Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105795 EXPLOITDB text VERIFIED
CF Image Hosting Script 1.1 - 'upload.php' Arbitrary File Upload
by The.Morpheus
EIP-2026-105792 EXPLOITDB text
CF Image Host 1.1 - Remote File Inclusion
by The.Morpheus
EIP-2026-100217 EXPLOITDB text VERIFIED
Comersus 8 Shopping Cart - SQL Injection / Cross-Site Request Forgery
by Sid3^effects
EIP-2026-113380 EXPLOITDB text VERIFIED
Webthaiapp - 'detail.php?cat' Blind SQL Injection
by Xelenonz
EIP-2026-111591 EXPLOITDB text VERIFIED
Puntal 2.1.0 - Remote File Inclusion
by eidelweiss
EIP-2026-109903 EXPLOITDB text
New-CMS - Multiple Vulnerabilities
by Dr. Alberto Fontanella
CVE-2010-1739 EXPLOITDB text VERIFIED
Joomla Com Newsfeeds - SQL Injection
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.
by Archimonde
CVE-2010-1727 EXPLOITDB text VERIFIED
Aspsiteware Jobpost - SQL Injection
SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.
by Sid3^effects
CVE-2010-1726 EXPLOITDB text VERIFIED
Alibabaclone Ec21 Clone - SQL Injection
SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by v3n0m
EIP-2026-105701 EXPLOITDB text VERIFIED
Campsite 3.x - 'article_id' SQL Injection
by Stefan Esser
CVE-2010-1744 EXPLOITDB text VERIFIED
Alibabaclone B2b Gold Script - SQL Injection
SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
by v3n0m
CVE-2007-0053 EXPLOITDB text VERIFIED
ASP Siteware Autodealer < 2.0 - SQL Injection
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.
by Sid3^effects
CVE-2010-1725 EXPLOITDB text VERIFIED
Alibabaclone Alibaba Clone Platinum - SQL Injection
SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.
by v3n0m
CVE-2010-0711 EXPLOITDB text
ASPCode CMS <2.0.0 Build 103 - CSRF
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.
by Dr. Alberto Fontanella
CVE-2010-1742 EXPLOITDB text VERIFIED
Satyadeep Scratcher - XSS
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.
by cr4wl3r
EIP-2026-119459 EXPLOITDB text VERIFIED
Apple Safari 4.0.3 (Windows x86) - 'CSS' Remote Denial of Service (2)
by ITSecTeam
CVE-2010-0817 EXPLOITDB text VERIFIED
Microsoft SharePoint Server 2007 <12.0.0.6421 - XSS
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
by High-Tech Bridge SA
EIP-2026-114657 EXPLOITDB text VERIFIED
Zyke CMS 1.1 - Bypass
by indoushka
EIP-2026-114655 EXPLOITDB text VERIFIED
Zyke CMS 1.0 - Arbitrary File Upload
by indoushka
EIP-2026-114542 EXPLOITDB text VERIFIED
Your Articles Directory - Login Option SQL Injection
by Sid3^effects
EIP-2026-114485 EXPLOITDB text
XT-Commerce 1.0 Beta 1 - Pass / Create and Download Backup
by indoushka
EIP-2026-112849 EXPLOITDB text
Ucenter Projekt 2.0 - Insecure crossdomain (Cross-Site Scripting)
by indoushka
EIP-2026-112764 EXPLOITDB text
TR Forum 1.5 - Multiple Vulnerabilities
by indoushka
CVE-2010-1583 EXPLOITDB text VERIFIED
Tirzen Framework <1.5 - SQL Injection
SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.
by Justin C. Klein Keane
EIP-2026-112309 EXPLOITDB text VERIFIED
Socialware 2.2 - Upload / Cross-Site Scripting
by Sid3^effects