Exploitdb Exploits
31,394 exploits tracked across all sources.
ScriptsFeed & BrotherScripts - SQL Injection
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.
by k4k4shi
Novell GroupWise <7.0-8.0 - Buffer Overflow
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.
by Francis Provencher
Spitfire 1.0.381 - Cross-Site Scripting / Cross-Site Request Forgery
by Nijel the Destroyer
Pligg CMS 1.0.4 - 'search.php' Cross-Site Scripting
by High-Tech Bridge SA
PHPWCMS 1.4.5 - 'PHPwcms.php' Cross-Site Scripting
by High-Tech Bridge SA
Joomla! Component redSHOP 1.0.23.1 - Blind SQL Injection
by Salvatore Fresta
Gekko Web Builder 9.0 - 'index.php' Cross-Site Scripting
by High-Tech Bridge SA
FestOS 2.3 - 'contents' Cross-Site Scripting
by High-Tech Bridge SA
Campsite CMS - Remote Persistent Cross-Site Scripting
by D4rk357
ScriptsFeed/BrotherScripts - SQL Injection
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
by D4rk357
Unreal Engine - 'ReceivedRawBunch()' Denial of Service
by Luigi Auriemma
Novell Groupwise Webaccess - Stack Overflow
by Francis Provencher
ORACLE Business Process Management (Process Administrator) 5.7-6.0-10.3 - Cross-Site Scripting
by Markot
Apache Struts 2.0.0-2.1.8.1 - Remote Code Execution via OGNL Context Variable Manipulation
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504.
by Meder Kydyraliev
Oracle Solaris <10 - Info Disclosure
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS.
by Frank Stuart
Oracle OpenSolaris 10 - Info Disclosure
Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rdist.
by Monarch Rich
By Source