Exploitdb Exploits
31,394 exploits tracked across all sources.
YaPiG 0.92b, 0.93u, 0.94u - Directory Traversal via dir Parameter in upload.php
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.
by anonymous
Rakkarsoft RakNet < 2.33 - Denial of Service via Zero-Byte UDP Packet
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.
by Luigi Auriemma
WWWeb Concepts Events System 1.0 - 'login.asp' SQL Injection
by Romty
ProductCart Ecommerce < 2.7 - SQL Injection via idcategory, lid, icd, or idccr Parameter
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
by Dedi Dwianto
ProductCart Ecommerce < 2.7 - SQL Injection via idcategory, lid, icd, or idccr Parameter
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
by Dedi Dwianto
ProductCart Ecommerce < 2.7 - SQL Injection via idcategory, lid, icd, or idccr Parameter
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
by Dedi Dwianto
ProductCart Ecommerce < 2.7 - SQL Injection via idcategory, lid, icd, or idccr Parameter
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
by Dedi Dwianto
Popper <= 1.41-r2 - Remote File Inclusion via childwindow.inc.php Form Parameter
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.
by Leon Juranic
MWChat 6.7 - 'Start_Lobby.php' Remote File Inclusion
by Status-x
Liberum Help Desk 0.97.3 - Multiple SQL Injections
by Dedi Dwianto
Microsoft Outlook Express 4.x/5.x/6.0 - Attachment Processing File Extension Obfuscation
by Benjamin Tobias Franz
HP OpenView Radia 2.0/3.1/4.0 - Notify Daemon Multiple Remote Buffer Overflow Vulnerabilities
by John Cartwright
Livingcolor Livingmailing 1.3 - 'login.asp' SQL Injection
by Dj romty
JiRo's Upload System 1.0 - 'login.asp' SQL Injection
by Romty
DUware DUclassmate 1.2 - SQL Injection via iState or iPro Parameter
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
by Dedi Dwianto
DUware DUclassmate 1.2 - SQL Injection via iState or iPro Parameter
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
by Dedi Dwianto
PowerDownload <3.0.3 - Code Injection
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.
by SoulBlack Group
MyBulletinBoard (MyBB) RC4 - Multiple Cross-Site Scripting / SQL Injections
by Alberto Trivero
Calendarix 0.8.20071118 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities
by DarkBicho
Qualiteam X-Cart 4.0.8 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.
by CENSORED Search Vulnerabilities
Qualiteam X-Cart 4.0.8 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.
by CENSORED Search Vulnerabilities
By Source