Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-18382 EXPLOITDB HIGH text
Advanced HRM 1.6 - Remote Code Execution via User Avatar Upload
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
by Renos Nikolaou
CVSS 8.8
CVE-2018-18323 EXPLOITDB HIGH text
Webpanel - Path Traversal
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.
by seccops
CVSS 7.5
CVE-2018-18322 EXPLOITDB CRITICAL text
Webpanel - OS Command Injection
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.
by seccops
CVSS 9.8
CVE-2018-18307 EXPLOITDB MEDIUM text
AlchemyCMS 4.1.0 - Stored Cross-Site Scripting via Admin Pictures Image Field
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized."
by Ismail Tasdelen
CVSS 6.1
CVE-2018-25139 EXPLOITDB HIGH text
FLIR AX8 Thermal Camera <1.32.16 - Info Disclosure
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
by LiquidWorm
CVSS 7.5
CVE-2018-25137 EXPLOITDB HIGH text
FLIR Brickstream 3D+ <2.1.742.1842 - Info Disclosure
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
by LiquidWorm
CVSS 7.5
CVE-2018-25136 EXPLOITDB HIGH text
FLIR Brickstream 3D+ <2.1.742.1842 - Info Disclosure
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can retrieve video stream images by directly accessing multiple image endpoints like middleImage.jpg, rightimage.jpg, and leftimage.jpg.
by LiquidWorm
CVSS 7.5
EIP-2026-109040 EXPLOITDB text
KORA 2.7.0 - 'cid' SQL Injection
by Ihsan Sencan
EIP-2026-106061 EXPLOITDB text
College Notes Management System 1.0 - 'user' SQL Injection
by Ihsan Sencan
CVE-2018-18324 EXPLOITDB MEDIUM text
Webpanel - Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.
by seccops
CVSS 6.1
EIP-2026-104897 EXPLOITDB text
Academic Timetable Final Build 7.0b - Cross-Site Request Forgery (Add Admin)
by Ihsan Sencan
EIP-2026-104896 EXPLOITDB text
Academic Timetable Final Build 7.0a-7.0b - 'id' SQL Injection
by Ihsan Sencan
EIP-2026-101735 EXPLOITDB text
FLIR AX8 Thermal Camera 1.32.16 - Arbitrary File Disclosure
by LiquidWorm
CVE-2018-25390 EXPLOITDB HIGH text
HaPe PKH 1.1 SQL Injection via desa Parameter
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.
by Ihsan Sencan
CVSS 8.2
CVE-2018-25389 EXPLOITDB HIGH text
HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.
by Ihsan Sencan
CVSS 8.2
CVE-2018-25388 EXPLOITDB HIGH text
HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
by Ihsan Sencan
CVSS 8.8
CVE-2018-25387 EXPLOITDB MEDIUM text
HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php
HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin credentials without authentication.
by Ihsan Sencan
CVSS 5.3
CVE-2018-25386 EXPLOITDB HIGH text
HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfasilitas, and act=editkelompok). Successful exploitation allows extraction of sensitive database information including the current user, database name, and DBMS version.
by Ihsan Sencan
CVSS 8.2
CVE-2018-25391 EXPLOITDB HIGH text
HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and admin/modul/mod_update/aksi_update.php (module=update&act=hapus) endpoints process deletions without verifying the requester's privileges, enabling removal of pengurus (administrator) and update records.
by Ihsan Sencan
CVSS 7.5
EIP-2026-114694 EXPLOITDB text
CAMALEON CMS 2.4 - Cross-Site Scripting
by Ismail Tasdelen
CVE-2018-17784 EXPLOITDB MEDIUM text
SugarCRM Community Edition 6.5.26 - XSS
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
by Purplemet Security
CVSS 6.1
EIP-2026-109228 EXPLOITDB text
LUYA CMS 1.0.12 - Cross-Site Scripting
by Ismail Tasdelen
CVE-2018-25385 EXPLOITDB HIGH text
E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data.
by Ihsan Sencan
CVSS 8.2
CVE-2018-25384 EXPLOITDB MEDIUM text
Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter
Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can post comments containing JavaScript code through the rpc.php endpoint that executes in other users' browsers when viewing forum replies.
by Amir Hossein Mahboubi
CVSS 5.4
CVE-2018-16210 EXPLOITDB MEDIUM text
WAGO 750-88X and 750-89X Ethernet Controller Devices < 01.09.18(13) - Stored Cross-Site Scripting via SNMP Configuration
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
by SecuNinja
CVSS 6.1