Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108597 EXPLOITDB text VERIFIED
Joomla! Component com_xball - 'team_id' SQL Injection
by CoBRa_21
EIP-2026-108288 EXPLOITDB text VERIFIED
Joomla! Component com_br - 'Controller' Local File Inclusion
by the_cyber_nuxbie
CVE-2012-1010 EXPLOITDB text
AllWebMenus <1.1.8 - Code Injection
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
by 6Scan
CVE-2012-1011 EXPLOITDB text
AllWebMenus WordPress Plugin 1.1.8 - Unauthenticated Arbitrary File Upload and Remote Code Execution
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.
by 6Scan
CVE-2012-5231 EXPLOITDB text
miniCMS 1.0 and 2.0 - Remote Code Execution via Pagename or Area Variable
miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.
by Or4nG.M4N
CVE-2012-5312 EXPLOITDB text VERIFIED
tribiq CMS - SQL Injection via id Parameter
SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
by Skote Vahshat
EIP-2026-109961 EXPLOITDB text VERIFIED
Nova CMS - Directory Traversal
by Red Security TEAM
CVE-2012-0932 EXPLOITDB text VERIFIED
Lead Capture Page System - Stored Cross-Site Scripting via Admin Login Message Parameter
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
by HashoR
CVE-2011-4823 EXPLOITDB text VERIFIED
Extensionsforjoomla Com Vikrealestate - SQL Injection
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.
by the_cyber_nuxbie
EIP-2026-108656 EXPLOITDB text VERIFIED
Joomla! Component Full - 'id' SQL Injection
by the_cyber_nuxbie
EIP-2026-108548 EXPLOITDB text VERIFIED
Joomla! Component com_some - 'Controller' Local File Inclusion
by the_cyber_nuxbie
CVE-2011-4804 EXPLOITDB text VERIFIED
com_obsuggest < 1.8 - Path Traversal via Controller Parameter
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by the_cyber_nuxbie
EIP-2026-108298 EXPLOITDB text VERIFIED
Joomla! Component com_car - Multiple SQL Injections
by the_cyber_nuxbie
EIP-2026-108291 EXPLOITDB text VERIFIED
Joomla! Component com_bulkenquery - 'Controller' Local File Inclusion
by the_cyber_nuxbie
EIP-2026-108287 EXPLOITDB text VERIFIED
Joomla! Component com_boss - 'Controller' Local File Inclusion
by the_cyber_nuxbie
EIP-2026-100518 EXPLOITDB text VERIFIED
Raven 1.0 - 'connector.asp' Arbitrary File Upload
by HELLBOY
CVE-2012-0935 EXPLOITDB text
Aryadad CMS - SQL Injection via PageID Parameter
SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.
by Red Security TEAM
CVE-2012-0933 EXPLOITDB text VERIFIED
acidcat_cms 3.5.1, 3.5.2, 3.5.6 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.
by Avram Marius
EIP-2026-112530 EXPLOITDB text VERIFIED
Syneto Unified Threat Management 1.3.3/1.4.2 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by Alexander Fuchs
CVE-2012-5313 EXPLOITDB text VERIFIED
Snitz Forums 2000 - SQL Injection via TOPIC_ID Parameter
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.
by snup
CVE-2012-0913 EXPLOITDB text VERIFIED
ICloudCenter ICTimeAttendance 1.0 - SQL Injection
SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute arbitrary SQL commands via the passw parameter. NOTE: Some of these details are obtained from third party information.
by v3n0m
EIP-2026-100297 EXPLOITDB text VERIFIED
EasyPage - SQL Injection
by Red Security TEAM
EIP-2026-114132 EXPLOITDB text VERIFIED
WordPress Plugin ucan post 1.0.09 - Persistent Cross-Site Scripting
by Gianluca Brindisi
EIP-2026-112967 EXPLOITDB text VERIFIED
Vastal EzineShop - 'view_mags.php' SQL Injection
by Lazmania61
EIP-2026-111442 EXPLOITDB text VERIFIED
PostNuke pnAddressbook Module - 'id' SQL Injection
by Robert Cooper