Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-1534 EXPLOITDB text VERIFIED
com_shoutbox - Path Traversal via Controller Parameter
Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by Vrs-hCk
CVE-2010-1307 EXPLOITDB text VERIFIED
com_joomlaupdater - Path Traversal via Controller Parameter
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by Vrs-hCk
CVE-2010-1353 EXPLOITDB text VERIFIED
wowjoomla com_loginbox - Path Traversal via View Parameter
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
by Vrs-hCk
CVE-2010-1305 EXPLOITDB text VERIFIED
Joomla! com_jinventory <1.26.03 - Path Traversal
Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by Chip d3 bi0s
EIP-2026-108275 EXPLOITDB text VERIFIED
Joomla! Component com_bca-rss-syndicator - Local File Inclusion
by Vrs-hCk
EIP-2026-108085 EXPLOITDB text
jevoncms - Local/Remote File Inclusion
by eidelweiss
EIP-2026-114401 EXPLOITDB text
x10 mirco blogging 121 - SQL Injection
by ITSecTeam
EIP-2026-112341 EXPLOITDB text VERIFIED
Solutive CMS - SQL Injection
by Th3 RDX
EIP-2026-111870 EXPLOITDB text
SAGU-PRO 1.0 - Multiple Remote File Inclusions
by mat
EIP-2026-109334 EXPLOITDB text VERIFIED
MassMirror Uploader - Multiple Remote File Inclusions
by cr4wl3r
CVE-2010-1983 EXPLOITDB text VERIFIED
Redcomponent Com Redtwitter - Path Traversal
Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.
by NoGe
CVE-2010-1531 EXPLOITDB text VERIFIED
Joomla! com_redshop 1.0.x - Path Traversal
Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
by NoGe
CVE-2010-1306 EXPLOITDB text VERIFIED
com_joomlapicasa2 2.0 and 2.0.5 - Path Traversal via Controller Parameter
Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
by Vrs-hCk
EIP-2026-108594 EXPLOITDB text VERIFIED
Joomla! Component com_wisroyq 1.1 - Local File Inclusion
by NoGe
EIP-2026-108534 EXPLOITDB text VERIFIED
Joomla! Component com_serie - SQL Injection
by DevilZ TM
EIP-2026-108508 EXPLOITDB text VERIFIED
Joomla! Component com_ranking - SQL Injection
by DevilZ TM
EIP-2026-108492 EXPLOITDB text VERIFIED
Joomla! Component com_press - SQL Injection
by DevilZ TM
CVE-2008-7176 EXPLOITDB text VERIFIED
Facil CMS 0.1RC - Path Traversal via change_lang or modload Parameter
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.
by eidelweiss
EIP-2026-104987 EXPLOITDB text VERIFIED
Advanced Management For Services Sites - Bypass Create And Download SQL Backup
by indoushka
EIP-2026-104410 EXPLOITDB text VERIFIED
QuickEStore 6.1 - Backup Dump
by indoushka
EIP-2026-111198 EXPLOITDB text VERIFIED
phpscripte24 Vor und Rückwärts Auktions System - Blind SQL Injection
by Easy Laster
CVE-2009-3119 EXPLOITDB text
X-iweb.ru Download System Msf - SQL Injection
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.
by Inj3ct0r
CVE-2010-1350 EXPLOITDB text VERIFIED
com_jp_jobs < 1.4.1 - SQL Injection via id Parameter
SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
by Valentin
EIP-2026-107140 EXPLOITDB text
Flatpress 0.909.1 - Persistent Cross-Site Scripting
by ITSecTeam
EIP-2026-103949 EXPLOITDB text
Java Mini Web Server 1.0 - Directory Traversal / Cross-Site Scripting
by cp77fk4r