Exploitdb Exploits
31,394 exploits tracked across all sources.
e107 Website System 0.6 - Nested BBCode URL Tag Script Injection
by Nick Griffin
Hosting Controller 6.1 HotFix 2.2 - Add Domain without Quota
by Soroush Dalili
Winamp < 5.093 - Buffer Overflow via Long ID3v2 Tag
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.
by Leon Juranic
Microsoft Internet Explorer - Denial of Service via Crafted JPEG Images
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
by Michal Zalewski
Internet Explorer <6.0 - RCE
Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".
by Michal Zalewski
Microsoft Internet Explorer / MSN - ICC Profiles Crash (PoC)
by Edward Gagnon
Clever Copy 2.0 and 2.0a - Cross-Site Scripting via calendar.php yr Parameter
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.
by Lostmon
Novell Groupwise WebAccess 6.5 - Cross-Site Scripting via Encoded JavaScript URI in Email
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag.
by Francisco Amato
e107 <= 0.617 - Cross-Site Scripting via Nested URL BBCode Tags
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.
by warlord
Simple Message Board 2.0 beta1 - 'User.cfm' Cross-Site Scripting
by rUnViRuS
Simple Message Board 2.0 beta1 - 'Thread.cfm' Cross-Site Scripting
by rUnViRuS
Simple Message Board 2.0 beta1 - 'Search.cfm' Cross-Site Scripting
by rUnViRuS
Simple Message Board 2.0 beta1 - 'Forum.cfm' Cross-Site Scripting
by rUnViRuS
phpBB 2.0.16 - Cross-Site Scripting Remote Cookie Disclosure (Cookie Grabber)
by Sjaak Rake
Hosting Controller 6.1 - Multiple SQL Injections
by Soroush Dalili
Nokia Affix <3.2.0 - Command Injection
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
by Kevin Finisterre
Cisco CallManager DoS via Crafted Packets
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe).
by Jeff Fay
DVBBS 7.1 SP2 - Cross-Site Scripting via showerr.asp Action Parameter
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
by rUnViRuS
Dragonfly Commerce 1.0 - Multiple SQL Injections
by Diabolic Crab
Blog Torrent <0.92 - Info Disclosure
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.
by LazyCrs
Hosting Controller 6.1 - Privilege Escalation
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
by Soroush Dalili
PPA web photo gallery 0.5.6 - Remote File Inclusion via config[ppa_root_path]
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
by skdaemon porra
ID Team ID Board 1.1.3 - 'SQL.CLS.php' SQL Injection
by Defa
PunBB 1.x - 'profile.php' User Profile Edit Module SQL Injection
by Stefan Esser
By Source