Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-1309 EXPLOITDB text
D-Link DSL-2640B ADSL Router - Authentication Bypass
by Ivano Binetti
CVE-2012-1304 EXPLOITDB text
Fork CMS 3.2.4 - Local File Inclusion / Cross-Site Scripting
by Ivano Binetti
CVE-2012-1305 EXPLOITDB text
Fork CMS 3.2.5 - Multiple Vulnerabilities
by Ivano Binetti
CVE-2012-1208 EXPLOITDB text
Fork-cms Fork Cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.
by Ivano Binetti
CVE-2012-0873 EXPLOITDB text VERIFIED
Boonex Dolphin <7.0.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php.
by Aung Khant
CVE-2012-0873 EXPLOITDB text VERIFIED
Boonex Dolphin <7.0.8 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php.
by Aung Khant
EIP-2026-106227 EXPLOITDB text VERIFIED
CPG Dragonfly CMS 9.3.3.0 - Multiple Multiple Cross-Site Scripting Vulnerabilities
by Ariko-Security
CVE-2012-5322 EXPLOITDB text VERIFIED
Xavi X7968 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to webconfig/lan/lan_config.html/local_lan_config.
by Busindre
EIP-2026-101590 EXPLOITDB text
Cisco Linksys WAG54GS - Cross-Site Request Forgery (Change Admin Password)
by Ivano Binetti
CVE-2012-5323 EXPLOITDB text VERIFIED
Xavi X7968 - CSRF
Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysUserName, sysPassword, and sysCfmPwd parameters.
by Busindre
CVE-2012-5322 EXPLOITDB text VERIFIED
Xavi X7968 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to webconfig/lan/lan_config.html/local_lan_config.
by Busindre
EIP-2026-113151 EXPLOITDB text VERIFIED
VOXTRONIC Voxlog Professional 3.7.x - 'userlogdetail.php?idclient' SQL Injection
by J. Greil
EIP-2026-113150 EXPLOITDB text VERIFIED
VOXTRONIC Voxlog Professional 3.7.x - 'get.php?v' Arbitrary File Access
by J. Greil
EIP-2026-112604 EXPLOITDB text VERIFIED
TestLink - Multiple SQL Injections
by Juan M. Natal
EIP-2026-108776 EXPLOITDB text VERIFIED
Joomla! Component Machine - Multiple SQL Injections
by the_cyber_nuxbie
CVE-2012-0869 EXPLOITDB text VERIFIED
Frams' Fast File EXchange <20120215 - XSS
Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by muuratsalo
CVE-2012-1308 EXPLOITDB text
Dlink Dsl-2640b Firmware - CSRF
Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.
by Ivano Binetti
EIP-2026-104852 EXPLOITDB text
4PSA CMS - SQL Injection
by BHG Security Center
CVE-2012-5321 EXPLOITDB text VERIFIED
TikiWiki CMS/Groupware 8.3 - XSS
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."
by sonyy
EIP-2026-108605 EXPLOITDB text VERIFIED
Joomla! Component com_xvs - 'Controller' Local File Inclusion
by KedAns-Dz
EIP-2026-108599 EXPLOITDB text VERIFIED
Joomla! Component com_xcomp - Local File Inclusion
by KedAns-Dz
EIP-2026-108596 EXPLOITDB text VERIFIED
Joomla! Component com_x-shop - 'idd' SQL Injection
by KedAns-Dz
CVE-2012-1221 EXPLOITDB text VERIFIED
Rabidhamster R2/ < extreme - Path Traversal
Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command.
by Luigi Auriemma
EIP-2026-110456 EXPLOITDB text
Pandora Fms 4.0.1 - Local File Inclusion
by Vulnerability-Lab
EIP-2026-110455 EXPLOITDB text VERIFIED
Pandora FMS 4.0.1 - 'sec2' Local File Inclusion
by Ucha Gobejishvili