Exploitdb Exploits
31,394 exploits tracked across all sources.
Datetopia Buy Dating Site 1.0 - Cross-Site Scripting via profile.php s_r Parameter
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.
by Moudi
Visitors Google Map Lite 1.0.1 Free mod_visitorsgooglemap Module - SQL Injection
by Chip d3 bi0s
FestOS 2.3b - Cross-Site Scripting via Category Parameter
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.
by Abysssec
EnergyScripts Simple Download 1.0 - Path Traversal
Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by Kazza
SmarterTools SmarterStats 5.3.3819 - 'frmHelp.aspx' Cross-Site Scripting
by David Hoyt
FreeBSD 8.1/7.3 - 'vm.pmap' Local Race Condition
by Maksymilian Arciemowicz
sirang web-based d-control - Multiple Vulnerabilities
by Abysssec
ColdOfficeView 2.04 - Multiple Blind SQL Injections
by mr_me
ColdGen ColdBookmarks 1.22 - SQL Injection
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
by mr_me
Internet Download Accelerator 5.2 - Buffer Overflow via idaiehlp ActiveX Control
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.
by eidelweiss
Zenphoto 1.3 and 1.3.1.2 - SQL Injection via a Parameter
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.
by Bogdan Calin
Zenphoto 1.3 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
by Bogdan Calin
1024 CMS 2.1.1 - SQL Injection via RSS.php id Parameter
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.
by Stephan Sattler
Weborf < 0.12.3 - Path Traversal via URI ..%2f Sequences
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.
by Rew
WordPress Plugin Events Manager Extended - Persistent Cross-Site Scripting
by Craw
Santafox 2.0.2 - 'search' Cross-Site Scripting
by High-Tech Bridge SA
MySource Matrix 3.28.3 - Cross-Site Scripting via char_map.php Height or Width Parameter
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
by Gjoko Krstic
Joomla! com_aardvertiser 2.1-2.1.1 - SQL Injection
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
by Stephan Sattler
Horde Application Framework <3.3.9 - XSS
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.
by Moritz Naumann
HeffnerCMS 1.22 - 'index.php' Local File Inclusion
by MiND C0re
Micronetsoft RV Dealer Website 1.0 - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
by L0rd CrusAd3r
By Source