Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-2105 EXPLOITDB text
Timesheet Next Gen 1.5.2 - SQL Injection via Username or Password Parameter
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
by G13
EIP-2026-106872 EXPLOITDB text
Endian UTM Firewall 2.4.x < 2.5.0 - Multiple Web Vulnerabilities
by Vulnerability-Lab
CVE-2012-4996 EXPLOITDB text
rivettracker < 1.03 - SQL Injection via Hash Parameter
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
by Ali Raheem
CVE-2012-4998 EXPLOITDB text VERIFIED
starCMS - Cross-Site Scripting via q Parameter
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.
by Am!r
CVE-2012-1124 EXPLOITDB CRITICAL text
phxEventManager 2.0 beta 5 - SQL Injection
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
by skysbsb
CVSS 9.8
CVE-2007-6752 EXPLOITDB text
Drupal < 7.12 - Cross-Site Request Forgery via User Logout URI
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.
by Ivano Binetti
CVE-2011-4189 EXPLOITDB text
Novell GroupWise 8.0x-8.02HP3 - Remote Code Execution via Long Email Address in Address Book File
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.
by Francis Provencher
CVE-2012-4925 EXPLOITDB text
Img Pals Photo Host 1.0 - SQL Injection
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by CorryL
CVE-2012-1466 EXPLOITDB text VERIFIED
NetMechanica NetDecision < 4.5.1 - Unauthenticated Source Code Exposure via Invalid Version Number
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.
by SecPod Research
EIP-2026-113452 EXPLOITDB text
Wolf CMS 0.7.5 - Multiple Vulnerabilities
by longrifle0x
CVE-2012-4926 EXPLOITDB text
Img Pals Photo Host 1.0 - Unauthenticated Administrator Activation Change via approve.php u Parameter
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
by CorryL
CVE-2012-1039 EXPLOITDB text VERIFIED
Dotclear < 2.4.2 - Cross-Site Scripting via Multiple Admin Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
by High-Tech Bridge SA
CVE-2012-1039 EXPLOITDB text VERIFIED
Dotclear < 2.4.2 - Cross-Site Scripting via Multiple Admin Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
by High-Tech Bridge SA
CVE-2012-1039 EXPLOITDB text VERIFIED
Dotclear < 2.4.2 - Cross-Site Scripting via Multiple Admin Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
by High-Tech Bridge SA
CVE-2012-1417 EXPLOITDB text
Yealink VOIP Phones - Authenticated Stored Cross-Site Scripting via User Field
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
by Narendra Shinde
CVE-2012-1498 EXPLOITDB text
Nikola Posa Webfoliocms1.0.2 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.
by Ivano Binetti
CVE-2012-1188 EXPLOITDB text VERIFIED
Fork CMS < 3.2.7 - Cross-Site Scripting via Type, Querystring, or Name Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index.
by anonymous
CVE-2012-1188 EXPLOITDB text VERIFIED
Fork CMS < 3.2.7 - Cross-Site Scripting via Type, Querystring, or Name Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index.
by anonymous
EIP-2026-117918 EXPLOITDB text VERIFIED
Socusoft Photo 2 Video 8.05 - Local Buffer Overflow
by Vulnerability-Lab
CVE-2012-1782 EXPLOITDB text VERIFIED
OSQA 3b - Cross-Site Scripting via URL or Picture Bar
Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.
by Ucha Gobejishvili
EIP-2026-105583 EXPLOITDB text VERIFIED
Bontq - 'user/' URI Cross-Site Scripting
by sonyy
CVE-2012-4923 EXPLOITDB text VERIFIED
Endian Firewall 2.4 - Cross-Site Scripting via dnat.cgi createrule Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
by Vulnerability Research Laboratory
CVE-2012-4923 EXPLOITDB text VERIFIED
Endian Firewall 2.4 - Cross-Site Scripting via dnat.cgi createrule Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
by Vulnerability Research Laboratory
CVE-2012-4923 EXPLOITDB text VERIFIED
Endian Firewall 2.4 - Cross-Site Scripting via dnat.cgi createrule Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.
by Vulnerability Research Laboratory
CVE-2012-1787 EXPLOITDB text VERIFIED
Webglimpse < 2.20.0 - Cross-Site Scripting via URL FILE or DOMAIN Parameters
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.
by MustLive