Text Exploits
31,386 exploits tracked across all sources.
Tracker Software PDF-XChange <3.60.0128 - Buffer Overflow
Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.
by LiquidWorm
Joomla! Component com_visa - Local File Inclusion / SQL Injection
by the_cyber_nuxbie
Joomla! Component com_cmotour - 'id' SQL Injection
by the_cyber_nuxbie
miniupnpd < 1.4 - Denial of Service via Crafted SSDP Request
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
by Rapid7
Peel SHOPPING 2.8 and 2.9 - Cross-Site Scripting via motclef Parameter or PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php.
by Cyber-Crystal
xClick Cart 1.0.1 and 1.0.2 - Cross-Site Scripting via shopping_url Parameter
Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.
by sonyy
Slideshow Gallery2 - Cross-Site Scripting via Border Parameter
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter.
by Bret Hawk
Peel SHOPPING 2.8 and 2.9 - SQL Injection via TVA ID Parameter
SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Cyber-Crystal
Joomla! Component com_products - Multiple SQL Injections
by the_cyber_nuxbie
Joomla! Component com_motor - 'cid' SQL Injection
by the_cyber_nuxbie
WordPress < 3.3.1 - Cross-Site Scripting via Installation Setup Parameters
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance
by Trustwave's SpiderLabs
WordPress < 3.3.1 - Static Code Injection and Cross-Site Scripting via Database Configuration
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments
by Trustwave's SpiderLabs
WordPress < 3.3.1 - Unauthenticated Sensitive Information Exposure via Installation Error Messages
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective
by Trustwave's SpiderLabs
WordPress < 3.3.1 - Denial of Service via MySQL Query Proxy in Setup-Config
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time
by Trustwave's SpiderLabs
vBadvanced CMPS < 3.2.2 - Remote Code Execution via pages[template] Parameter
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.
by PacketiK
OSClass < 2.3.5 - SQL Injection via sCategory Parameter
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.
by High-Tech Bridge SA
OSClass < 2.3.5 - Cross-Site Scripting via Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.
by High-Tech Bridge SA
DClassifieds 0.1 final - Cross-Site Request Forgery via Admin Settings Update
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.
by High-Tech Bridge SA
YouSayToo auto-publishing plugin 1.0 - XSS
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
by H4ckCity Security Team
Joomla! Component JE Story Submit - 'index.php' Arbitrary File Upload
by Robert Cooper
Stoneware webNetwork <6.0.8.0 - CSRF
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.
by Jacob Holcomb
By Source