Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-6587 EXPLOITDB text VERIFIED
Myrephp Myre Vacation Rental - XSS
Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arbitrary web script or HTML via the link_idd parameter in a login action.
by d3b4g
CVE-2012-6589 EXPLOITDB text VERIFIED
Myrephp Myre Business Directory - XSS
Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter.
by d3b4g
CVE-2012-6585 EXPLOITDB text VERIFIED
Myrephp Myre Realty Manager - XSS
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.
by d3b4g
EIP-2026-107257 EXPLOITDB text VERIFIED
friendsinwar FAQ Manager - SQL Injection / Authentication Bypass
by d3b4g
CVE-2006-0755 EXPLOITDB MEDIUM text VERIFIED
dotProject <2.0.1 - RCE
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product
by dun
CVSS 5.6
EIP-2026-116664 EXPLOITDB text VERIFIED
Zoner Photo Studio 15 b3 - Buffer Overflow (PoC)
by Vulnerability-Lab
EIP-2026-115772 EXPLOITDB text VERIFIED
Microsoft Visio 2010 - Crash (PoC)
by coolkaveh
CVE-2009-5022 EXPLOITDB text VERIFIED
Libtiff < 3.9.4 - Memory Corruption
Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.
by Francis Provencher
EIP-2026-115461 EXPLOITDB text VERIFIED
IrfanView - '.RLE' Image Decompression Buffer Overflow
by Francis Provencher
EIP-2026-106939 EXPLOITDB text VERIFIED
Eventy CMS 1.8 Plus - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-115762 EXPLOITDB text VERIFIED
Microsoft Publisher 2013 - Crash (PoC)
by coolkaveh
EIP-2026-105385 EXPLOITDB text
Bananadance Wiki b2.2 - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-115654 EXPLOITDB text VERIFIED
Microsoft Excel 2007 - WriteAV Crash (PoC)
by coolkaveh
EIP-2026-114334 EXPLOITDB text VERIFIED
WordPress Theme Kakao - 'ID' SQL Injection
by sil3nt
EIP-2026-113957 EXPLOITDB text VERIFIED
WordPress Plugin PHP Event Calendar - 'cid' SQL Injection
by Ashiyane Digital Security Team
EIP-2026-113714 EXPLOITDB text VERIFIED
WordPress Plugin Eco-annu - 'eid' SQL Injection
by Ashiyane Digital Security Team
EIP-2026-109884 EXPLOITDB text VERIFIED
NetOffice Dwins 1.4p3 - SQL Injection
by dun
CVE-2012-4949 EXPLOITDB text VERIFIED
ESRI ArcGIS 10.1 - SQL Injection
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
by anonymous
CVE-2012-2437 EXPLOITDB text VERIFIED
AWCM 2.2 - XSS
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
by Sooel Son
EIP-2026-114434 EXPLOITDB text VERIFIED
Xivo 1.2 - Arbitrary File Download
by Mr.Un1k0d3r
EIP-2026-113760 EXPLOITDB text VERIFIED
WordPress Plugin FLV Player - 'id' SQL Injection
by Ashiyane Digital Security Team
CVE-2012-5367 EXPLOITDB text VERIFIED
OrangeHRM 2.7.1 RC 1 - SQL Injection
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCustomers, (2) viewPayGrades, or (3) viewSystemUsers in symfony/web/index.php/admin/, as demonstrated using cross-site request forgery (CSRF) attacks.
by High-Tech Bridge
CVE-2013-4103 EXPLOITDB CRITICAL text VERIFIED
Cryptocat < 2.0.22 - Improper Input Validation
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
by Mario Heiderich
CVSS 9.8
CVE-2013-2261 EXPLOITDB HIGH text VERIFIED
Cryptocat < 2.0.22 - Information Disclosure
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
by Mario Heiderich
CVSS 7.5
EIP-2026-101545 EXPLOITDB text
AVerCaster Pro RS3400 Web Server - Directory Traversal
by Patrick Saladino