Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-1718 EXPLOITDB text VERIFIED
LS Games War Times 1.03 - Denial of Service via Long Nickname
Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.
by Luigi Auriemma
EIP-2026-113488 EXPLOITDB text VERIFIED
WordPress Core 1.5 - 'post.php' Cross-Site Scripting
by Thomas Waldegger
EIP-2026-112023 EXPLOITDB text VERIFIED
Shop-Script - ProductID SQL Injection
by CENSORED Search Vulnerabilities
EIP-2026-112022 EXPLOITDB text VERIFIED
Shop-Script - categoryId SQL Injection
by CENSORED Search Vulnerabilities
EIP-2026-111433 EXPLOITDB text VERIFIED
PostNuke 0.75/0.76 Blocks Module - Directory Traversal
by pokley
CVE-2005-1637 EXPLOITDB text VERIFIED
NPDS 4.8 and 5.0 - SQL Injection via thold Parameter
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.
by NoSP
CVE-2005-1637 EXPLOITDB text VERIFIED
NPDS 4.8 and 5.0 - SQL Injection via thold Parameter
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.
by NoSP
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1633 EXPLOITDB text VERIFIED
JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
by deluxe@security-project.org
CVE-2005-1365 EXPLOITDB text VERIFIED
Pico Server <3.2 - Command Injection
Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.
by Claus R. F. Overbeck
EIP-2026-100893 EXPLOITDB text VERIFIED
Sigma ISP Manager 6.6 - 'Sigmaweb.dll' SQL Injection
by mehran gashtasebi
CVE-2005-1366 EXPLOITDB text VERIFIED
pico_server <= 3.2 - Unauthenticated Arbitrary File Read via CGI Script Path Traversal
Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.
by Claus R. F. Overbeck
EIP-2026-100423 EXPLOITDB text VERIFIED
MetaCart E-Shop - 'ProductsByCategory.asp' Cross-Site Scripting
by Dedi Dwianto
EIP-2026-109562 EXPLOITDB text VERIFIED
MonoChat 1.0 - HTML Injection
by X-BOY
CVE-2005-1620 EXPLOITDB text VERIFIED
Skull-Splitter Guestbook 1.0, 2.0, 2.2 - Stored Cross-Site Scripting via Message Title or Content
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
by Morinex Eneco
CVE-2005-1618 EXPLOITDB text VERIFIED
Yahoo Messenger 5.x-6.0 - Denial of Service via Malformed Room Request Packet
The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.
by Torseq Tech
CVE-2005-1615 EXPLOITDB text VERIFIED
Ultimate PHP Board 1.8-1.9.6 - SQL Injection via postorder Parameter
viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.
by Morinex Eneco
CVE-2005-1614 EXPLOITDB text VERIFIED
Ultimate PHP Board 1.8-1.9.6 - Cross-Site Scripting via viewforum.php postorder Parameter
Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.
by Morinex Eneco
CVE-2005-1619 EXPLOITDB text VERIFIED
PHPMyChat 0.14.5 - Cross-Site Scripting via FontName Parameter
Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.
by Megasky
CVE-2005-1619 EXPLOITDB text VERIFIED
PHPMyChat 0.14.5 - Cross-Site Scripting via FontName Parameter
Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.
by Megasky