Exploitdb Exploits
31,394 exploits tracked across all sources.
PHPFreeNews 1.40 - Cross-Site Scripting via NewsMode or Match Parameter
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php.
by h4cky
Soft4e ECW-Shop 6.0.2 - 'index.php' SQL Injection
by John Cobb
Soft4e ECW-Shop 6.0.2 - 'index.php' HTML Injection
by John Cobb
My Image Gallery 1.4.1 - Cross-Site Scripting via currDir or image Parameter
Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.
by anonymous
ECW Shop 6.0.2 - 'index.php' Cross-Site Scripting
by John Cobb
CPaint 1.3 - xmlhttp Request Input Validation
by Thor Larholm
Weblog Server 10.4-10.4.2 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
by Donnie Werner
Mac OS X 10.4.2 - Privilege Escalation
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
by Neil Archibald
JaguarEditControl.dll - Buffer Overflow
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.
by Tacettin Karadeniz
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
Gaim < 1.5.0 - Buffer Overflow via AIM/ICQ Away Message Substitution Strings
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.
by Brandon Perry
CVSS 9.8
VegaDNS 0.8.1/0.9.8/0.9.9 - 'index.php' Cross-Site Scripting
by dyn0
PHPTB Topic Boards 2.0 - SQL Injection via mid Parameter
SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
by abducter_minds@yahoo.com
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
TriggerTG TClanPortal 3.0 - Multiple SQL Injections
by admin@batznet.com
SysCP 1.2.x - Multiple Script Execution Vulnerabilities
by Christopher Kunz
PHP Lite Calendar Express 2.2 - SQL Injection via cid Parameter
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
PHP Lite Calendar Express 2.2 - SQL Injection via cid Parameter
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
By Source