Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-4814 EXPLOITDB text
Best Soft Inc. Advance Hotel Booking System 1.0 - SQL Injection
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
by v3n0m
CVE-2010-4834 EXPLOITDB text VERIFIED
OneOrZero AIMS 2.6.0-2.7.0 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.
by Valentin
CVE-2010-20010 EXPLOITDB HIGH text VERIFIED
Foxit PDF Reader <4.2.0.0928 - RCE
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
by dookie
CVE-2010-4839 EXPLOITDB text VERIFIED
WordPress Event Registration <5.32 - SQL Injection
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.
by k3m4n9i
CVE-2010-4808 EXPLOITDB text VERIFIED
Webmatic - SQL Injection
SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p parameter.
by v3n0m
CVE-2010-4776 EXPLOITDB text VERIFIED
PreProjects Pre Online Tests Generator Pro - SQL Injection
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.
by Cru3l.b0y
EIP-2026-111469 EXPLOITDB text VERIFIED
Pre ADS Portal - Authentication Bypass
by Cru3l.b0y
CVE-2010-4835 EXPLOITDB text VERIFIED
OneOrZero AIMS 2.6.0 - Path Traversal
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
by Valentin
EIP-2026-108234 EXPLOITDB text
Joomla! Component CCBoard 1.2-RC - Multiple Vulnerabilities
by jdc
EIP-2026-107934 EXPLOITDB text
Invision Power Board 3 - 'search_app' SQL Injection
by Lord Tittis3000
EIP-2026-106719 EXPLOITDB text
EasyJobPortal - Arbitrary File Upload
by MeGo
EIP-2026-105642 EXPLOITDB text
Build a Niche Store 3.0 - 'BANS' Authentication Bypass
by ThunDEr HeaD
CVE-2010-4810 EXPLOITDB text
AR Web Content Manager AWCM 2.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.
by LoSt.HaCkEr
CVE-2010-4233 EXPLOITDB text VERIFIED
Camtron Cmnc-200 Firmware - Credentials Management
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it easier for remote attackers to obtain access via the TELNET interface.
by Trustwave's SpiderLabs
CVE-2010-4232 EXPLOITDB text VERIFIED
Camtron Cmnc-200 Firmware - Authentication Bypass
The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI.
by Trustwave's SpiderLabs
CVE-2010-4231 EXPLOITDB text VERIFIED
Camtron Cmnc-200 Firmware - Path Traversal
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by Trustwave's SpiderLabs
CVE-2010-4234 EXPLOITDB text VERIFIED
Camtron Cmnc-200 Firmware - Resource Management Error
The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to cause a denial of service (device reboot) via a large number of requests in a short time interval.
by Trustwave's SpiderLabs
CVE-2010-4230 EXPLOITDB text VERIFIED
Camtron Cmnc-200 Firmware - Memory Corruption
Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to execute arbitrary code via a long string in the first argument to the connect method.
by Trustwave's SpiderLabs
EIP-2026-100870 EXPLOITDB text VERIFIED
OpenWrt 10.03 - Multiple Cross-Site Scripting Vulnerabilities
by dave b
EIP-2026-113459 EXPLOITDB text
Woltlab Burning Board 2.3.4 - File Disclosure
by sfx
CVE-2010-4976 EXPLOITDB text VERIFIED
MetInfo 3.0 - XSS
Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.
by anT!-Tr0J4n
CVE-2010-4838 EXPLOITDB text VERIFIED
JSupport 1.5.6 - SQL Injection
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.
by Valentin
CVE-2010-4837 EXPLOITDB text VERIFIED
JSupport 1.5.6 - XSS
Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.
by Valentin
CVE-2010-4872 EXPLOITDB text VERIFIED
ASPilot Pilot Cart 7.3 - SQL Injection
SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter.
by Daikin
EIP-2026-114487 EXPLOITDB text
XT:Commerce < 3.04 SP2.1 - Cross-Site Scripting
by Philipp Niedziela