Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-0901 EXPLOITDB text VERIFIED
YouSayToo auto-publishing plugin 1.0 - XSS
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
by H4ckCity Security Team
EIP-2026-112876 EXPLOITDB text VERIFIED
Ultimate Locator - 'radius' SQL Injection
by Robert Cooper
EIP-2026-108714 EXPLOITDB text VERIFIED
Joomla! Component JE Story Submit - 'index.php' Arbitrary File Upload
by Robert Cooper
EIP-2026-107422 EXPLOITDB text VERIFIED
glFusion 1.x - SQL Injection
by KedAns-Dz
CVE-2012-0286 EXPLOITDB text VERIFIED
Stoneware webNetwork <6.0.8.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.
by Jacob Holcomb
EIP-2026-112367 EXPLOITDB text
SpamTitan Application 5.08x - SQL Injection
by Vulnerability-Lab
EIP-2026-108597 EXPLOITDB text VERIFIED
Joomla! Component com_xball - 'team_id' SQL Injection
by CoBRa_21
EIP-2026-108288 EXPLOITDB text VERIFIED
Joomla! Component com_br - 'Controller' Local File Inclusion
by the_cyber_nuxbie
CVE-2012-1010 EXPLOITDB text
AllWebMenus <1.1.8 - Code Injection
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
by 6Scan
CVE-2012-1011 EXPLOITDB text
AllWebMenus 1.1.8 - Auth Bypass
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
by 6Scan
CVE-2012-5231 EXPLOITDB text
miniCMS 1.0-2.0 - RCE
miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.
by Or4nG.M4N
CVE-2012-5312 EXPLOITDB text VERIFIED
Tribiq CMS - SQL Injection
SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
by Skote Vahshat
EIP-2026-109961 EXPLOITDB text VERIFIED
Nova CMS - Directory Traversal
by Red Security TEAM
CVE-2012-0932 EXPLOITDB text VERIFIED
Lead Capture Page System - XSS
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
by HashoR
CVE-2011-4823 EXPLOITDB text VERIFIED
Extensionsforjoomla Com Vikrealestate - SQL Injection
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.
by the_cyber_nuxbie
EIP-2026-108656 EXPLOITDB text VERIFIED
Joomla! Component Full - 'id' SQL Injection
by the_cyber_nuxbie
EIP-2026-108548 EXPLOITDB text VERIFIED
Joomla! Component com_some - 'Controller' Local File Inclusion
by the_cyber_nuxbie
CVE-2011-4804 EXPLOITDB text VERIFIED
Foobla Com Obsuggest < 1.6.4 - Path Traversal
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by the_cyber_nuxbie
EIP-2026-108298 EXPLOITDB text VERIFIED
Joomla! Component com_car - Multiple SQL Injections
by the_cyber_nuxbie
EIP-2026-108291 EXPLOITDB text VERIFIED
Joomla! Component com_bulkenquery - 'Controller' Local File Inclusion
by the_cyber_nuxbie
EIP-2026-108287 EXPLOITDB text VERIFIED
Joomla! Component com_boss - 'Controller' Local File Inclusion
by the_cyber_nuxbie
EIP-2026-100518 EXPLOITDB text VERIFIED
Raven 1.0 - 'connector.asp' Arbitrary File Upload
by HELLBOY
CVE-2012-0935 EXPLOITDB text
Aryadad CMS - SQL Injection
SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.
by Red Security TEAM
CVE-2012-0933 EXPLOITDB text VERIFIED
Acidcat CMS <3.5.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.
by Avram Marius
EIP-2026-112530 EXPLOITDB text VERIFIED
Syneto Unified Threat Management 1.3.3/1.4.2 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by Alexander Fuchs