Text Exploits
31,386 exploits tracked across all sources.
sirang web-based d-control - Multiple Vulnerabilities
by Abysssec
ColdOfficeView 2.04 - Multiple Blind SQL Injections
by mr_me
ColdGen ColdBookmarks 1.22 - SQL Injection
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
by mr_me
Internet Download Accelerator 5.2 - Buffer Overflow via idaiehlp ActiveX Control
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.
by eidelweiss
Zenphoto 1.3 and 1.3.1.2 - SQL Injection via a Parameter
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.
by Bogdan Calin
Zenphoto 1.3 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
by Bogdan Calin
1024 CMS 2.1.1 - SQL Injection via RSS.php id Parameter
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.
by Stephan Sattler
Weborf < 0.12.3 - Path Traversal via URI ..%2f Sequences
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
by Rew
WordPress Plugin Events Manager Extended - Persistent Cross-Site Scripting
by Craw
Santafox 2.0.2 - 'search' Cross-Site Scripting
by High-Tech Bridge SA
MySource Matrix 3.28.3 - Cross-Site Scripting via char_map.php Height or Width Parameter
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
by Gjoko Krstic
Joomla! com_aardvertiser 2.1-2.1.1 - SQL Injection
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
by Stephan Sattler
Horde Application Framework <3.3.9 - XSS
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
by Moritz Naumann
HeffnerCMS 1.22 - 'index.php' Local File Inclusion
by MiND C0re
Micronetsoft RV Dealer Website 1.0 - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
by L0rd CrusAd3r
Micronetsoft Rental Property Mgmt <1.0 - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
by L0rd CrusAd3r
DMXReady Members Area Manager - Persistent Cross-Site Scripting
by L0rd CrusAd3r
chillyCMS 1.1.3 - SQL Injection via Name Parameter
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.
by AmnPardaz
Softbiz Article Directory Script - SQL Injection
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.
by h4ck3r
ijoomla com_magazine 3.0.1 - Remote Code Execution via Config Parameter
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php.
by LoSt.HaCkEr
Joomla! com_clantools 1.2.3 - SQL Injection
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
by Solidmedia
Joomla! com_clantools 1.2.3 - SQL Injection
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
by Solidmedia
chillyCMS 1.1.3 - Cross-Site Scripting via Name Parameter
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information.
by AmnPardaz
By Source