Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111494 EXPLOITDB text VERIFIED
PrestaShop - 'getSimilarManufacturer.php?id_manufacturer' SQL Injection
by indoushka
CVE-2014-3206 EXPLOITDB CRITICAL text
Seagate Blackarmor Nas 220 Firmware - Improper Input Validation
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
by Shayan S
CVSS 9.8
CVE-2014-3205 EXPLOITDB CRITICAL text
Seagate Blackarmor Nas 220 Firmware - Hard-coded Credentials
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
by Shayan S
CVSS 9.8
EIP-2026-106239 EXPLOITDB text VERIFIED
Crime24 Stealer Panel 1.0 - Multiple Vulnerabilities
by Daisuke Dan
EIP-2026-101862 EXPLOITDB text
Netgear DGN2200 1.0.0.29_1.7.29_HotS - Persistent Cross-Site Scripting
by Dolev Farhi
CVE-2014-9727 EXPLOITDB text
AVM Fritz!Box - RCE
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
by 0x4148
EIP-2026-109994 EXPLOITDB text
NULL NUKE CMS 2.2 - Multiple Vulnerabilities
by LiquidWorm
EIP-2026-102083 EXPLOITDB text
TRENDnet TEW-634GRU 1.00.23 - Multiple Vulnerabilities
by SirGod
CVE-2014-8948 EXPLOITDB text
iMember360 plugin <3.9.001 - CSRF
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.
by Everett Griffiths
CVE-2014-3849 EXPLOITDB text
Imember360 - Access Control
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
by Everett Griffiths
CVE-2014-3848 EXPLOITDB text
Imember360 < 3.9.000 - Access Control
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
by Everett Griffiths
CVE-2014-3842 EXPLOITDB text
Imember360 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.
by Everett Griffiths
CVE-2006-3823 EXPLOITDB text
Geodesicsolutions Geoauctions Premier - SQL Injection
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.
by Esac
CVE-2013-0140 EXPLOITDB text
Mcafee Epolicy Orchestrator < 4.5.6 - SQL Injection
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
by st3n
CVE-2014-8949 EXPLOITDB text
iMember360 plugin <3.9.001 - Command Injection
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.
by Everett Griffiths
CVE-2014-3871 EXPLOITDB text
Geodesicsolutions Geocore Max - SQL Injection
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.
by Esac
EIP-2026-104949 EXPLOITDB text
Adem 0.5.1 - Local File Inclusion
by JIKO
EIP-2026-105200 EXPLOITDB text VERIFIED
ApPHP MicroBlog 1.0.1 - Multiple Vulnerabilities
by JIKO
EIP-2026-115039 EXPLOITDB text
cFos Personal Net 3.09 - Remote Heap Memory Corruption (Denial of Service)
by LiquidWorm
CVE-2014-2347 EXPLOITDB text
Amtelco miSecureMessages <6.2 - Info Disclosure
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
by Jared Bird
EIP-2026-102885 EXPLOITDB text
JRuby Sandbox 0.2.2 - Sandbox Escape
by joernchen
EIP-2026-102223 EXPLOITDB text
Depot WiFi 1.0.0 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-114201 EXPLOITDB text VERIFIED
WordPress Plugin Work-The-Flow 1.2.1 - Arbitrary File Upload
by nopesled
CVE-2014-2846 EXPLOITDB text
Westerndigital Arkeia Virtual Appliance Firmware - Path Traversal
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.
by SEC Consult
CVE-2014-2383 EXPLOITDB text VERIFIED
dompdf <0.6.1 - Auth Bypass
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.
by Portcullis