Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-1612 EXPLOITDB text VERIFIED
OpenBB 1.0.8 - SQL Injection via TID Parameter
SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.
by Megasky
CVE-2005-1613 EXPLOITDB text VERIFIED
OpenBB 1.0.8 - Cross-Site Scripting via Reverse Parameter in Member List Action
Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.
by Megasky
EIP-2026-118271 EXPLOITDB text VERIFIED
APG Technology ClassMaster - Unauthorized Folder Access
by Alex Garrett
EIP-2026-106461 EXPLOITDB text VERIFIED
DirectTopics 2 - 'topic.php' SQL Injection
by Morinex Eneco
CVE-2005-1587 EXPLOITDB text VERIFIED
Quick.cart 0.3.0 - Cross-Site Scripting via sWord Parameter
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.
by Lostmon
EIP-2026-100725 EXPLOITDB text VERIFIED
neteyes nexusway border gateway - Multiple Vulnerabilities
by pokley
CVE-2005-1561 EXPLOITDB text VERIFIED
MaxWebPortal 1.3.5 - Cross-Site Scripting via post.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.
by Zinho
EIP-2026-118937 EXPLOITDB text VERIFIED
MyServer 0.8 - Cross-Site Scripting
by dr_insane
CVE-2005-1552 EXPLOITDB text VERIFIED
GeoVision Digital Video Surveillance System <7.0 - Info Disclosure
GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.
by Tirath Rai
CVE-2004-2181 EXPLOITDB text VERIFIED
WowBB Forum 1.61 - SQL Injection via view_user.php Parameters
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.
by Megasky
CVE-2005-1610 EXPLOITDB text VERIFIED
Tru-Zone NukeET 3.0-3.1 - Cross-Site Scripting via Base64 Encoded Codigo Parameter
Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.
by Suko & Lostmon
EIP-2026-106683 EXPLOITDB text VERIFIED
e107 Website System 0.617 - 'Request.php' Directory Traversal
by Heintz
EIP-2026-106682 EXPLOITDB text VERIFIED
e107 Website System 0.617 - 'Forum_viewforum.php' SQL Injection
by Heintz
CVE-2005-1606 EXPLOITDB text VERIFIED
H-Sphere Winbox <2.4.3 - Info Disclosure
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
by Morning Wood
CVE-2005-1666 EXPLOITDB text VERIFIED
orenosv_http_ftp_server < 0.8.1 - Authenticated Buffer Overflow via Long FTP Command Arguments
Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.
by Tan Chew Keong
CVE-2005-1655 EXPLOITDB text VERIFIED
AOL Instant Messenger <= 5.5.x - Denial of Service via Invalid Smiley Icon Location
AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.
by fjlj@wvi.com
EIP-2026-111600 EXPLOITDB text VERIFIED
PWSPHP 1.2 - Multiple Cross-Site Scripting Vulnerabilities
by SecuBox fRoGGz
EIP-2026-111599 EXPLOITDB text VERIFIED
PWSPHP 1.1/1.2 - 'Profil.php' SQL Injection
by SecuBox fRoGGz
EIP-2026-110832 EXPLOITDB text VERIFIED
PHP-Nuke 0-7 - Double Hex Encoded Input Validation
by fistfuxxer@gmx.de
CVE-2005-1594 EXPLOITDB text VERIFIED
CodeThat ShoppingCart 1.3.1 - SQL Injection via catalog.php id Parameter
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Lostmon
CVE-2005-1593 EXPLOITDB text VERIFIED
CodeThat ShoppingCart 1.3.1 - Cross-Site Scripting via catalog.php id Parameter
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by Lostmon
CVE-2005-1548 EXPLOITDB text VERIFIED
Advanced Guestbook 2.3.1 - SQL Injection
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
by Spy Hat
CVE-2005-1193 EXPLOITDB text VERIFIED
phpBB < 2.0.15 - Stored Cross-Site Scripting via BBcode URI Scheme Injection
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.
by Papados
CVE-2005-1550 EXPLOITDB text VERIFIED
Easy Message Board - Command Injection
easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.
by SoulBlack Group
EIP-2026-100791 EXPLOITDB text VERIFIED
Easy Message Board - Directory Traversal
by SoulBlack Group