Exploitdb Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-25676 EXPLOITDB HIGH text
Ask Expert Script 3.0.5 Cross Site Scripting SQL Injection
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information.
by Mr Winst0n
CVSS 8.2
CVE-2019-25675 EXPLOITDB HIGH text
eDirectory All Versions SQL Injection Authentication Bypass
eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as administrator, then leverage authenticated file disclosure vulnerabilities in language_file.php to read arbitrary PHP files from the server.
by Efrén Díaz
CVSS 8.2
CVE-2019-15084 EXPLOITDB HIGH text
Waves Maxx Audio - Incorrect Permission Assignment
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
by Mike Siegel
CVSS 7.8
EIP-2026-114654 EXPLOITDB text
Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting
by Deyaa Muhammad
EIP-2026-109169 EXPLOITDB text
Listing Hub CMS 1.0 - 'pages.php id' SQL Injection
by Deyaa Muhammad
EIP-2026-107100 EXPLOITDB text
Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection
by Deyaa Muhammad
CVE-2019-1003002 EXPLOITDB HIGH text VERIFIED
Pipeline: Declarative Plugin <1.3.3 - RCE
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
by orange
CVSS 8.8
CVE-2019-25674 EXPLOITDB HIGH text
CMSsite 1.0 SQL Injection via post Parameter
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.
by Mr Winst0n
CVSS 8.2
CVE-2019-25430 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the username parameter. Attackers can send POST requests to the vpn_users endpoint with script payloads in the username field to execute arbitrary JavaScript in victim browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25429 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the openvpn_advanced endpoint. Attackers can inject JavaScript code through the GLOBAL_NETWORKS and GLOBAL_DNS parameters via POST requests to execute arbitrary scripts in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25428 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the openvpn_users endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted POST requests with script payloads in the username, remotenets, explicitroutes, static_ip, custom_dns, or custom_domain parameters to execute arbitrary JavaScript in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25427 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the antispyware endpoint. Attackers can send POST requests with JavaScript payloads in the DNSMASQ_WHITELIST or DNSMASQ_BLACKLIST parameters to execute arbitrary code in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25426 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the dnsmasq endpoint. Attackers can send POST requests with script payloads in the TRANSPARENT_SOURCE_BYPASS or TRANSPARENT_DESTINATION_BYPASS parameters to execute arbitrary JavaScript in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25425 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the VIRUS_ADMIN parameter. Attackers can send POST requests to the smtpconfig endpoint with script payloads to execute arbitrary JavaScript in the context of an administrator's browser session.
by Ozer Goker
CVSS 6.1
CVE-2019-25424 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the EXCEPTIONSITELIST parameter. Attackers can craft POST requests to the https_exceptions endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
by Ozer Goker
CVSS 6.1
CVE-2019-25423 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the /korugan/proxyconfig endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted POST requests with JavaScript payloads in parameters like PROXY_PORT, VISIBLE_HOSTNAME, ADMIN_MAIL_ADDRESS, CACHE_MEM, MAX_SIZE, MIN_SIZE, and DST_NOCACHE to execute arbitrary scripts in administrator browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25422 EXPLOITDB HIGH text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for stored XSS to execute arbitrary JavaScript in administrator browsers.
by Ozer Goker
CVSS 7.2
CVE-2019-25421 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application.
by Ozer Goker
CVSS 6.1
CVE-2019-25420 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the snat endpoint. Attackers can send POST requests with JavaScript payloads in the port or snat_to_ip parameters to execute arbitrary scripts in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25419 EXPLOITDB HIGH text
Comodo Dome Firewall 2.7.0 - Stored XSS
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.
by Ozer Goker
CVSS 7.2
CVE-2019-25418 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the FWADDRESSES parameter. Attackers can send POST requests to the /korugan/fwgroups endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
by Ozer Goker
CVSS 6.1
CVE-2019-25417 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the protocol parameter. Attackers can send POST requests to the QoS rules management endpoint with JavaScript payloads in the protocol parameter to execute arbitrary code in administrator browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25416 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input through the device parameter. Attackers can send POST requests to the QoS devices management endpoint with script payloads in the device parameter to execute arbitrary JavaScript in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25415 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the hotspot_permanent_users endpoint. Attackers can send POST requests with JavaScript payloads in the MACADDRESSES parameter to execute arbitrary scripts in users' browsers.
by Ozer Goker
CVSS 6.1
CVE-2019-25414 EXPLOITDB MEDIUM text
Comodo Dome Firewall 2.7.0 - XSS
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/appid/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.
by Ozer Goker
CVSS 6.1