Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118930 EXPLOITDB text VERIFIED
Multi-Threaded HTTP Server 1.1 - Directory Traversal (2)
by Dr_IDE
CVE-2009-4535 EXPLOITDB text VERIFIED
Mongoose <2.8.0 - Info Disclosure
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
by Dr_IDE
EIP-2026-118226 EXPLOITDB text VERIFIED
Acritum Femitter 1.03 - Directory Traversal
by Dr_IDE
EIP-2026-113023 EXPLOITDB text VERIFIED
vBulletin Two-Step External Link Module - 'externalredirect.php' Cross-Site Scripting
by Edgard Chammas
CVE-2010-1947 EXPLOITDB text VERIFIED
Openmairie Openregistrecil - Path Traversal
Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter. NOTE: this may be related to CVE-2007-2069.
by cr4wl3r
CVE-2010-1950 EXPLOITDB text VERIFIED
Emultisoft Com Jnewspaper - SQL Injection
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Don Tukulesto
CVE-2010-1877 EXPLOITDB text VERIFIED
Jtmreseller Com Jtm - SQL Injection
SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.
by kaMtiEz
EIP-2026-103995 EXPLOITDB text VERIFIED
Multi-Threaded HTTP Server 1.1 - Directory Traversal (1)
by chr1x
CVE-2010-1320 EXPLOITDB text VERIFIED
MIT Kerberos <1.8.2 - Use After Free
Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.
by Joel Johnson
CVE-2010-5057 EXPLOITDB text
CMS Ariadna 1.1 - SQL Injection
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.
by Andrés Gómez
EIP-2026-118651 EXPLOITDB text VERIFIED
HTTP File Server 2.2 - Security Bypass / Denial of Service
by Luigi Auriemma
EIP-2026-114966 EXPLOITDB text VERIFIED
Avtech Software - ActiveX 'avc781viewer.dll' Multiple Vulnerabilities
by LiquidWorm
EIP-2026-110316 EXPLOITDB text
Openreglement 1.04 - Local File Inclusion / Remote File Inclusion
by cr4wl3r
EIP-2026-109817 EXPLOITDB text
N/X Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities
by eidelweiss
EIP-2026-109020 EXPLOITDB text VERIFIED
Kleophatra CMS 0.1.1 - 'module' Cross-Site Scripting
by anT!-Tr0J4n
CVE-2010-5056 EXPLOITDB text VERIFIED
GBU Facebook 1.0.5 - SQL Injection
SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.
by kaMtiEz
EIP-2026-107146 EXPLOITDB text
Flex File Manager - Arbitrary File Upload
by Mr.MLL
CVE-2010-5058 EXPLOITDB text
CMS Ariadna 1.1 - SQL Injection
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Andrés Gómez
EIP-2026-101306 EXPLOITDB text
Huawei EchoLife HG520 - Remote Information Disclosure
by hkm
EIP-2026-101023 EXPLOITDB text
Huawei EchoLife HG520c - Modem Reset (Denial of Service)
by hkm
EIP-2026-100986 EXPLOITDB text
Apple iPhone 3.1.2 - '7D11' Model MB702LL Mobile Safari Denial of Service
by Matthew Bergin
CVE-2010-1497 EXPLOITDB text VERIFIED
dl_stats < 2.0 - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by Valentin Hoebel
EIP-2026-111724 EXPLOITDB text VERIFIED
Redaxo 4.2.1 - Remote File Inclusion
by eidelweiss
EIP-2026-110317 EXPLOITDB text VERIFIED
Openscrutin 1.03 - Local File Inclusion / Remote File Inclusion
by cr4wl3r
CVE-2010-1603 EXPLOITDB text VERIFIED
Zimbllc Com Zimbcore - Path Traversal
Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity