Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-4909 EXPLOITDB text VERIFIED
PaysiteReviewCMS 1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.
by Valentin Hoebel
CVE-2010-4909 EXPLOITDB text VERIFIED
PaysiteReviewCMS 1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.
by Valentin Hoebel
CVE-2010-3422 EXPLOITDB text VERIFIED
Joomla! com_jgen 0.9.33 - SQL Injection
SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
by **RoAd_KiLlEr**
CVE-2010-3407 EXPLOITDB text VERIFIED
IBM Lotus Domino <8.0.2 FP5-8.5.1 FP2 - RCE
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.
by A. Plaskett
EIP-2026-100331 EXPLOITDB text VERIFIED
freediscussionforums 1.0 - Multiple Vulnerabilities
by Abysssec
EIP-2026-114825 EXPLOITDB text VERIFIED
AA SMTP Server 1.1 - Crash (PoC)
by SONIC
CVE-2010-4912 EXPLOITDB text VERIFIED
UCenter Home 2.0 - SQL Injection
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.
by KnocKout
EIP-2026-112443 EXPLOITDB text
Storyteller CMS - 'var' Local File Inclusion
by h4ck3r
EIP-2026-110393 EXPLOITDB text
osDate - 'uploadvideos.php' Arbitrary File Upload
by Xa7m3d
EIP-2026-108448 EXPLOITDB text VERIFIED
Joomla! Component com_mtree 2.1.5 - Arbitrary File Upload
by jdc
CVE-2010-3428 EXPLOITDB text VERIFIED
Intermesh Group-Office 3.5.9 - SQL Injection
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.
by ViciOuS
EIP-2026-100400 EXPLOITDB text VERIFIED
Luftguitar CMS - Upload Arbitrary File
by Abysssec
EIP-2026-112538 EXPLOITDB text VERIFIED
System Shop - 'Module aktka' SQL Injection
by secret
EIP-2026-109768 EXPLOITDB text VERIFIED
MyHobbySite 1.01 - SQL Injection / Authentication Bypass
by YuGj VN
EIP-2026-105128 EXPLOITDB text VERIFIED
Alstrasoft AskMe Pro 2.1 - 'profile.php' SQL Injection
by CoBRa_21
CVE-2010-3404 EXPLOITDB text VERIFIED
eshtery CMS - SQL Injection
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.
by Abysssec
EIP-2026-115394 EXPLOITDB text VERIFIED
HP Data Protector Media Operations 6.11 (Multiple Modules) - Null Pointer Dereference Denial of Service
by d0lc3
EIP-2026-111299 EXPLOITDB text VERIFIED
piwigo-2.1.2 - Multiple Vulnerabilities
by Sweet
EIP-2026-103252 EXPLOITDB text VERIFIED
YOPS - Web Server Remote Command Execution
by Rodrigo Escobar
EIP-2026-100119 EXPLOITDB text VERIFIED
ASP Nuke - SQL Injection
by Abysssec
CVE-2010-3457 EXPLOITDB text
Symphony CMS <2.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-default-theme/ or (2) send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.
by JosS
CVE-2010-1813 EXPLOITDB text VERIFIED
Apple Iphone OS < 4.1 - Memory Corruption
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.
by Jose A. Vazquez
CVE-2010-3458 EXPLOITDB text
Symphony CMS <2.1.1 - SQL Injection
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.
by JosS
CVE-2010-3426 EXPLOITDB text VERIFIED
JPhone <1.0 Alpha 3 - Path Traversal
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
by Chip d3 bi0s
CVE-2010-3419 EXPLOITDB text
Haudenschilt FCMS <2.2.3 - RCE
Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.
by LoSt.HaCkEr