Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-101247 EXPLOITDB text VERIFIED
D-Link ShareCenter Products - Multiple Remote Code Execution Vulnerabilities
by Roberto Paleari
CVE-2012-1028 EXPLOITDB text VERIFIED
SimpleGroupware < 0.743 - Cross-Site Scripting via Export Parameter
Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter.
by Infoserve Security Team
CVE-2012-1048 EXPLOITDB text VERIFIED
eFront Community++ 3.6.10 - Cross-Site Scripting via Administrator Filter Parameter
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
by Chokri B.A
CVE-2012-1049 EXPLOITDB text VERIFIED
ManageEngine ADManager Plus <5.2.5210 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
by LiquidWorm
CVE-2012-1049 EXPLOITDB text VERIFIED
ManageEngine ADManager Plus <5.2.5210 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
by LiquidWorm
EIP-2026-115209 EXPLOITDB text VERIFIED
Edraw Diagram Component 5 - ActiveX Control 'LicenseName()' Method Buffer Overflow
by Senator of Pirates
CVE-2012-1026 EXPLOITDB text VERIFIED
XRay CMS 1.1.1 - SQL Injection via Username or Password Parameter
Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
by chap0
EIP-2026-113055 EXPLOITDB text VERIFIED
Vespa 0.8.6 - 'getid3.php' Local File Inclusion
by T0x!c
CVE-2012-1029 EXPLOITDB text VERIFIED
Tube Ace 1.6 - SQL Injection via q Parameter
SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter. NOTE: some of these details are obtained from third party information.
by Daniel Godoy
CVE-2012-1017 EXPLOITDB text
BASE 1.4.5 - SQL Injection via ip_addr Parameters
Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.
by a.kadir altan
CVE-2011-3639 EXPLOITDB text VERIFIED
Apache HTTP Server <2.0.64, <2.2.18 - SSRF
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
by Tomas Hoger
CVE-2012-1027 EXPLOITDB text VERIFIED
]project-open[ 3.4.x-3.5.0.1-2 - Cross-Site Scripting via Message Parameter
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.
by Michail Poultsakis
EIP-2026-110810 EXPLOITDB text VERIFIED
PHP-Fusion 7.2.4 - 'weblink_id' SQL Injection
by Am!r
EIP-2026-104665 EXPLOITDB text VERIFIED
PHP 5.4SVN-2012-02-03 - htmlspecialchars/entities Buffer Overflow
by cataphract
CVE-2012-1005 EXPLOITDB text VERIFIED
Sphinx Software Mobile Web Server 3.1.2.47 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt.
by SecPod Research
CVE-2012-1008 EXPLOITDB text VERIFIED
OfficeSIP Server 3.1 - Denial of Service via Crafted SIP INVITE To Header
OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.
by SecPod Research
CVE-2012-1009 EXPLOITDB text
NetSarang Xlpd and Xmanager Enterprise - Denial of Service via Malformed LPD Request
NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.
by SecPod Research
CVE-2012-1059 EXPLOITDB text VERIFIED
OSCommerce Online Merchant 3.0.2 - XSS
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.
by Vulnerability-Lab
CVE-2012-1018 EXPLOITDB text VERIFIED
Joomla mod_currencyconverter 1.0.0 - XSS
Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.
by BHG Security Center
EIP-2026-108284 EXPLOITDB text VERIFIED
Joomla! Component com_bnf - 'seccion_id' SQL Injection
by Daniel Godoy
CVE-2012-1069 EXPLOITDB text VERIFIED
lknSupport - Cross-Site Scripting via PATH_INFO in Search Module
Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Red Security TEAM
EIP-2026-107406 EXPLOITDB text VERIFIED
GForge 5.7.1 - Multiple Cross-Site Scripting Vulnerabilities
by sonyy
EIP-2026-104913 EXPLOITDB text
Achievo 1.4.3 - Multiple Web Vulnerabilities
by Vulnerability-Lab
CVE-2012-1007 EXPLOITDB text
Apache Struts 1.3.10 - Cross-Site Scripting via Name or Message Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
by SecPod Research
EIP-2026-112503 EXPLOITDB text
swDesk - Multiple Vulnerabilities
by Red Security TEAM