Text Exploits
31,386 exploits tracked across all sources.
iOffice 0.1 - 'parametre' Remote Command Execution
by Marshall Whittaker
Kayako eSupport <3.70.02 - SQL Injection
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.
by Sid3^effects
Subrion Auto Classifieds - Persistent Cross-Site Scripting
by Sid3^effects
Kayako eSupport 3.70.02 - SQL Injection
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
by Sid3^effects
StaticXT (com_staticxt) - SQL Injection via id Parameter
SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
by Palyo34 & KroNicKq
Joomla! Component com_spa - SQL Injection (2)
by Palyo34 & KroNicKq
Freelancers Marketplace Script - Persistent Cross-Site Scripting
by Sid3^effects
Freelancer Marketplace Script - Arbitrary File Upload
by Sid3^effects
Haihaisoft PDF Reader OCX Control 1.1.2.0 - Remote Buffer Overflow (PoC)
by shinnai
Pre SoftClones Marketing Management System - Authentication Bypass
by D4rk357
Pre Projects Pre Podcast Portal - SQL Injection
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
by D4rk357
Pre Dynamic Institution - Web Authentication Bypass
by D4rk357
ScriptsFeed & BrotherScripts - SQL Injection
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.
by k4k4shi
Novell GroupWise <7.0-8.0 - Buffer Overflow
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.
by Francis Provencher
Spitfire 1.0.381 - Cross-Site Scripting / Cross-Site Request Forgery
by Nijel the Destroyer
Pligg CMS 1.0.4 - 'search.php' Cross-Site Scripting
by High-Tech Bridge SA
By Source