Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
CVE-2012-6523 EXPLOITDB text
W-cms - XSS
Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3) guestbook.php, or (4) forum.php in codes/. NOTE: some of these details are obtained from third party information.
by th3.g4m3_0v3r
CVE-2012-6038 EXPLOITDB text VERIFIED
Razorcms < 1.2 - Path Traversal
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal."
by chap0
CVE-2012-6500 EXPLOITDB text
Pragyan Cms < 3.0 - Path Traversal
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
by Or4nG.M4N
CVE-2012-6043 EXPLOITDB text VERIFIED
Php-fusion - XSS
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
by Am!r
CVE-2011-4191 EXPLOITDB text VERIFIED
Novell NetWare 6.5 SP8 - Buffer Overflow
Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.
by Francis Provencher
EIP-2026-104083 EXPLOITDB text VERIFIED
SonicWALL AntiSpam & EMail 7.3.1 - Multiple Vulnerabilities
by Benjamin Kunz Mejri
CVE-2012-0067 EXPLOITDB text VERIFIED
Wireshark - Improper Input Validation
wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.
by Laurent Butti
CVE-2012-5293 EXPLOITDB text VERIFIED
SAPID CMS 1.2.3 - RCE
Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to usr/extensions/get_infochannel.inc.php.
by Opa Yong
EIP-2026-110445 EXPLOITDB text
Paddelberg Topsite Script - Authentication Bypass
by Christian Inci
CVE-2012-6529 EXPLOITDB text VERIFIED
Marinet Cms - SQL Injection
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.
by H4ckCity Security Team
CVE-2012-6529 EXPLOITDB text VERIFIED
Marinet Cms - SQL Injection
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.
by H4ckCity Security Team
CVE-2012-6529 EXPLOITDB text VERIFIED
Marinet Cms - SQL Injection
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.
by H4ckCity Security Team
EIP-2026-107498 EXPLOITDB text VERIFIED
Gregarius 0.6.1 - Multiple SQL Injections / Cross-Site Scripting
by sonyy
CVE-2012-6644 EXPLOITDB text
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6643 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - SQL Injection
Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php. NOTE: some of these details are obtained from third party information.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6643 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - SQL Injection
Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php. NOTE: some of these details are obtained from third party information.
by YaDoY666
CVE-2012-6644 EXPLOITDB text VERIFIED
Clip-bucket Clipbucket - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
by YaDoY666
CVE-2012-6040 EXPLOITDB text VERIFIED
Convergine File King Advanced File Management - XSS
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Am!r
CVE-2012-5288 EXPLOITDB text VERIFIED
phpMyDirectory 1.3.3 - SQL Injection
SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Serseri