Exploitdb Exploits
31,394 exploits tracked across all sources.
OpenBB 1.0.8 - SQL Injection via TID Parameter
SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.
by Megasky
OpenBB 1.0.8 - Cross-Site Scripting via Reverse Parameter in Member List Action
Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.
by Megasky
APG Technology ClassMaster - Unauthorized Folder Access
by Alex Garrett
Quick.cart 0.3.0 - Cross-Site Scripting via sWord Parameter
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.
by Lostmon
neteyes nexusway border gateway - Multiple Vulnerabilities
by pokley
MaxWebPortal 1.3.5 - Cross-Site Scripting via post.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.
by Zinho
GeoVision Digital Video Surveillance System <7.0 - Info Disclosure
GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.
by Tirath Rai
WowBB Forum 1.61 - SQL Injection via view_user.php Parameters
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.
by Megasky
Tru-Zone NukeET 3.0-3.1 - Cross-Site Scripting via Base64 Encoded Codigo Parameter
Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.
by Suko & Lostmon
e107 Website System 0.617 - 'Request.php' Directory Traversal
by Heintz
e107 Website System 0.617 - 'Forum_viewforum.php' SQL Injection
by Heintz
H-Sphere Winbox <2.4.3 - Info Disclosure
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
by Morning Wood
orenosv_http_ftp_server < 0.8.1 - Authenticated Buffer Overflow via Long FTP Command Arguments
Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.
by Tan Chew Keong
AOL Instant Messenger <= 5.5.x - Denial of Service via Invalid Smiley Icon Location
AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.
by fjlj@wvi.com
PWSPHP 1.2 - Multiple Cross-Site Scripting Vulnerabilities
by SecuBox fRoGGz
PWSPHP 1.1/1.2 - 'Profil.php' SQL Injection
by SecuBox fRoGGz
PHP-Nuke 0-7 - Double Hex Encoded Input Validation
by fistfuxxer@gmx.de
CodeThat ShoppingCart 1.3.1 - SQL Injection via catalog.php id Parameter
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Lostmon
CodeThat ShoppingCart 1.3.1 - Cross-Site Scripting via catalog.php id Parameter
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by Lostmon
Advanced Guestbook 2.3.1 - SQL Injection
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
by Spy Hat
phpBB < 2.0.15 - Stored Cross-Site Scripting via BBcode URI Scheme Injection
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.
by Papados
Easy Message Board - Command Injection
easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.
by SoulBlack Group
By Source