Exploitdb Exploits
31,344 exploits tracked across all sources.
Hauntmax Haunted House Directory Listing Cms - SQL Injection
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.
by Sid3^effects
GREEZLE - Global Real Estate Agent Site Auth SQL Injection
by L0rd CrusAd3r
Pilotgroup Elms Pro - XSS
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.
by Sid3^effects
Joomla! Component Jreservation 1.5 - SQL Injection / Cross-Site Scripting
by Sid3^effects
(GREEZLE) Global Real Estate Agent Login - Multiple SQL Injections
by L0rd CrusAd3r
Adobe Flash Player
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
by anonymous
CVSS 7.8
Juniper Networks SA2000 SSL VPN Appliance - 'welcome.cgi' Cross-Site Scripting
by Richard Brain
Mckenzie Creations VRM <3.5 - SQL Injection
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.
by Sid3^effects
Dmxready Online Notebook Manager - SQL Injection
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
by L0rd CrusAd3r
Phreebooks 2.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
by Gustavo Sorondo
Hotel / Resort Site Script with OnLine Reservation System - SQL Injection
by L0rd CrusAd3r
MCLogin System <1.3 - SQL Injection
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.
by L0rd CrusAd3r
By Source