Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112058 EXPLOITDB text VERIFIED
Simea CMS - 'index.php' SQL Injection
by Cru3l.b0y
EIP-2026-111668 EXPLOITDB text VERIFIED
Raised Eyebrow CMS - 'venue.php' SQL Injection
by Cru3l.b0y
EIP-2026-110303 EXPLOITDB text
openEngine 2.0 100226 - Local File Inclusion / Cross-Site Scripting
by SecPod Research
EIP-2026-108435 EXPLOITDB text VERIFIED
Joomla! Component com_maianmedia - SQL Injection
by v3n0m
EIP-2026-107728 EXPLOITDB text
IceBB 1.0-rc10 - Multiple Vulnerabilities
by High-Tech Bridge SA
EIP-2026-106094 EXPLOITDB text VERIFIED
CompactCMS 1.4.1 - SQL Injection
by High-Tech Bridge SA
EIP-2026-105871 EXPLOITDB text
ClanSphere 2010.0 Final - Multiple Vulnerabilities
by High-Tech Bridge SA
CVE-2010-4647 EXPLOITDB text VERIFIED
Eclipse IDE < 3.6.2 - Cross-Site Scripting via Help Contents Query String
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.
by Aung Khant
CVE-2010-4647 EXPLOITDB text VERIFIED
Eclipse IDE < 3.6.2 - Cross-Site Scripting via Help Contents Query String
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.
by Aung Khant
EIP-2026-100177 EXPLOITDB text VERIFIED
BPRealestate Real Estate - Authentication Bypass
by v3n0m
EIP-2026-100176 EXPLOITDB text VERIFIED
BPDirectory Business Directory - Authentication Bypass
by v3n0m
EIP-2026-100175 EXPLOITDB text VERIFIED
BPConferenceReporting Web Reporting - Authentication Bypass
by v3n0m
EIP-2026-100174 EXPLOITDB text VERIFIED
BPAffiliate Affiliate Tracking - Authentication Bypass
by v3n0m
EIP-2026-109991 EXPLOITDB text VERIFIED
Nuked-klaN Module Boutique - Blind SQL Injection
by [AR51]Kevinos
EIP-2026-108263 EXPLOITDB text VERIFIED
Joomla! Component com_alfurqan15x - SQL Injection
by kaMtiEz
CVE-2010-4366 EXPLOITDB text VERIFIED
Chameleon Social Networking - Stored Cross-Site Scripting via Thread Title and Description Parameters
Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message.
by Dr-mosta
CVE-2009-5019 EXPLOITDB text VERIFIED
Web Wiz NewsPad - Unauthenticated Sensitive Information Exposure via Direct Database Request
Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.
by keracker
CVE-2010-4814 EXPLOITDB text
Best Soft Inc. Advance Hotel Booking System 1.0 - SQL Injection
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
by v3n0m
CVE-2010-4834 EXPLOITDB text VERIFIED
OneOrZero AIMS 2.6.0-2.7.0 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.
by Valentin
CVE-2010-20010 EXPLOITDB HIGH text VERIFIED
Foxit PDF Reader < 4.2.0.0928 - Stack-based Buffer Overflow via PDF Info Title Entry
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
by dookie
CVE-2010-4839 EXPLOITDB text VERIFIED
WordPress Event Registration <5.32 - SQL Injection
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.
by k3m4n9i
CVE-2010-4808 EXPLOITDB text VERIFIED
Webmatic - SQL Injection via Index.php p Parameter
SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p parameter.
by v3n0m
CVE-2010-4776 EXPLOITDB text VERIFIED
PreProjects Pre Online Tests Generator Pro - SQL Injection
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.
by Cru3l.b0y
EIP-2026-111469 EXPLOITDB text VERIFIED
Pre ADS Portal - Authentication Bypass
by Cru3l.b0y
CVE-2010-4835 EXPLOITDB text VERIFIED
OneOrZero AIMS 2.6.0 - Path Traversal
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
by Valentin