Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111722 EXPLOITDB text VERIFIED
ReCMS - 'users_lang' Directory Traversal
by Locu
EIP-2026-109940 EXPLOITDB text VERIFIED
NinkoBB - Cross-Site Request Forgery
by ADEO Security
EIP-2026-108325 EXPLOITDB text
Joomla! Component com_dateconverter 0.1 - SQL Injection
by RoAd_KiLlEr
CVE-2010-4980 EXPLOITDB text VERIFIED
iScripts ReserveLogic 1.0 - SQL Injection
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
by Salvatore Fresta
CVE-2010-2624 EXPLOITDB text VERIFIED
Iscripts Easysnaps - SQL Injection
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.
by Salvatore Fresta
EIP-2026-107885 EXPLOITDB text
Interscan Web Security 5.0 - Persistent Cross-Site Scripting
by Ivan Huertas
EIP-2026-107135 EXPLOITDB text VERIFIED
Flatnux 2010-06.09 - 'find' Cross-Site Scripting
by ITSecTeam
EIP-2026-106562 EXPLOITDB text VERIFIED
DPScms - 'q' SQL Injection / Cross-Site Scripting
by Ariko-Security
EIP-2026-100546 EXPLOITDB text VERIFIED
SIDA University System - SQL Injection
by K053
EIP-2026-100543 EXPLOITDB text
Setiran CMS - Blind SQL Injection
by Th3 RDX
CVE-2010-5330 EXPLOITDB CRITICAL text VERIFIED
Ubiquiti - Command Injection
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.
by emgent
CVSS 9.8
EIP-2026-112537 EXPLOITDB text VERIFIED
System CMS Contentia - 'news.php' SQL Injection
by GlaDiaT0R
CVE-2010-2623 EXPLOITDB text
Internetdm Bed And Breakfast - SQL Injection
SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.
by JaMbA
CVE-2010-2622 EXPLOITDB text VERIFIED
Joomanager - SQL Injection
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
by Sid3^effects
CVE-2010-2690 EXPLOITDB text
JOOFORGE Gamesbox <1.0.2 - SQL Injection
SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php.
by v3n0m
CVE-2010-4968 EXPLOITDB text
Joomla! com_wmtpic <1.0 - SQL Injection
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
by RoAd_KiLlEr
EIP-2026-107455 EXPLOITDB text
Golf Club Site - SQL Injection
by JaMbA
EIP-2026-119372 EXPLOITDB text
Gekko CMS - SQL Injection
by []0iZy5
EIP-2026-116122 EXPLOITDB text VERIFIED
Qt 4.6.3 - Remote Denial of Service
by Luigi Auriemma
EIP-2026-114553 EXPLOITDB text VERIFIED
YPNinc PHP Realty Script - 'docID' SQL Injection
by v3n0m
CVE-2010-4972 EXPLOITDB text VERIFIED
YPNinc JokeScript - SQL Injection
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.
by v3n0m
CVE-2010-2689 EXPLOITDB text VERIFIED
Internet DM WebDM CMS - SQL Injection
SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL commands via the cf_id parameter.
by Dr.0rYX & Cr3W-DZ
CVE-2010-1327 EXPLOITDB text VERIFIED
TornadoStore <1.4.3 - SQL Injection
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
by Lucas Apa
EIP-2026-111031 EXPLOITDB text VERIFIED
PHPDirector 0.30 - 'videos.php' SQL Injection
by Mr-AbdoX
CVE-2010-2616 EXPLOITDB text VERIFIED
Paul Mcenery Php Bible Search - SQL Injection
SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.
by L0rd CrusAd3r