Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108632 EXPLOITDB text VERIFIED
Joomla! Component EasyBlog - Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-103866 EXPLOITDB text VERIFIED
Asterisk Recording Interface 0.7.15/0.10 - Multiple Vulnerabilities
by TurboBorland
CVE-2010-2630 EXPLOITDB text VERIFIED
libtiff - Denial of Service via Malformed TIFF File
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
by Tom Lane
EIP-2026-102366 EXPLOITDB text VERIFIED
dotDefender 4.02 - 'clave' Cross-Site Scripting
by David K
EIP-2026-111834 EXPLOITDB text VERIFIED
RunCMS 2.1 - 'magpie_debug.php' Cross-Site Scripting
by John Leitch
EIP-2026-106256 EXPLOITDB text VERIFIED
CSSTidy 1.3 - 'css_optimiser.php' Cross-Site Scripting
by John Leitch
EIP-2026-102398 EXPLOITDB text VERIFIED
Mac's CMS 1.1.4 - 'SearchString' Cross-Site Scripting
by 10n1z3d
CVE-2010-4984 EXPLOITDB text VERIFIED
My Kazaam Notes Management System - SQL Injection
SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.
by L0rd CrusAd3r
CVE-2010-2699 EXPLOITDB text VERIFIED
Edge PHP Clickbank Affiliate Marketplace Script - SQL Injection
SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.
by L0rd CrusAd3r
EIP-2026-112043 EXPLOITDB text VERIFIED
Sillaj time tracking tool - Authentication Bypass
by L0rd CrusAd3r
CVE-2010-4985 EXPLOITDB text VERIFIED
My Kazaam Notes Management System - XSS
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.
by L0rd CrusAd3r
CVE-2010-4982 EXPLOITDB text
My Kazaam Address & Contact Organizer - SQL Injection
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.
by v3n0m
CVE-2010-2694 EXPLOITDB text
Joomla! com_redshop 1.0 - SQL Injection
SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.
by v3n0m
EIP-2026-108840 EXPLOITDB text
Joomla! Component Rapid-Recipe - Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-108839 EXPLOITDB text VERIFIED
Joomla! Component Rapid-Recipe - HTML Injection
by Sid3^effects
EIP-2026-108808 EXPLOITDB text
Joomla! Component MySMS - Arbitrary File Upload
by Sid3^effects
EIP-2026-108806 EXPLOITDB text
Joomla! Component MyHome - Blind SQL Injection
by Sid3^effects
EIP-2026-106836 EXPLOITDB text VERIFIED
eliteCMS 1.01 - Multiple Cross-Site Scripting Vulnerabilities
by 10n1z3d
CVE-2010-2700 EXPLOITDB text VERIFIED
Edge PHP Clickbank Affiliate Marketplace Script - XSS
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.
by L0rd CrusAd3r
EIP-2026-114510 EXPLOITDB text VERIFIED
Yappa 3.1.2 - 'yappa.php' Multiple Remote Command Execution Vulnerabilities
by Sn!pEr.S!Te Hacker
EIP-2026-113752 EXPLOITDB text VERIFIED
WordPress Plugin Firestats 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities
by Jelmer de Hen
EIP-2026-113749 EXPLOITDB text VERIFIED
WordPress Plugin Firestats - Remote Configuration File Download
by Jelmer de Hen
EIP-2026-112379 EXPLOITDB text VERIFIED
sphider 1.3.5 - Remote File Inclusion
by Li0n-PaL
CVE-2010-2858 EXPLOITDB text VERIFIED
SimpNews < 2.47.03 - Cross-Site Scripting via Layout and Sortorder Parameters
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
by MustLive
EIP-2026-111705 EXPLOITDB text VERIFIED
Real Estate Manager 1.0.1 - 'index.php' Cross-Site Scripting
by bi0