Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108058 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'shrimp_petition.php' Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
EIP-2026-108057 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'jax_newsletter.php?language' Cross-Site Scripting
by Lostmon
CVE-2008-6562 EXPLOITDB text VERIFIED
Jax LinkLists 1.00 - Cross-Site Scripting via cat Parameter
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Lostmon
EIP-2026-108056 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'jax_guestbook.php' Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
EIP-2026-108055 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'jax_calendar.php' Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
EIP-2026-108054 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'dwt_editor.php' Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
EIP-2026-108053 EXPLOITDB text VERIFIED
Jax PHP Scripts 1.0/1.34/2.14/3.31 - 'archive.php?language' Cross-Site Scripting
by Lostmon
CVE-2005-2539 EXPLOITDB text VERIFIED
FlatNuke 2.5.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
by rgod
CVE-2005-2539 EXPLOITDB text VERIFIED
FlatNuke 2.5.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
by rgod
CVE-2005-2543 EXPLOITDB text VERIFIED
Comdev eCommerce 3.0 - Directory Traversal via wce.download.php Download Parameter
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.
by anonymous
EIP-2026-106069 EXPLOITDB text VERIFIED
Comdev eCommerce 3.0 - 'config.php' Remote File Inclusion
by anonymous
CVE-2005-2357 EXPLOITDB text VERIFIED
EMC Navisphere Manager 6.4.1.0.0 - Directory Traversal via URL
Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
by anonymous
CVE-2005-2486 EXPLOITDB text VERIFIED
PortailPHP - SQL Injection via id Parameter
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.
by abducter_minds@yahoo.com
CVE-2005-2453 EXPLOITDB text VERIFIED
NetworkActiv Web Server - Cross-Site Scripting via Query String
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.
by Secunia Research
CVE-2005-2488 EXPLOITDB text VERIFIED
Web Content Management News System - Cross-Site Scripting via strRootpath or strTable Parameter
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
by rgod
CVE-2005-2488 EXPLOITDB text VERIFIED
Web Content Management News System - Cross-Site Scripting via strRootpath or strTable Parameter
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
by rgod
CVE-2005-2480 EXPLOITDB text VERIFIED
ColdFusion Fusebox 4.1.0 - Cross-Site Scripting via Fuseaction Parameter
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.
by N.N.P
EIP-2026-100452 EXPLOITDB text VERIFIED
Naxtor E-directory 1.0 - 'Message.asp' Cross-Site Scripting
by basher13
EIP-2026-100451 EXPLOITDB text VERIFIED
Naxtor E-directory 1.0 - 'default.asp' SQL Injection
by basher13
EIP-2026-109844 EXPLOITDB text VERIFIED
Naxtor Shopping Cart 1.0 - 'Shop_Display_Products.php' SQL Injection
by John Cobb
CVE-2005-2476 EXPLOITDB text VERIFIED
Naxtor Shopping Cart 1.0 - Cross-Site Scripting via lost_password.php Email Parameter
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
by John Cobb
EIP-2026-111059 EXPLOITDB text VERIFIED
PHPFreeNews 1.x - Multiple Cross-Site Scripting Vulnerabilities
by rgod
EIP-2026-111058 EXPLOITDB text VERIFIED
PHPFreeNews 1.x - Admin Login SQL Injection
by rgod
CVE-2005-2466 EXPLOITDB text VERIFIED
OpenBook 1.2.2 - SQL Injection via Username or Password Parameter
Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
by SVT
CVE-2005-2467 EXPLOITDB text VERIFIED
MySQL Eventum <= 1.5.5 - Cross-Site Scripting via id, release, or F Parameter
Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.
by GulfTech Security