Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-100547 EXPLOITDB text VERIFIED
sirang web-based d-control - Multiple Vulnerabilities
by Abysssec
EIP-2026-119354 EXPLOITDB text VERIFIED
ColdOfficeView 2.04 - Multiple Blind SQL Injections
by mr_me
CVE-2010-4915 EXPLOITDB text VERIFIED
ColdGen ColdBookmarks 1.22 - SQL Injection
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
by mr_me
CVE-2007-3162 EXPLOITDB text VERIFIED
Internet Download Accelerator 5.2 - Buffer Overflow via idaiehlp ActiveX Control
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.
by eidelweiss
CVE-2010-4906 EXPLOITDB text VERIFIED
Zenphoto 1.3 and 1.3.1.2 - SQL Injection via a Parameter
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.
by Bogdan Calin
CVE-2010-4907 EXPLOITDB text VERIFIED
Zenphoto 1.3 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
by Bogdan Calin
EIP-2026-106609 EXPLOITDB text VERIFIED
dynpage 1.0 - Multiple Vulnerabilities
by Abysssec
CVE-2010-1093 EXPLOITDB text VERIFIED
1024 CMS 2.1.1 - SQL Injection via RSS.php id Parameter
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.
by Stephan Sattler
CVE-2010-3306 EXPLOITDB text VERIFIED
Weborf < 0.12.3 - Path Traversal via URI ..%2f Sequences
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
by Rew
EIP-2026-113730 EXPLOITDB text
WordPress Plugin Events Manager Extended - Persistent Cross-Site Scripting
by Craw
EIP-2026-111889 EXPLOITDB text VERIFIED
Santafox 2.0.2 - 'search' Cross-Site Scripting
by High-Tech Bridge SA
CVE-2010-4901 EXPLOITDB text VERIFIED
MySource Matrix 3.28.3 - Cross-Site Scripting via char_map.php Height or Width Parameter
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
by Gjoko Krstic
CVE-2010-4904 EXPLOITDB text VERIFIED
Joomla! com_aardvertiser 2.1-2.1.1 - SQL Injection
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
by Stephan Sattler
EIP-2026-107884 EXPLOITDB text VERIFIED
InterPhoto Gallery - Multiple Vulnerabilities
by Abysssec
CVE-2010-3077 EXPLOITDB text VERIFIED
Horde Application Framework <3.3.9 - XSS
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
by Moritz Naumann
EIP-2026-107573 EXPLOITDB text VERIFIED
HeffnerCMS 1.22 - 'index.php' Local File Inclusion
by MiND C0re
CVE-2010-4919 EXPLOITDB text VERIFIED
Micronetsoft RV Dealer Website 1.0 - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
by L0rd CrusAd3r
CVE-2010-4920 EXPLOITDB text VERIFIED
Micronetsoft Rental Property Mgmt <1.0 - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
by L0rd CrusAd3r
EIP-2026-100265 EXPLOITDB text VERIFIED
DMXReady Members Area Manager - Persistent Cross-Site Scripting
by L0rd CrusAd3r
CVE-2010-4894 EXPLOITDB text VERIFIED
chillyCMS 1.1.3 - SQL Injection via Name Parameter
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.
by AmnPardaz
CVE-2010-4905 EXPLOITDB text VERIFIED
Softbiz Article Directory Script - SQL Injection
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.
by h4ck3r
CVE-2010-4918 EXPLOITDB text
ijoomla com_magazine 3.0.1 - Remote Code Execution via Config Parameter
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php.
by LoSt.HaCkEr
CVE-2010-4902 EXPLOITDB text
Joomla! com_clantools 1.2.3 - SQL Injection
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
by Solidmedia
CVE-2010-4902 EXPLOITDB text
Joomla! com_clantools 1.2.3 - SQL Injection
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
by Solidmedia
CVE-2010-4895 EXPLOITDB text VERIFIED
chillyCMS 1.1.3 - Cross-Site Scripting via Name Parameter
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information.
by AmnPardaz