Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112419 EXPLOITDB text
StaMPi - Local File Inclusion
by e . V . E . L
CVE-2015-1518 EXPLOITDB text
Redaxscript <2.3.0 - SQL Injection
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
by ITAS Team
CVE-2015-1467 EXPLOITDB text
Fork CMS <3.8.6 - SQL Injection
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.
by Sven Schleier
EIP-2026-105810 EXPLOITDB text
Chamilo LMS 1.9.8 - Blind SQL Injection
by Kacper Szurek
CVE-2014-7864 EXPLOITDB text
Zohocorp Manageengine Opmanager - SQL Injection
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
by Pedro Ribeiro
EIP-2026-102572 EXPLOITDB text
Chemtool 1.6.14 - Memory Corruption
by Pablo González
CVE-2015-2067 EXPLOITDB text
Magmi - Path Traversal
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by SECUPENT
CVE-2015-2068 EXPLOITDB text
Magmi < 0.7.22 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
by SECUPENT
CVE-2015-1471 EXPLOITDB text
Pragyan CMS 3.0 - SQL Injection
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
by Steffen Rösemann
CVE-2014-7883 EXPLOITDB text VERIFIED
HP Universal Configuration Management... - Information Disclosure
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
by Hans-Martin Muench
CVE-2015-1428 EXPLOITDB text
Sefrengo <1.6.2 - SQL Injection
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL commands via the sefrengo cookie in a login to backend/main.php or (2) remote authenticated users to execute arbitrary SQL commands via the value_id parameter in a save_value action to backend/main.php.
by ITAS Team
CVE-2014-7288 EXPLOITDB text VERIFIED
Symantec PGP Universal Server & Encryption Management Server <3.3.2...
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
by Paul Craig
CVE-2014-8826 EXPLOITDB text
Apple OS X <10.10.2 - Info Disclosure
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.
by Amplia Security Research
CVE-2012-4891 EXPLOITDB text
ManageEngine Firewall Analyzer 7.2 - XSS
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Ertebat Gostar Co
CVE-2014-8612 EXPLOITDB text VERIFIED
Freebsd - Access Control
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel memory via the stream id to the getsockopt function, when getting the SCTP_SS_PRIORITY option.
by Core Security
CVE-2015-1477 EXPLOITDB text
CMSJunkie J-ClassifiedsManager - SQL Injection
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads.
by Sarath Nair
CVE-2014-9598 EXPLOITDB text
VideoLAN VLC media player <2.1.5 - RCE
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.
by Veysel HATAS
CVE-2014-9597 EXPLOITDB text
VideoLAN VLC media player <2.1.5 - RCE
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
by Veysel HATAS
EIP-2026-110790 EXPLOITDB text
PHP Webquest 2.6 - SQL Injection
by jordan root
EIP-2026-109312 EXPLOITDB text
Mangallam CMS - SQL Injection
by Vulnerability-Lab
CVE-2015-1374 EXPLOITDB text VERIFIED
ferretCMS 1.0.4-alpha - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3) unrestricted file upload attacks.
by Steffen Rösemann
CVE-2014-9226 EXPLOITDB text
Symantec SCSP <5.2.9, SDCS:SA <6.0 MP1 - Auth Bypass
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.
by SEC Consult
EIP-2026-104459 EXPLOITDB text
SWFupload 2.5.0 - Cross Frame Scripting (XFS)
by MindCracker
CVE-2015-1478 EXPLOITDB text
Joomla! - XSS
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds.
by Sarath Nair
CVE-2015-1480 EXPLOITDB text
ZOHO ManageEngine ServiceDesk Plus <9.0 build 9031 - Info Disclosure
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.
by Rewterz - Research Group