Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106985 EXPLOITDB text VERIFIED
Eyeland Studio Inc. - SQL Injection
by Mr.P3rfekT
EIP-2026-106984 EXPLOITDB text VERIFIED
Eyeland Studio Inc. - 'game.php' SQL Injection
by CoBRa_21
EIP-2026-100522 EXPLOITDB text VERIFIED
Real-time ASP Calendar - SQL Injection
by L0rd CrusAd3r
CVE-2010-5021 EXPLOITDB text VERIFIED
Digital Interchange Document Library <5.8.5 - SQL Injection
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.
by L0rd CrusAd3r
CVE-2010-5023 EXPLOITDB text VERIFIED
Digital Interchange Calendar <5.8.5 - SQL Injection
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.
by L0rd CrusAd3r
CVE-2010-2335 EXPLOITDB text
Yamamah - SQL Injection
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.
by anT!-Tr0J4n
CVE-2010-1300 EXPLOITDB text VERIFIED
Yamamah (Dove Photo Album) 1.00 - SQL Injection
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.
by TheMaStEr
CVE-2010-2336 EXPLOITDB text
Yamamah - Information Disclosure
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.
by anT!-Tr0J4n
EIP-2026-111183 EXPLOITDB text VERIFIED
phpplanner - Cross-Site Scripting / SQL Injection
by anT!-Tr0J4n
EIP-2026-107842 EXPLOITDB text
Infront - SQL Injection
by TheMaStEr
CVE-2010-2338 EXPLOITDB text VERIFIED
Vunet VU Web Visitor Analyst - SQL Injection
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.
by L0rd CrusAd3r
EIP-2026-100609 EXPLOITDB text VERIFIED
VU Mass Mailer - Authentication Bypass
by L0rd CrusAd3r
EIP-2026-100608 EXPLOITDB text VERIFIED
VU Case Manager - Authentication Bypass
by L0rd CrusAd3r
CVE-2010-5008 EXPLOITDB text VERIFIED
BrightSuite Groupware 5.4 - SQL Injection
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.
by L0rd CrusAd3r
EIP-2026-100162 EXPLOITDB text VERIFIED
BDSMIS TraX with Payroll - SQL Injection
by L0rd CrusAd3r
CVE-2010-2263 EXPLOITDB text VERIFIED
F5 Nginx < 0.7.66 - Information Disclosure
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
by Dr_IDE
CVE-2010-2266 EXPLOITDB text VERIFIED
F5 Nginx < 0.7.67 - Path Traversal
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
by Dr_IDE
CVE-2010-2263 EXPLOITDB text VERIFIED
F5 Nginx < 0.7.66 - Information Disclosure
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
by Jose A. Vazquez
EIP-2026-112180 EXPLOITDB text VERIFIED
Site to Store Automobile - Motorcycle Boat SQL Injection
by L0rd CrusAd3r
EIP-2026-112179 EXPLOITDB text VERIFIED
Site for Real Estate - Brokers SQL Injection
by L0rd CrusAd3r
EIP-2026-110477 EXPLOITDB text VERIFIED
Parallels System Automation (PSA) - Local File Inclusion
by Pouya Daneshmand
EIP-2026-107306 EXPLOITDB text VERIFIED
Full Site for Restaurant - SQL Injection
by L0rd CrusAd3r
EIP-2026-106634 EXPLOITDB text VERIFIED
E-PHP B2B Marketplace - Multiple Vulnerabilities
by MizoZ
EIP-2026-106429 EXPLOITDB text VERIFIED
Development Site Professional Liberal - Company Institutional SQL Injection
by L0rd CrusAd3r
EIP-2026-106349 EXPLOITDB text
DaLogin 2.2 - 'FCKeditor' Arbitrary File Upload
by eidelweiss