Exploitdb Exploits
31,394 exploits tracked across all sources.
phpBB 2.0.16 - Cross-Site Scripting Remote Cookie Disclosure
by D|ablo
PhotoGal 1.0/1.5 - News_File Remote File Inclusion
by skdaemon porra
Elemental Software CartWIZ 1.20 - Multiple SQL Injections
by Diabolic Crab
Pngren 2.0.1 - 'Kaiseki.cgi' Remote Command Execution
by blahplok
Comersus Open Technologies Comersus Cart 6.0.41 - Multiple SQL Injections
by Diabolic Crab
Comersus Open Technologies Comersus Cart 6.0.41 - Multiple Cross-Site Scripting Vulnerabilities
by Diabolic Crab
Novell NetMail - Automatic HTML Processing in Attachments
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
by shalom@venera.com
phpWebSite 0.7.3/0.8.x/0.9.x - 'index.php' Directory Traversal
by Diabolic Crab
IBM Lotus Notes - Unauthenticated Cookie Theft via Automatic HTML Attachment Processing
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
by shalom@venera.com
GNU GNATS 4.0/4.1 - Gen-Index Arbitrary Local File Disclosure/Overwrite
by pi3ki31ny
oftpd 0.3.7 - Denial of Service via USER Command with Null Characters
oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.
by new.security@gmail.com
McAfee IntruShield Security Management System - Multiple Vulnerabilities
by c0ntex
phppgadmin 3.1-3.5.3 - Directory Traversal via Encoded Dot-Dot Sequences in formLanguage Parameter
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.
by rznvynqqe@hushmail.com
MyGuestbook 0.6.1 - Remote File Inclusion via Lang Parameter
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
by SoulBlack Group
AutoIndex PHP Script 1.5.2 - Cross-Site Scripting via Search Parameter
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
by mozako
GlobalNoteScript 4.20 - 'Read.cgi' Remote Command Execution
by AcidCrash
Plague News System 0.7 - 'delete.php' Access Restriction Bypass
by Easyex
Plague News System 0.7 - 'CID' Cross-Site Scripting
by Easyex
EasyPHPCalendar 6.1.5 - Remote File Inclusion via serverPath Parameter
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
by Albania Security Clan
EasyPHPCalendar 6.1.5 - Remote File Inclusion via serverPath Parameter
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
by Albania Security Clan
EasyPHPCalendar 6.1.5 - Remote File Inclusion via serverPath Parameter
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
by Albania Security Clan
EasyPHPCalendar 6.1.5 - Remote File Inclusion via serverPath Parameter
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
by Albania Security Clan
By Source