Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105896 EXPLOITDB text VERIFIED
ClassifiedsGeek.com Vacation Packages - 'listing_search' SQL Injection
by r45c4l
EIP-2026-103849 EXPLOITDB text VERIFIED
Apache Tomcat - Account Scanner / 'PUT' Request Command Execution
by kingcope
EIP-2026-102495 EXPLOITDB text VERIFIED
ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet - Directory Traversal
by rgod
CVE-2012-5334 EXPLOITDB text VERIFIED
Pre Printing Press - SQL Injection
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.
by Easy Laster
EIP-2026-102379 EXPLOITDB text VERIFIED
JavaBB 0.99 - 'userId' Cross-Site Scripting
by sonyy
CVE-2009-5112 EXPLOITDB text VERIFIED
Iwork Webglimpse < 2.18.7 - Information Disclosure
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
by Websecurity
CVE-2012-5333 EXPLOITDB text VERIFIED
Pre Printing Press - SQL Injection
SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.
by r45c4l
CVE-2007-2675 EXPLOITDB text
Pre Classifieds Listings 1.0 - SQL Injection
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
by r45c4l
CVE-2012-0002 EXPLOITDB text VERIFIED
Microsoft Windows 7 - Code Injection
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
by Luigi Auriemma
EIP-2026-110046 EXPLOITDB text VERIFIED
OneFileCMS 1.1.5 - Local File Inclusion
by mr.pr0n
EIP-2026-108927 EXPLOITDB text VERIFIED
JPM Article Script 6 - 'page2' SQL Injection
by Vulnerability Research Laboratory
EIP-2026-107148 EXPLOITDB text VERIFIED
FlexCMS 3.2.1 - Persistent Cross-Site Scripting
by storm
CVE-2012-1901 EXPLOITDB text VERIFIED
Flexcms < 3.2.1 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.
by Ivano Binetti
CVE-2012-10061 EXPLOITDB HIGH text VERIFIED
Sockso Music Host Server <=1.5 - Path Traversal
Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.
by Luigi Auriemma
EIP-2026-115057 EXPLOITDB text VERIFIED
Citrix 11.6.1 - Licensing Administration Console Denial of Service
by Rune
CVE-2012-1184 EXPLOITDB text
Digium Asterisk - Memory Corruption
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.
by Russell Bryant
CVE-2012-5330 EXPLOITDB text
asaanCart 0.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4) index.php in libs/smarty_ajax/; or the (5) page parameter to libs/smarty_ajax/index.php.
by Number 7
CVE-2008-6359 EXPLOITDB text VERIFIED
Phpf1 Max's Guestbook - XSS
Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.
by n0tch
EIP-2026-119448 EXPLOITDB text VERIFIED
TVersity 1.9.7 - Arbitrary File Download
by Luigi Auriemma
EIP-2026-115221 EXPLOITDB text VERIFIED
Epson EventManager 2.50 - Denial of Service
by Luigi Auriemma
EIP-2026-112136 EXPLOITDB text VERIFIED
Simple Posting System - Multiple Vulnerabilities
by n0tch
EIP-2026-109544 EXPLOITDB text
ModX 2.2.0 - Multiple Vulnerabilities
by n0tch
EIP-2026-109355 EXPLOITDB text VERIFIED
Max's PHP Photo Album 1.0 - 'id' Local File Inclusion
by n0tch
EIP-2026-109353 EXPLOITDB text VERIFIED
Max's Guestbook 1.0 - Multiple Remote Vulnerabilities
by n0tch
EIP-2026-106869 EXPLOITDB text
Encaps PHP Gallery - SQL Injection
by Daniel Godoy