Exploitdb Exploits

31,342 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-5214 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
by High-Tech Bridge SA
CVE-2011-5213 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - SQL Injection
Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php.
by High-Tech Bridge SA
CVE-2011-5214 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
by High-Tech Bridge SA
CVE-2011-5214 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
by High-Tech Bridge SA
CVE-2011-5213 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - SQL Injection
Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php.
by High-Tech Bridge SA
CVE-2011-5214 EXPLOITDB text VERIFIED
Browsercrm < 5.100.01 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
by High-Tech Bridge SA
EIP-2026-104000 EXPLOITDB text VERIFIED
Nagios XI - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by anonymous
EIP-2026-113758 EXPLOITDB text VERIFIED
WordPress Plugin flash-album-gallery - 'flagshow.php' Cross-Site Scripting
by Am!r
CVE-2011-4684 EXPLOITDB text VERIFIED
Opera Browser < 11.60 - Cryptographic Issue
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."
by anonymous
EIP-2026-113800 EXPLOITDB text VERIFIED
WordPress Plugin GRAND FlAGallery 1.57 - 'flagshow.php' Cross-Site Scripting
by Am!r
EIP-2026-114464 EXPLOITDB text
Xoops 2.5.4 - Blind SQL Injection
by blkhtc0rp
EIP-2026-114153 EXPLOITDB text VERIFIED
WordPress Plugin UPM Polls 1.0.4 - Blind SQL Injection
by Saif
EIP-2026-111306 EXPLOITDB text VERIFIED
Pixie 1.04 - Blog Post Cross-Site Request Forgery
by hackme
EIP-2026-107065 EXPLOITDB text VERIFIED
FCMS CMS 2.7.2 - Multiple Cross-Site Request Forgery Vulnerabilities
by Ahmed Elhady Mohamed
CVE-2012-0699 EXPLOITDB HIGH text VERIFIED
Family Connections CMS <2.9 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.
by Ahmed Elhady Mohamed
CVSS 8.8
EIP-2026-111996 EXPLOITDB text
SePortal 2.5 - SQL Injection (1)
by Don
EIP-2026-110554 EXPLOITDB text VERIFIED
Pet Listing - 'preview.php' Cross-Site Scripting
by Mr.PaPaRoSSe
EIP-2026-111890 EXPLOITDB text VERIFIED
SantriaCMS - SQL Injection
by Troy
EIP-2026-108501 EXPLOITDB text
Joomla! Component com_qcontacts 1.0.6 - SQL Injection
by Don
CVE-2011-4836 EXPLOITDB text VERIFIED
Homeseer Hs2 - XSS
Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI.
by Silent Dream
EIP-2026-116087 EXPLOITDB text VERIFIED
PowerDVD 11.0.0.2114 - Remote Denial of Service
by Luigi Auriemma
EIP-2026-112355 EXPLOITDB text
SourceBans 1.4.8 - SQL Injection / Local File Inclusion Injection
by Havok
EIP-2026-110979 EXPLOITDB text
phpBB MyPage Plugin - SQL Injection
by CrazyMouse
EIP-2026-110664 EXPLOITDB text VERIFIED
PHP City Portal Script Software - SQL Injection
by Don
CVE-2011-5057 EXPLOITDB text VERIFIED
Apache Struts < 2.3.3 - Access Control
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
by Hisato Killing