Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108255 EXPLOITDB text VERIFIED
Joomla! Component com_adds - Blind SQL Injection
by DevilZ TM
CVE-2010-2673 EXPLOITDB text VERIFIED
Devana < 1.6.6 - SQL Injection via Profile View ID Parameter
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Valentin
EIP-2026-104864 EXPLOITDB text VERIFIED
68KB Knowledge Base Script 1.0.0rc2 - Search SQL Injection
by Jelmer de Hen
CVE-2010-2676 EXPLOITDB text VERIFIED
Open Web Analytics OWA <1.2.3 - Path Traversal
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.
by ITSecTeam
CVE-2007-5235 EXPLOITDB text VERIFIED
uebimiau 2.7.2-2.7.10 - Cross-Site Scripting via f_email Parameter
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML via the f_email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by cp77fk4r
EIP-2026-112115 EXPLOITDB text VERIFIED
Simple Machines Forum (SMF) 1.1.8 - 'avatar' Remote PHP File Execute
by JosS
CVE-2010-2677 EXPLOITDB text VERIFIED
Open Web Analytics (OWA) 1.2.3 - RCE
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. NOTE: some of these details are obtained from third party information.
by ITSecTeam
EIP-2026-109774 EXPLOITDB text VERIFIED
MyOWNspace 8.2 - Multiple Local File Inclusions
by ITSecTeam
EIP-2026-108547 EXPLOITDB text VERIFIED
Joomla! Component com_solution - SQL Injection
by DevilZ TM
EIP-2026-104860 EXPLOITDB text VERIFIED
68KB - Multiple Remote File Inclusions
by ITSecTeam
EIP-2026-111422 EXPLOITDB text VERIFIED
post Card - 'catid' SQL Injection
by Hussin X
EIP-2026-109088 EXPLOITDB text VERIFIED
leaftec CMS - Multiple Vulnerabilities
by Valentin
CVE-2010-1265 EXPLOITDB text VERIFIED
Adam Corley dcsFlashGames - SQL Injection
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
by kaMtiEz
EIP-2026-107155 EXPLOITDB text
Flirt Matching Sms System - SQL Injection
by Easy Laster
EIP-2026-106337 EXPLOITDB text
DaFun Spirit 2.2.5 - Multiple Remote File Inclusions
by 2010-03-26
EIP-2026-106317 EXPLOITDB text
CyberCMS - SQL Injection
by hc0de
EIP-2026-106011 EXPLOITDB text VERIFIED
CmsFaethon 2.2.0 (ultimate.7z) - Multiple Vulnerabilities
by eidelweiss
EIP-2026-105616 EXPLOITDB text
BPTutors Tutoring site script - Cross-Site Request Forgery (Add Admin)
by bi0
CVE-2010-1176 EXPLOITDB text VERIFIED
Safari on Apple iPhone OS 3.1.3 for iPod touch - DoS
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods, possibly a related issue to CVE-2009-0075.
by Nishant Das Patnaik
CVE-2010-1179 EXPLOITDB text VERIFIED
Safari on iPhone OS 3.1.3 - Denial of Service or Remote Code Execution via VML recolorinfo numcolors Attribute
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to CVE-2007-0024.
by Nishant Das Patnaik
EIP-2026-119107 EXPLOITDB text VERIFIED
SAP GUI 7.00 - BExGlobal Active-X unsecure method
by Alexey Sintsov
EIP-2026-113355 EXPLOITDB text VERIFIED
WebsiteBaker 2.8.1 - DataBase Backup Disclosure
by Tr0y-x
CVE-2010-1268 EXPLOITDB text VERIFIED
justVisual CMS 2.0 - Path Traversal
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files directory traversal sequences in the p parameter. NOTE: some of these details are obtained from third party information.
by eidelweiss
CVE-2010-1336 EXPLOITDB text VERIFIED
INVOhost 3.4 - SQL Injection via site.php id/newlanguage Parameters
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. NOTE: some of these details are obtained from third party information.
by Andrés Gómez
EIP-2026-107881 EXPLOITDB text
Interactivefx.ie CMS - SQL Injection
by Inj3ct0r