-Site Scripting via Nested URL BBCode Tags
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
by slacker4ever_1
CVE-2005-2675 EXPLOITDB text VERIFIED
Land Down Under 800 - SQL Injection
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter to list.php, (7) m parameter to journal.php, (8) x or (9) n parameter to forums.php, or (10) w parameter to links.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.
by matrix_killer
CVE-2005-2788 EXPLOITDB text VERIFIED
Land Down Under <801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.
by matrix_killer
CVE-2005-2788 EXPLOITDB text VERIFIED
Land Down Under <801 - SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.
by matrix_killer
CVE-2005-2782 EXPLOITDB text VERIFIED
AutoLinks Pro 2.1 - Remote File Inclusion via alpath Parameter FTP URL Bypass
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
by 4Degrees
CVE-2005-2791 EXPLOITDB text VERIFIED
BFCommand & Control Server Manager <1.22_A - DoS
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.
by Luigi Auriemma
CVE-2005-2869 EXPLOITDB text VERIFIED
phpMyAdmin < 2.6.4 - Cross-Site Scripting via Username or Error Parameter
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
by Michal Cihar
EIP-2026-109207 EXPLOITDB text VERIFIED
Looking Glass - Cross-Site Scripting
by rgod
CVE-2005-2729 EXPLOITDB text VERIFIED
Astaro Security Linux 6.0 - Unauthenticated Firewall Bypass via HTTP CONNECT Request
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
by Oliver Karow
EIP-2026-118308 EXPLOITDB text VERIFIED
BEA WebLogic 7.0/8.1 - Administration Console Cross-Site Scripting
by GomoR
CVE-2005-2767 EXPLOITDB text VERIFIED
LeapFTP - Buffer Overflow via Long Host String in Site Queue File
Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file.
by Sowhat
CVE-2005-2721 EXPLOITDB text VERIFIED
Foojan PHP Weblog - Cross-Site Scripting via HTTP Referer Header
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.
by ali202
CVE-2005-2725 EXPLOITDB text VERIFIED
QNX RTOS 6.1.0 and 6.3 - Arbitrary File Read via inputtrap Utility
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.
by Julio Cesar Fort
EIP-2026-111908 EXPLOITDB text VERIFIED
SaveWebPortal 3.4 - Unauthorized Access
by rgod
EIP-2026-111907 EXPLOITDB text VERIFIED
SaveWebPortal 3.4 - Multiple Remote File Inclusions
by rgod
EIP-2026-111906 EXPLOITDB text VERIFIED
SaveWebPortal 3.4 - Multiple Directory Traversal Vulnerabilities
by rgod
EIP-2026-111905 EXPLOITDB text VERIFIED
SaveWebPortal 3.4 - Multiple Cross-Site Scripting Vulnerabilities
by rgod
EIP-2026-111161 EXPLOITDB text VERIFIED
PHPMyFAQ 1.5.1 - Logs Unauthorized Access
by rgod
EIP-2026-111160 EXPLOITDB text VERIFIED
PHPMyFAQ 1.5.1 - Local File Inclusion
by rgod
EIP-2026-111159 EXPLOITDB text VERIFIED
PHPMyFAQ 1.5.1 - 'Password.php' SQL Injection
by retrogod@aliceposta.it
EIP-2026-111826 EXPLOITDB text VERIFIED
RunCMS 1.1/1.2 Module Newbb_plus/Messages - SQL Injection
by GulfTech Security
CVE-2005-2689 EXPLOITDB text VERIFIED
PostNuke 0.760-RC4b - Cross-Site Scripting via Comments Moderate Parameter or User HTML Text
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
by Maksymilian Arciemowicz
CVE-2005-2689 EXPLOITDB text VERIFIED
PostNuke 0.760-RC4b - Cross-Site Scripting via Comments Moderate Parameter or User HTML Text
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
by Maksymilian Arciemowicz