Text Exploits
31,337 exploits tracked across all sources.
PrestaShop - 'getSimilarManufacturer.php?id_manufacturer' SQL Injection
by indoushka
Seagate Blackarmor Nas 220 Firmware - Improper Input Validation
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
by Shayan S
CVSS 9.8
Seagate Blackarmor Nas 220 Firmware - Hard-coded Credentials
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
by Shayan S
CVSS 9.8
Crime24 Stealer Panel 1.0 - Multiple Vulnerabilities
by Daisuke Dan
Netgear DGN2200 1.0.0.29_1.7.29_HotS - Persistent Cross-Site Scripting
by Dolev Farhi
AVM Fritz!Box - RCE
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
by 0x4148
iMember360 plugin <3.9.001 - CSRF
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.
by Everett Griffiths
Imember360 - Access Control
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
by Everett Griffiths
Imember360 < 3.9.000 - Access Control
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
by Everett Griffiths
Imember360 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.
by Everett Griffiths
Geodesicsolutions Geoauctions Premier - SQL Injection
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.
by Esac
Mcafee Epolicy Orchestrator < 4.5.6 - SQL Injection
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
by st3n
iMember360 plugin <3.9.001 - Command Injection
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.
by Everett Griffiths
Geodesicsolutions Geocore Max - SQL Injection
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.
by Esac
cFos Personal Net 3.09 - Remote Heap Memory Corruption (Denial of Service)
by LiquidWorm
Amtelco miSecureMessages <6.2 - Info Disclosure
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
by Jared Bird
WordPress Plugin Work-The-Flow 1.2.1 - Arbitrary File Upload
by nopesled
Westerndigital Arkeia Virtual Appliance Firmware - Path Traversal
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.
by SEC Consult
dompdf <0.6.1 - Auth Bypass
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.
by Portcullis
By Source