Exploitdb Exploits
31,394 exploits tracked across all sources.
Nokia 9500 - Denial of Service via vCard Name Field
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.
by Marek Bialoglowy
MaxWebPortal 1.35, 1.36, 2.0, 20050418 Next - SQL Injection via memKey Parameter
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.
by Soroush Dalili
PHP Poll Creator 1.0.1 - 'Poll_Vote.php' Remote File Inclusion
by rash ilusion
FunkyASP AD Systems 1.1 - 'login.asp' SQL Injection
by Romty
Sambar Server 5.x/6.0/6.1 - Server Referer Cross-Site Scripting
by Jamie Fisher
Sambar Server 5.x/6.0/6.1 - logout RCredirect Cross-Site Scripting
by Jamie Fisher
Sambar Server 5.x/6.0/6.1 - 'results.stm' indexname Cross-Site Scripting
by Jamie Fisher
Blue Coat Reporter <7.1.2 - Privilege Escalation
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.
by Oliver Karow
Blue Coat Reporter < 7.1.1 - Unauthenticated License Addition
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.
by Oliver Karow
Halo: Combat Evolved 1.6 - Denial of Service via Malformed Data
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.
by Luigi Auriemma
HelpCenter Live! 1.0/1.2.x - Multiple Input Validation Vulnerabilities
by GulfTech Security
Gforge - Remote Code Execution via scm viewFile.php file_name Parameter
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.
by Filippo Spike Morelli
Apache Tomcat 5.0.16 - Unauthenticated Arbitrary File Read via JavaMail Download Parameter
JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.
by Ricky Latt
Spread The Word - Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
Warrior Kings < 1.3 and Warrior Kings: Battles < 1.23 - Remote Code Execution via Format String in Nickname
Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.
by Luigi Auriemma
Warrior Kings: Battles 1.23 - Denial of Service via Partial Join Packet
Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.
by Luigi Auriemma
MWChat 6.8 - SQL Injection via Username Parameter
SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter.
by rgod
phpMyAdmin - Cross-Site Scripting via left.php, queryframe.php, or server_databases.php
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.
by Tobias Klein
phpMyAdmin - Cross-Site Scripting via left.php, queryframe.php, or server_databases.php
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.
by Tobias Klein
cPanel <= 9.1 - Cross-Site Scripting via Login Page User Parameter
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.
by abducter_minds@yahoo.com
php_advanced_transfer_manager 1.21 - Remote File Inclusion via include_location Parameter
PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.
by Ingvar Gilbert
Sun JavaMail 1.3 - API MimeMessage Infromation Disclosure
by Ricky Latt
By Source