Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107828 EXPLOITDB text VERIFIED
India Software Solution Shopping Cart - SQL Injection
by Rayden
CVE-2005-1807 EXPLOITDB text VERIFIED
PHPMailer < 1.72 - Denial of Service via Long Header Field
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.
by Mariano Nunez Di Croce
EIP-2026-103467 EXPLOITDB text VERIFIED
Firefly Studios Stronghold 2 - Remote Denial of Service
by Luigi Auriemma
CVE-2005-1805 EXPLOITDB text VERIFIED
Online Solutions for Educators - SQL Injection via login.asp Password Parameter
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.
by Dj romty
CVE-2005-1788 EXPLOITDB text VERIFIED
Hosting Controller 6.1 Hotfix 2.0 - SQL Injection via jresourceid Parameter
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
by GrayHatz Security Group
CVE-2005-1788 EXPLOITDB text VERIFIED
Hosting Controller 6.1 Hotfix 2.0 - SQL Injection via jresourceid Parameter
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
by GrayHatz Security Group
CVE-2005-1800 EXPLOITDB text VERIFIED
Clam Anti-virus Clamav - XSS
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.
by Nah
CVE-2005-1598 EXPLOITDB text VERIFIED
Invision Power Board <= 2.0.3 - SQL Injection via Cookie Password Hash
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.
by Danica Jones
EIP-2026-102462 EXPLOITDB text VERIFIED
BEA WebLogic 7.0/8.1 - Administration Console LoginForm.jsp Cross-Site Scripting
by Team SHATTER
EIP-2026-102461 EXPLOITDB text VERIFIED
BEA WebLogic 7.0/8.1 - Administration Console Error Page Cross-Site Scripting
by Team SHATTER
CVE-2005-1784 EXPLOITDB text VERIFIED
Hosting Controller <6.1.2.0 - Info Disclosure
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
by Soroush Dalili
EIP-2026-115789 EXPLOITDB text VERIFIED
Microsoft Windows 98SE - 'User32.dll' Icon Handling Denial of Service
by klistas
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
CVE-2005-1782 EXPLOITDB text VERIFIED
BookReview beta 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
by Lostmon
EIP-2026-103883 EXPLOITDB text VERIFIED
Clever's Games Terminator 3: War of the Machines 1.16 Server - Remote Buffer Overflow
by Luigi Auriemma
EIP-2026-103878 EXPLOITDB text VERIFIED
C'Nedra 0.4 Network Plugin - 'Read_TCP_String' Remote Buffer Overflow
by Luigi Auriemma
CVE-2004-2135 EXPLOITDB text VERIFIED
Linux kernel <2.6 - Info Disclosure
cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.
by Markku-Juhani O. Saarinen
EIP-2026-101083 EXPLOITDB text VERIFIED
Sony Ericsson P900 Beamer - Malformed File Name Handling Denial of Service
by Marek Bialoglowy