Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104627 EXPLOITDB text VERIFIED
Croogo CMS 1.3.4 - Multiple HTML Injection Vulnerabilities
by Chokri Ben Achor
EIP-2026-112016 EXPLOITDB text VERIFIED
Shawn Bradley PHP Volunteer Management 1.0.2 - 'id' SQL Injection
by eidelweiss
CVE-2012-1936 EXPLOITDB text
Wordpress < 3.3.1 - CSRF
The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user session, which might make it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks on specific actions and objects by sniffing the network, as demonstrated by attacks against the wp-admin/admin-ajax.php and wp-admin/user-new.php scripts. NOTE: the vendor reportedly disputes the significance of this issue because wp_create_nonce operates as intended, even if it is arguably inconsistent with certain CSRF protection details advocated by external organizations
by Ivano Binetti
CVE-2012-4055 EXPLOITDB text VERIFIED
Uiga Fan Club - SQL Injection
SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via the p parameter.
by Farbod Mahini
EIP-2026-112206 EXPLOITDB text VERIFIED
SKYUC 3.2.1 - 'encode' Cross-Site Scripting
by farbodmahini
CVE-2012-4254 EXPLOITDB text VERIFIED
Mysqldumper - Information Disclosure
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
by AkaStep
CVE-2012-4251 EXPLOITDB text VERIFIED
Mysqldumper - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
by AkaStep
CVE-2012-4251 EXPLOITDB text VERIFIED
Mysqldumper - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
by AkaStep
CVE-2012-4252 EXPLOITDB text VERIFIED
Mysqldumper - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.
by AkaStep
CVE-2012-4251 EXPLOITDB text VERIFIED
Mysqldumper - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
by AkaStep
CVE-2012-4251 EXPLOITDB text VERIFIED
Mysqldumper - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
by AkaStep
CVE-2012-4253 EXPLOITDB text VERIFIED
Mysqldumper - Path Traversal
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
by AkaStep
EIP-2026-105340 EXPLOITDB text VERIFIED
Axous 1.1.0 - SQL Injection
by H4ckCity Secuirty TeaM
CVE-2012-4253 EXPLOITDB text VERIFIED
Mysqldumper - Path Traversal
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
by AkaStep
CVE-2012-4060 EXPLOITDB text VERIFIED
Asp-dev XM Forums - SQL Injection
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.
by Farbod Mahini
EIP-2026-100161 EXPLOITDB text VERIFIED
BBSXP CMS - Multiple SQL Injections
by Farbod Mahini
CVE-2012-6504 EXPLOITDB text VERIFIED
Shawn Bradley Php Volunteer Management - SQL Injection
SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by G13
CVE-2012-6506 EXPLOITDB text VERIFIED
Zingiri Web Shop - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.
by Mehmet Ince
EIP-2026-111639 EXPLOITDB text VERIFIED
Quick.CMS 4.0 - 'p' Cross-Site Scripting
by Jakub Galczyk
CVE-2012-6505 EXPLOITDB text VERIFIED
Shawn Bradley Php Volunteer Management - XSS
Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by G13
CVE-2012-6513 EXPLOITDB text VERIFIED
Gpeasy Cms - XSS
Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback parameter.
by Jakub Galczyk
EIP-2026-106124 EXPLOITDB text VERIFIED
Concrete5 CMS 5.5.2.1 - Information Disclosure / SQL Injection / Cross-Site Scripting
by Jakub Galczyk
EIP-2026-102945 EXPLOITDB text
Parallels PLESK 9.x - Insecure Permissions
by Nicolas Krassas
CVE-2012-2208 EXPLOITDB text
Piwigo < 2.3.3 - Path Traversal
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
by High-Tech Bridge SA
CVE-2012-2209 EXPLOITDB text
Piwigo < 2.3.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuration module, (2) installstatus parameter in the languages_new module, or (3) theme parameter in the theme module.
by High-Tech Bridge SA