Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108478 EXPLOITDB text VERIFIED
Joomla! Component com_people 1.0.0 - Local File Inclusion
by ALTBTA
CVE-2011-0516 EXPLOITDB text
Epromptc Betmore Site Suite - SQL Injection
SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to execute arbitrary SQL commands via the bid parameter.
by h4ck3r
CVE-2011-0510 EXPLOITDB text VERIFIED
Awbs Advanced Webhost Billing System < 2.9.2 - SQL Injection
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
by ShivX
EIP-2026-104994 EXPLOITDB text VERIFIED
Advanced Webhost Billing System (AWBS) 2.9.2 - 'oid' SQL Injection
by ShivX
EIP-2026-107423 EXPLOITDB text VERIFIED
glfusion CMS 1.2.1 - 'img' Persistent Cross-Site Scripting
by Saif
EIP-2026-106093 EXPLOITDB text
CompactCMS 1.4.1 - Multiple Vulnerabilities
by Patrick de Brouwer
EIP-2026-106092 EXPLOITDB text VERIFIED
CompactCMS 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities (2)
by Patrick de Brouwer
CVE-2011-0517 EXPLOITDB text
Sielcosistemi Winlog Pro < 2.07.00 - Memory Corruption
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.
by Luigi Auriemma
EIP-2026-108826 EXPLOITDB text
Joomla! Component People 1.0.0 - SQL Injection
by Salvatore Fresta
EIP-2026-105080 EXPLOITDB text VERIFIED
Alguest 1.1c-patched - 'elimina' SQL Injection
by Aliaksandr Hartsuyeu
EIP-2026-109126 EXPLOITDB text VERIFIED
LifeType 1.2.10 - HTTP Referer Persistent Cross-Site Scripting
by Saif El-Sherei
EIP-2026-108173 EXPLOITDB text
Joomla! 1.5.22 / 1.6.0 - 'com_mailto' Spam Mail Relay
by Jeff Channell
CVE-2011-0503 EXPLOITDB text
Vamsoft Vam Shop < 1.6.1 - CSRF
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via admin/accounting.php. NOTE: some of these details are obtained from third party information.
by High-Tech Bridge SA
EIP-2026-113401 EXPLOITDB text
whCMS 0.115 - Cross-Site Request Forgery
by High-Tech Bridge SA
CVE-2011-0504 EXPLOITDB text
Vamshop Vam Shop - XSS
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php, (2) search parameter to admin/customers.php, or (3) STORE_NAME parameter to admin/configuration.php.
by High-Tech Bridge SA
EIP-2026-106973 EXPLOITDB text
Extcalendar 2 - 'calendar.php' SQL Injection
by Lagripe-Dz & Mca-Crb
EIP-2026-106878 EXPLOITDB text
energine 2.3.8 - Multiple Vulnerabilities
by High-Tech Bridge SA
CVE-2011-5318 EXPLOITDB text
Diafan.cms < 5.0 - CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.
by High-Tech Bridge SA
EIP-2026-106002 EXPLOITDB text VERIFIED
CMS Tovar - 'tovar.php' SQL Injection
by jos_ali_joe
EIP-2026-105698 EXPLOITDB text
Cambio 0.5a - Cross-Site Request Forgery
by High-Tech Bridge SA
CVE-2010-4301 EXPLOITDB text
Wireshark - Resource Management Error
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes.
by Fred Fierling
CVE-2010-4254 EXPLOITDB text VERIFIED
Mono < 2.3.0 - Improper Input Validation
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
by Chris Howie
EIP-2026-113436 EXPLOITDB text VERIFIED
WikLink 0.1.3 - Multiple SQL Injections
by Aliaksandr Hartsuyeu
CVE-2011-0443 EXPLOITDB text VERIFIED
Tinybb - SQL Injection
SQL injection vulnerability in inc/tinybb-settings.php in tinyBB 1.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.
by Aodrulez
EIP-2026-109361 EXPLOITDB text
Maximus CMS 1.1.2 - 'FCKeditor' Arbitrary File Upload
by eidelweiss