Text Exploits

31,339 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107704 EXPLOITDB text
iauto mobile Application 2012 - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-106463 EXPLOITDB text VERIFIED
dirLIST 0.3.0 - Local File Inclusion
by L0n3ly-H34rT
EIP-2026-102364 EXPLOITDB text VERIFIED
ConcourseSuite - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
by Matthew Joyce
EIP-2026-119455 EXPLOITDB text
Zoho BugTracker - Multiple Persistent Cross-Site Scripting Vulnerabilities
by LiquidWorm
EIP-2026-119009 EXPLOITDB text VERIFIED
Oracle Business Transaction Management Server 12.1.0.2.7 FlashTunnelService - Remote File Deletion
by rgod
EIP-2026-119008 EXPLOITDB text VERIFIED
Oracle Business Transaction Management Server 12.1.0.2.7 - FlashTunnelService WriteToFile Message Remote Code Execution
by rgod
CVE-2012-4237 EXPLOITDB text VERIFIED
Tecnick Tcexam < 11.3.007 - SQL Injection
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.
by Chris Cooper
CVE-2012-4237 EXPLOITDB text VERIFIED
Tecnick Tcexam < 11.3.007 - SQL Injection
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.
by Chris Cooper
EIP-2026-107394 EXPLOITDB text VERIFIED
Getsimple CMS 3.1.2 - 'path' Local File Inclusion
by PuN!Sh3r
CVE-2012-4070 EXPLOITDB text VERIFIED
Dir2web - SQL Injection
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
by Daniel Correa
EIP-2026-114910 EXPLOITDB text VERIFIED
AOL Products downloadUpdater2 Plugin - 'SRC' Remote Code Execution
by rgod
EIP-2026-114555 EXPLOITDB text VERIFIED
YT-Videos Script - 'id' SQL Injection
by 3spi0n
EIP-2026-108481 EXPLOITDB text VERIFIED
Joomla! Component com_photo - Multiple SQL Injections
by Chokri Ben Achor
EIP-2026-104501 EXPLOITDB text VERIFIED
Worksforweb iAuto - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by Benjamin Kunz Mejri
EIP-2026-113716 EXPLOITDB text
WordPress Plugin Effective Lead Management 3.0.0 - Persistent Cross-Site Scripting
by Chris Kellum
EIP-2026-112674 EXPLOITDB text VERIFIED
Tickets CAD 2.20G - Multiple Vulnerabilities
by chap0
EIP-2026-107969 EXPLOITDB text
Islamnt Islam Forum Script 1.2 - Blind SQL Injection
by s3n4t00r
EIP-2026-100488 EXPLOITDB text VERIFIED
PolarisCMS - 'WebForm_OnSubmit()' Cross-Site Scripting
by Gjoko Krstic
EIP-2026-113425 EXPLOITDB text VERIFIED
Wiki Web Help - 'configpath' Remote File Inclusion
by L0n3ly-H34rT
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
EIP-2026-106826 EXPLOITDB text VERIFIED
Elefant CMS - 'id' Cross-Site Scripting
by PuN!Sh3r
EIP-2026-104363 EXPLOITDB text VERIFIED
ntop - 'arbfile' Cross-Site Scripting
by Marcos Garcia
EIP-2026-114349 EXPLOITDB text VERIFIED
WordPress Theme ShopperPress - SQL Injection / Cross-Site Scripting
by Benjamin Kunz Mejri