Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-2638 EXPLOITDB text VERIFIED
PHPFreeNews 1.40 - Cross-Site Scripting via NewsMode or Match Parameter
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php.
by h4cky
EIP-2026-112314 EXPLOITDB text VERIFIED
Soft4e ECW-Shop 6.0.2 - 'index.php' SQL Injection
by John Cobb
EIP-2026-112313 EXPLOITDB text VERIFIED
Soft4e ECW-Shop 6.0.2 - 'index.php' HTML Injection
by John Cobb
CVE-2005-2603 EXPLOITDB text VERIFIED
My Image Gallery 1.4.1 - Cross-Site Scripting via currDir or image Parameter
Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.
by anonymous
EIP-2026-106768 EXPLOITDB text VERIFIED
ECW Shop 6.0.2 - 'index.php' Cross-Site Scripting
by John Cobb
EIP-2026-100481 EXPLOITDB text VERIFIED
PersianBlog - 'Userslist.asp' SQL Injection
by trueend5
EIP-2026-100233 EXPLOITDB text VERIFIED
CPaint 1.3 - xmlhttp Request Input Validation
by Thor Larholm
CVE-2005-2523 EXPLOITDB text VERIFIED
Weblog Server 10.4-10.4.2 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
by Donnie Werner
CVE-2005-2508 EXPLOITDB text VERIFIED
Mac OS X 10.4.2 - Privilege Escalation
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
by Neil Archibald
CVE-2005-2644 EXPLOITDB text VERIFIED
JaguarEditControl.dll - Buffer Overflow
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.
by Tacettin Karadeniz
CVE-2005-2580 EXPLOITDB text VERIFIED
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
CVE-2005-2580 EXPLOITDB text VERIFIED
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
CVE-2005-2580 EXPLOITDB text VERIFIED
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
CVE-2005-2580 EXPLOITDB text VERIFIED
MyBulletinBoard 1.00 RC4 - SQL Injection via Username Field or Action Parameter
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.
by phuket
CVE-2005-2103 EXPLOITDB CRITICAL text VERIFIED
Gaim < 1.5.0 - Buffer Overflow via AIM/ICQ Away Message Substitution Strings
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.
by Brandon Perry
CVSS 9.8
EIP-2026-113039 EXPLOITDB text VERIFIED
VegaDNS 0.8.1/0.9.8/0.9.9 - 'index.php' Cross-Site Scripting
by dyn0
CVE-2005-2587 EXPLOITDB text VERIFIED
PHPTB Topic Boards 2.0 - SQL Injection via mid Parameter
SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
by abducter_minds@yahoo.com
CVE-2005-2616 EXPLOITDB text VERIFIED
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
CVE-2005-2616 EXPLOITDB text VERIFIED
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
CVE-2005-2616 EXPLOITDB text VERIFIED
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
CVE-2005-2616 EXPLOITDB text VERIFIED
ezUpload 2.2 - Remote Code Execution via Path Parameter File Include
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
by Johnnie Walker
EIP-2026-112796 EXPLOITDB text VERIFIED
TriggerTG TClanPortal 3.0 - Multiple SQL Injections
by admin@batznet.com
EIP-2026-112536 EXPLOITDB text VERIFIED
SysCP 1.2.x - Multiple Script Execution Vulnerabilities
by Christopher Kunz
CVE-2007-3627 EXPLOITDB text VERIFIED
PHP Lite Calendar Express 2.2 - SQL Injection via cid Parameter
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
CVE-2007-3627 EXPLOITDB text VERIFIED
PHP Lite Calendar Express 2.2 - SQL Injection via cid Parameter
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster