Exploitdb Exploits
31,394 exploits tracked across all sources.
Scratcher - SQL Injection via projects.php id Parameter
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.
by cr4wl3r
iScripts VisualCaster - SQL Injection
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter.
by Sid3^effects
DZCP (deV!L_z Clanportal) 1.5.3 - Multiple Vulnerabilities
by indoushka
chcounter 3.1.3 - SQL Injection via login_name Parameter
SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Valentin
velBox 1.2 - Insecure Cookie Authentication Bypass
by indoushka
Tele Data's Contact Management Server 0.9 - 'Username' SQL Injection
by John Leitch
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
by 41.w4r10r
Softbiz Dating 1.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d) index.php, and (e) news_desc.php.
by 41.w4r10r
Pligg CMS 1.0.4 - 'story.php' SQL Injection
by Don Tukulesto
PHP Video Battle Script - SQL Injection via browse.html cat Parameter
SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by v3n0m
Modelbook - SQL Injection via casting_view.php adnum Parameter
SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.
by v3n0m
Joomla! Component Wap4Joomla! - 'wapmain.php' SQL Injection
by Manas58
Joomla! Component com_jesectionfinder - Arbitrary File Upload
by Sid3^effects
Apache ActiveMQ 5.3 - 'admin/queueBrowse' Cross-Site Scripting
by arun kethipelly
PHP-Quick-Arcade 3.0.21 - SQL Injection via phpqa_user_c or id Parameter
Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php.
by ITSecTeam
SmartBlog 1.3 - SQL Injection / Cross-Site Scripting
by indoushka
ProArcadeScript - 'search.php' Cross-Site Scripting
by Sid3^effects
PHP-Quick-Arcade 3.0.21 - Cross-Site Scripting via serv Parameter
Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.
by ITSecTeam
com_ultimateportfolio 1.0 - Path Traversal via Controller Parameter
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
com_smartsite 1.0.0 - Path Traversal via Controller Parameter
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
Code-Garage NoticeBoard 1.3 - Path Traversal via Controller Parameter
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
By Source