Text Exploits
31,386 exploits tracked across all sources.
Adobe Acrobat and Reader 8.x-8.2.4 and 9.x-9.3 - Remote Code Execution
Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
by Knud & nSense
SquirrelMail Virtual Keyboard Plugin - 'vkeyboard.php' Cross-Site Scripting
by Moritz Naumann
CAG CMS 0.2 Beta - SQL Injection via click.php itemid Parameter
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
by Shamus
NetWin SurgeMail < 4.3g - Cross-Site Scripting via Username Parameter
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
by Kerem Kocaer
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (2)
by Abysssec
DNET Live-Stats <0.8 - Path Traversal
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.
by blake
TinyMCE MCFileManager 2.1.2 - Arbitrary File Upload
by Hackeri-AL
Aprox CMS Engine 6.0 - Multiple Vulnerabilities
by Stephan Sattler
TradeMC E-Ticaret - SQL Injection / Cross-Site Scripting
by KnocKout
SmarterStats 5.3 - Cross-Site Scripting via frmHelp.aspx url Parameter
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
by sqlhacker
SmarterMail 7.1.3876 - Path Traversal
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash), (2) %5C (encoded backslash), or (3) %255c (double-encoded backslash) in the name parameter.
by sqlhacker
Internet Information Services 5.1-7.5 - Denial of Service via Crafted ASP Request
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
by kingcope
Zen Cart 1.3.9f - 'typefilter' Local File Inclusion
by LiquidWorm
Tiki Wiki CMS Groupware 5.2 - Multiple Vulnerabilities
by John Leitch
phpMyShopping 1.0.1505 - Multiple Vulnerabilities
by Metropolis
jCart 1.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery/Open Redirect Vulnerabilities
by p0deje
By Source