Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118901 EXPLOITDB text VERIFIED
MinaliC WebServer 1.0 - Directory Traversal
by John Leitch
EIP-2026-114638 EXPLOITDB text VERIFIED
Zomplog 3.9 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
by High-Tech Bridge SA
EIP-2026-114635 EXPLOITDB text VERIFIED
Zomplog 3.9 - Cross-Site Request Forgery
by High-Tech Bridge SA
EIP-2026-113162 EXPLOITDB text VERIFIED
W-Agora 4.1.5 - Local File Inclusion / Cross-Site Scripting
by MustLive
EIP-2026-111123 EXPLOITDB text VERIFIED
phpLiterAdmin 1.0 RC1 - Authentication Bypass
by High-Tech Bridge SA
EIP-2026-109965 EXPLOITDB text VERIFIED
Novaboard 1.1.4 - Local File Inclusion
by High-Tech Bridge SA
CVE-2010-4874 EXPLOITDB text VERIFIED
NinkoBB 1.3 RC5 - Cross-Site Scripting via User Profile Parameters
Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim parameter.
by High-Tech Bridge SA
EIP-2026-109757 EXPLOITDB text VERIFIED
mycart 2.0 - Multiple Vulnerabilities
by Salvatore Fresta
EIP-2026-109692 EXPLOITDB text
MyBB 1.6 - Full Path Disclosure
by High-Tech Bridge SA
EIP-2026-109101 EXPLOITDB text VERIFIED
LES PACKS - 'ID' SQL Injection
by Cru3l.b0y
CVE-2010-4185 EXPLOITDB text VERIFIED
Energine < 2.3.8 - SQL Injection via NRGNSID Cookie
SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the NRGNSID cookie.
by High-Tech Bridge SA
EIP-2026-106614 EXPLOITDB text VERIFIED
DZCP (deV!L_z Clanportal) 1.5.4 - Local File Inclusion
by High-Tech Bridge SA
EIP-2026-106373 EXPLOITDB text
DBHcms 1.1.4 - 'dbhcms_user/SearchString' SQL Injection
by High-Tech Bridge SA
CVE-2010-4870 EXPLOITDB text VERIFIED
BloofoxCMS 0.3.5 - SQL Injection via Gender Parameter
SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.
by High-Tech Bridge SA
EIP-2026-105544 EXPLOITDB text VERIFIED
BloofoxCMS 0.3.5 - Information Disclosure
by High-Tech Bridge SA
EIP-2026-105527 EXPLOITDB text
BlogBird Platform - Multiple Cross-Site Scripting Vulnerabilities
by High-Tech Bridge SA
CVE-2008-5751 EXPLOITDB text VERIFIED
AlstraSoft Web Email Script Enterprise - SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.
by Salvatore Fresta
CVE-2010-4273 EXPLOITDB text VERIFIED
DescargarVista ACC IMoveis 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by EraGoN
CVE-2010-4099 EXPLOITDB text
NitroSecurity NitroView ESM 8.4.0a - Remote Command Execution via Request Parameter
ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.
by Filip Palian
EIP-2026-111328 EXPLOITDB text
Plesk Small Business Manager 10.2.0 and Site Editor - Multiple Vulnerabilities
by David Hoyt
EIP-2026-111578 EXPLOITDB text VERIFIED
Pulse Pro 1.4.3 - Persistent Cross-Site Scripting
by Th3 RDX
CVE-2010-4869 EXPLOITDB text VERIFIED
DBHcms 1.1.4 - SQL Injection via Editmenu Parameter
SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.
by ZonTa
CVE-2010-4868 EXPLOITDB text VERIFIED
W-Agora < 4.2.1 - Cross-Site Scripting via search.php3 bn Parameter
Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.
by MustLive
CVE-2010-4867 EXPLOITDB text VERIFIED
W-Agora < 4.2.1 - Path Traversal via Search Parameter
Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.
by MustLive
EIP-2026-112086 EXPLOITDB text VERIFIED
Simple Directory Listing 2.1 - 'SDL2.php' Cross-Site Scripting
by Amol Naik