Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106681 EXPLOITDB text VERIFIED
e107 Website System 0.6 - Nested BBCode URL Tag Script Injection
by Nick Griffin
EIP-2026-100352 EXPLOITDB text VERIFIED
Hosting Controller 6.1 HotFix 2.2 - Add Domain without Quota
by Soroush Dalili
CVE-2005-2310 EXPLOITDB text VERIFIED
Winamp < 5.093 - Buffer Overflow via Long ID3v2 Tag
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.
by Leon Juranic
CVE-2005-2308 EXPLOITDB text VERIFIED
Microsoft Internet Explorer - Denial of Service via Crafted JPEG Images
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
by Michal Zalewski
CVE-2005-1988 EXPLOITDB text VERIFIED
Internet Explorer <6.0 - RCE
Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".
by Michal Zalewski
EIP-2026-115672 EXPLOITDB text VERIFIED
Microsoft Internet Explorer / MSN - ICC Profiles Crash (PoC)
by Edward Gagnon
CVE-2005-2326 EXPLOITDB text VERIFIED
Clever Copy 2.0 and 2.0a - Cross-Site Scripting via calendar.php yr Parameter
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.
by Lostmon
CVE-2005-2276 EXPLOITDB text VERIFIED
Novell Groupwise WebAccess 6.5 - Cross-Site Scripting via Encoded JavaScript URI in Email
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.
by Francisco Amato
CVE-2005-2327 EXPLOITDB text VERIFIED
e107 <= 0.617 - Cross-Site Scripting via Nested URL BBCode Tags
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.
by warlord
EIP-2026-100707 EXPLOITDB text VERIFIED
Simple Message Board 2.0 beta1 - 'User.cfm' Cross-Site Scripting
by rUnViRuS
EIP-2026-100706 EXPLOITDB text VERIFIED
Simple Message Board 2.0 beta1 - 'Thread.cfm' Cross-Site Scripting
by rUnViRuS
EIP-2026-100705 EXPLOITDB text VERIFIED
Simple Message Board 2.0 beta1 - 'Search.cfm' Cross-Site Scripting
by rUnViRuS
EIP-2026-100704 EXPLOITDB text VERIFIED
Simple Message Board 2.0 beta1 - 'Forum.cfm' Cross-Site Scripting
by rUnViRuS
EIP-2026-110951 EXPLOITDB text VERIFIED
phpBB 2.0.16 - Cross-Site Scripting Remote Cookie Disclosure (Cookie Grabber)
by Sjaak Rake
EIP-2026-100350 EXPLOITDB text VERIFIED
Hosting Controller 6.1 - Multiple SQL Injections
by Soroush Dalili
CVE-2005-2277 EXPLOITDB text VERIFIED
Nokia Affix <3.2.0 - Command Injection
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
by Kevin Finisterre
CVE-2005-2242 EXPLOITDB text VERIFIED
Cisco CallManager DoS via Crafted Packets
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe).
by Jeff Fay
CVE-2005-2318 EXPLOITDB text VERIFIED
DVBBS 7.1 SP2 - Cross-Site Scripting via showerr.asp Action Parameter
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
by rUnViRuS
EIP-2026-100282 EXPLOITDB text VERIFIED
Dragonfly Commerce 1.0 - Multiple SQL Injections
by Diabolic Crab
EIP-2026-112385 EXPLOITDB text VERIFIED
Spid 1.3 - 'lang_path' File Inclusion
by skdaemon porra
CVE-2005-2229 EXPLOITDB text VERIFIED
Blog Torrent <0.92 - Info Disclosure
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.
by LazyCrs
CVE-2005-2219 EXPLOITDB text VERIFIED
Hosting Controller 6.1 - Privilege Escalation
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
by Soroush Dalili
CVE-2005-2199 EXPLOITDB text VERIFIED
PPA web photo gallery 0.5.6 - Remote File Inclusion via config[ppa_root_path]
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
by skdaemon porra
EIP-2026-107752 EXPLOITDB text VERIFIED
ID Team ID Board 1.1.3 - 'SQL.CLS.php' SQL Injection
by Defa
EIP-2026-111585 EXPLOITDB text VERIFIED
PunBB 1.x - 'profile.php' User Profile Edit Module SQL Injection
by Stefan Esser