Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-2155 EXPLOITDB text VERIFIED
EasyPHPCalendar 6.1.5 - Remote File Inclusion via serverPath Parameter
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
by Albania Security Clan
CVE-2005-2154 EXPLOITDB text VERIFIED
osTicket <1.3.1 - Local File Inclusion
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.
by edisan & foster
CVE-2005-2140 EXPLOITDB text VERIFIED
FSboard 2.0 - Directory Traversal via Filename Parameter
Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.
by ActualMInd
CVE-2003-0509 EXPLOITDB text VERIFIED
Cyberstrong eShop <4.2 - SQL Injection
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
by aresu@bosen.net
CVE-2003-0509 EXPLOITDB text VERIFIED
Cyberstrong eShop <4.2 - SQL Injection
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
by aresu@bosen.net
EIP-2026-100235 EXPLOITDB text VERIFIED
CyberStrong EShop 4.2 - '10browse.asp' SQL Injection
by aresu@bosen.net
EIP-2026-116155 EXPLOITDB text VERIFIED
Raven Software Soldier Of Fortune 2 - Ignore Command Remote Denial of Service
by Luigi Auriemma
EIP-2026-100769 EXPLOITDB text VERIFIED
CGI-Club imTRBBS 1.0 - Remote Command Execution
by blahplok
CVE-2005-2077 EXPLOITDB text VERIFIED
Hosting Controller - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
by Ashiyane Digital Security Team
EIP-2026-100289 EXPLOITDB text VERIFIED
Dynamic Biz Website Builder (QuickWeb) 1.0 - 'login.asp' SQL Injection
by basher13
EIP-2026-100227 EXPLOITDB text VERIFIED
Community Server Forums - 'SearchResults.aspx' Cross-Site Scripting
by abducter_minds@yahoo.com
EIP-2026-109418 EXPLOITDB text VERIFIED
Mensajeitor 1.8.9 - 'IP' HTML Injection
by Megabyte
EIP-2026-100140 EXPLOITDB text VERIFIED
ASPPlayGround.NET 3.2 SR1 - Arbitrary File Upload
by Psycho
CVE-2005-2064 EXPLOITDB text VERIFIED
ASP Nuke 0.80 - Cross-Site Scripting via Multiple Registration Parameters
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.
by Alberto Trivero
CVE-2005-2065 EXPLOITDB text VERIFIED
ASP Nuke 0.80 - HTTP Response Splitting via LangCode Parameter
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.
by Alberto Trivero
CVE-2005-2064 EXPLOITDB text VERIFIED
ASP Nuke 0.80 - Cross-Site Scripting via Multiple Registration Parameters
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.
by Alberto Trivero
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
CVE-2005-2058 EXPLOITDB text VERIFIED
UBB.Threads - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.
by GulfTech Security
EIP-2026-113420 EXPLOITDB text VERIFIED
Whois.Cart 2.2.x - 'profile.php' Cross-Site Scripting
by Elzar Stuffenbach
EIP-2026-105750 EXPLOITDB text VERIFIED
CarLine Forum Russian Board 4.2 - IMG Tag Cross-Site Scripting
by 1dt.w0lf