Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-100546 EXPLOITDB text VERIFIED
SIDA University System - SQL Injection
by K053
EIP-2026-100543 EXPLOITDB text
Setiran CMS - Blind SQL Injection
by Th3 RDX
CVE-2010-5330 EXPLOITDB CRITICAL text VERIFIED
Ubiquiti AirOS < 4.0.1 - Command Injection via stainfo.cgi ifname Parameter
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.
by emgent
CVSS 9.8
EIP-2026-112537 EXPLOITDB text VERIFIED
System CMS Contentia - 'news.php' SQL Injection
by GlaDiaT0R
CVE-2010-2623 EXPLOITDB text
Internet DM Specialist Bed and Breakfast - SQL Injection via pp_id Parameter
SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.
by JaMbA
CVE-2010-2622 EXPLOITDB text VERIFIED
Joomanager - SQL Injection via catid Parameter
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
by Sid3^effects
CVE-2010-2690 EXPLOITDB text
JOOFORGE Gamesbox <1.0.2 - SQL Injection
SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php.
by v3n0m
CVE-2010-4968 EXPLOITDB text
Joomla! com_wmtpic <1.0 - SQL Injection
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
by RoAd_KiLlEr
EIP-2026-107455 EXPLOITDB text
Golf Club Site - SQL Injection
by JaMbA
EIP-2026-119372 EXPLOITDB text
Gekko CMS - SQL Injection
by []0iZy5
EIP-2026-116122 EXPLOITDB text VERIFIED
Qt 4.6.3 - Remote Denial of Service
by Luigi Auriemma
EIP-2026-114553 EXPLOITDB text VERIFIED
YPNinc PHP Realty Script - 'docID' SQL Injection
by v3n0m
CVE-2010-4972 EXPLOITDB text VERIFIED
YPNinc JokeScript - SQL Injection via ypncat_id Parameter
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.
by v3n0m
CVE-2010-2689 EXPLOITDB text VERIFIED
Internet DM WebDM CMS - SQL Injection
SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL commands via the cf_id parameter.
by Dr.0rYX & Cr3W-DZ
CVE-2010-1327 EXPLOITDB text VERIFIED
TornadoStore <1.4.3 - SQL Injection
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
by Lucas Apa
EIP-2026-111031 EXPLOITDB text VERIFIED
PHPDirector 0.30 - 'videos.php' SQL Injection
by Mr-AbdoX
CVE-2010-2616 EXPLOITDB text VERIFIED
PHP Bible Search - SQL Injection via Chapter Parameter
SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.
by L0rd CrusAd3r
CVE-2010-2617 EXPLOITDB text VERIFIED
PHP Bible Search - Cross-Site Scripting via Chapter Parameter
Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.
by L0rd CrusAd3r
CVE-2010-2683 EXPLOITDB text VERIFIED
Customer Paradigm PageDirector CMS - SQL Injection
SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter.
by v3n0m
CVE-2010-4979 EXPLOITDB text VERIFIED
CANDID - SQL Injection via image_id Parameter
SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
by L0rd CrusAd3r
CVE-2010-4978 EXPLOITDB text VERIFIED
CANDID - Cross-Site Scripting via image_id Parameter
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
by L0rd CrusAd3r
EIP-2026-105226 EXPLOITDB text VERIFIED
ArcademSX 2.904 - 'cat' Cross-Site Scripting
by Th3 RDX
EIP-2026-105111 EXPLOITDB text
Allomani Super MultiMedia 2.5 - Cross-Site Request Forgery (Add Admin)
by G0D-F4Th3r
EIP-2026-105106 EXPLOITDB text
Allomani E-Store 1.0 - Cross-Site Request Forgery (Add Admin) (1)
by G0D-F4Th3r
EIP-2026-104308 EXPLOITDB text
LIOOSYS CMS - 'news.php' SQL Injection
by GlaDiaT0R