Text Exploits

31,383 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-4237 EXPLOITDB text VERIFIED
TCExam < 11.3.008 - Authenticated SQL Injection via subject_module_id Parameter
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.
by Chris Cooper
CVE-2012-4237 EXPLOITDB text VERIFIED
TCExam < 11.3.008 - Authenticated SQL Injection via subject_module_id Parameter
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.
by Chris Cooper
EIP-2026-107394 EXPLOITDB text VERIFIED
Getsimple CMS 3.1.2 - 'path' Local File Inclusion
by PuN!Sh3r
CVE-2012-4070 EXPLOITDB text VERIFIED
dir2web 3.0 - SQL Injection via oid Parameter
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
by Daniel Correa
EIP-2026-114910 EXPLOITDB text VERIFIED
AOL Products downloadUpdater2 Plugin - 'SRC' Remote Code Execution
by rgod
EIP-2026-114555 EXPLOITDB text VERIFIED
YT-Videos Script - 'id' SQL Injection
by 3spi0n
EIP-2026-108481 EXPLOITDB text VERIFIED
Joomla! Component com_photo - Multiple SQL Injections
by Chokri Ben Achor
EIP-2026-104501 EXPLOITDB text VERIFIED
Worksforweb iAuto - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by Benjamin Kunz Mejri
EIP-2026-113716 EXPLOITDB text
WordPress Plugin Effective Lead Management 3.0.0 - Persistent Cross-Site Scripting
by Chris Kellum
EIP-2026-112674 EXPLOITDB text VERIFIED
Tickets CAD 2.20G - Multiple Vulnerabilities
by chap0
EIP-2026-107969 EXPLOITDB text
Islamnt Islam Forum Script 1.2 - Blind SQL Injection
by s3n4t00r
EIP-2026-100488 EXPLOITDB text VERIFIED
PolarisCMS - 'WebForm_OnSubmit()' Cross-Site Scripting
by Gjoko Krstic
EIP-2026-113425 EXPLOITDB text VERIFIED
Wiki Web Help - 'configpath' Remote File Inclusion
by L0n3ly-H34rT
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
CVE-2012-3872 EXPLOITDB text VERIFIED
Openconstructor - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
by Lorenzo Cantoni
EIP-2026-106826 EXPLOITDB text VERIFIED
Elefant CMS - 'id' Cross-Site Scripting
by PuN!Sh3r
EIP-2026-104363 EXPLOITDB text VERIFIED
ntop - 'arbfile' Cross-Site Scripting
by Marcos Garcia
EIP-2026-114349 EXPLOITDB text VERIFIED
WordPress Theme ShopperPress - SQL Injection / Cross-Site Scripting
by Benjamin Kunz Mejri
CVE-2012-2237 EXPLOITDB MEDIUM text VERIFIED
Mahara 1.4.0-1.4.2 and 1.5.0-1.5.1 - Cross-Site Scripting via Login Form, Links, Resources, and Display Name
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.
by anonymous
CVSS 6.1
EIP-2026-108409 EXPLOITDB text VERIFIED
Joomla! Component com_joomgalaxy 1.2.0.4 - Multiple Vulnerabilities
by D4NB4R
EIP-2026-105150 EXPLOITDB text VERIFIED
am4ss 1.2 - Multiple Vulnerabilities
by s3n4t00r
EIP-2026-101174 EXPLOITDB text VERIFIED
Barracuda Email Security Service - Multiple HTML Injection Vulnerabilities
by Benjamin Kunz Mejri
EIP-2026-112587 EXPLOITDB text VERIFIED
tekno.Portal 0.1b - 'link.php' SQL Injection
by Socket_0x03
EIP-2026-109311 EXPLOITDB text
ManageEngine Mobile Application Manager 10 - SQL Injection
by Vulnerability-Lab