Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3627 EXPLOITDB text VERIFIED
PHP Lite Calendar Express 2.2 - SQL Injection via cid Parameter
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
CVE-2005-2562 EXPLOITDB text VERIFIED
Gravity Board X 1.1 - SQL Injection via Login Field
SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.
by rgod
EIP-2026-107486 EXPLOITDB text VERIFIED
Gravity Board X 1.1 - CSS Template Unauthorized Access
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
CVE-2005-2569 EXPLOITDB text VERIFIED
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
by rgod
EIP-2026-105832 EXPLOITDB text VERIFIED
Chipmunk CMS 1.3 - Fontcolor Cross-Site Scripting
by rgod
EIP-2026-105691 EXPLOITDB text VERIFIED
Calendar Express 2.2 - 'search.php' Cross-Site Scripting
by almaster
CVE-2005-2588 EXPLOITDB text VERIFIED
DVBBS 7.1 SP2 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to dispuser.asp, or the (3) title, (4) view, or (5) act parameter to boardhelp.asp.
by Lostmon
CVE-2005-2588 EXPLOITDB text VERIFIED
DVBBS 7.1 SP2 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to dispuser.asp, or the (3) title, (4) view, or (5) act parameter to boardhelp.asp.
by Lostmon
CVE-2005-2588 EXPLOITDB text VERIFIED
DVBBS 7.1 SP2 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to dispuser.asp, or the (3) title, (4) view, or (5) act parameter to boardhelp.asp.
by Lostmon
CVE-2005-3159 EXPLOITDB text VERIFIED
PHP-Fusion - SQL Injection via msg_view Parameter
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
by almaster
EIP-2026-108064 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 petitionbook Script - User IP Disclosure
by Lostmon
EIP-2026-108063 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - suggestions.csv User IP Disclosure
by Lostmon
CVE-2005-4880 EXPLOITDB text VERIFIED
Jax Guestbook 3.1-3.31 - Info Disclosure
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
by Lostmon
EIP-2026-108062 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - jnl_records User Database Disclosure
by Lostmon
CVE-2005-4880 EXPLOITDB text VERIFIED
Jax Guestbook 3.1-3.31 - Info Disclosure
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
by Lostmon
EIP-2026-108061 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - ips2block Banned IP Disclosure
by Lostmon
CVE-2005-4880 EXPLOITDB text VERIFIED
Jax Guestbook 3.1-3.31 - Info Disclosure
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
by Lostmon
CVE-2005-4880 EXPLOITDB text VERIFIED
Jax Guestbook 3.1-3.31 - Info Disclosure
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
by Lostmon
EIP-2026-108060 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - formmailer.log User Sent Mail Disclosure
by Lostmon
EIP-2026-108059 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'sign_in.php?language' Cross-Site Scripting
by Lostmon