Exploitdb Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112461 EXPLOITDB text
Subdreamer 3.0.1 - CMS upload
by indoushka
EIP-2026-111486 EXPLOITDB text VERIFIED
Preisschlacht 4.0 Flash System - 'index.php?aid' SQL Injection
by Easy Laster
EIP-2026-110669 EXPLOITDB text
PHP Classifieds 7.5 - Blind SQL Injection
by ITSecTeam
EIP-2026-110582 EXPLOITDB text
Phenix 3.5b - SQL Injection
by ITSecTeam
CVE-2010-1055 EXPLOITDB text VERIFIED
osDate 2.1.9 and 2.5.4 - Remote Code Execution via config[forum_installed] Parameter
Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to (1) forum/adminLogin.php and (2) forum/userLogin.php. NOTE: some of these details are obtained from third party information.
by NoGe
EIP-2026-109939 EXPLOITDB text VERIFIED
Ninja RSS Syndicator 1.0.8 - Local File Inclusion
by jdc
EIP-2026-109906 EXPLOITDB text VERIFIED
Newbie CMS - File Disclosure
by JIKO
EIP-2026-108530 EXPLOITDB text VERIFIED
Joomla! Component com_sectionex - Local File Inclusion
by AtT4CKxT3rR0r1ST
EIP-2026-108517 EXPLOITDB text VERIFIED
Joomla! Component com_rpx Ulti RPX 2.1.0 - Local File Inclusion
by jdc
EIP-2026-108516 EXPLOITDB text VERIFIED
Joomla! Component com_route - SQL Injection
by N2n-Hacker
CVE-2010-1056 EXPLOITDB text VERIFIED
RokDownloads < 1.0.1 - Unauthenticated Path Traversal via Controller Parameter
Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
by AtT4CKxT3rR0r1ST
EIP-2026-108464 EXPLOITDB text VERIFIED
Joomla! Component com_org - 'letter' SQL Injection
by kazuya
EIP-2026-108431 EXPLOITDB text VERIFIED
Joomla! Component com_linkr - Local File Inclusion
by AtT4CKxT3rR0r1ST
CVE-2010-1219 EXPLOITDB text VERIFIED
JA News (com_janews) 1.0 - Path Traversal
Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
by AtT4CKxT3rR0r1ST
CVE-2010-0972 EXPLOITDB text VERIFIED
Joomla! com_gcalendar 2.1.5 - Path Traversal
Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
by jdc
EIP-2026-108358 EXPLOITDB text VERIFIED
Joomla! Component com_ganalytics - Local File Inclusion
by AtT4CKxT3rR0r1ST
EIP-2026-108279 EXPLOITDB text VERIFIED
Joomla! Component com_bidding - SQL Injection
by N2n-Hacker
EIP-2026-107892 EXPLOITDB text
Interspire SHOPPING CART 5.5.4 - Ultimate Edition backup dump
by indoushka
EIP-2026-107226 EXPLOITDB text
FreeHost 1.00 - Arbitrary File Upload
by indoushka
EIP-2026-106601 EXPLOITDB text
Duhok Forum 1.0 script - Cross-Site Scripting
by indoushka
EIP-2026-106534 EXPLOITDB text VERIFIED
Domain Verkaus & Auktions Portal - 'index.php' SQL Injection
by Easy Laster
EIP-2026-105801 EXPLOITDB text VERIFIED
CH-CMS.ch 2 - Multiple Arbitrary File Upload Vulnerabilities
by EL-KAHINA
EIP-2026-105800 EXPLOITDB text
CH-CMS.ch 2 - Arbitrary File Upload
by EL-KAHINA
EIP-2026-105173 EXPLOITDB text VERIFIED
Andromeda 1.9.2 - 's' Cross-Site Scripting / Session Fixation
by indoushka
CVE-2010-1058 EXPLOITDB text VERIFIED
Phpkobo Address Book Script <1.09 - Path Traversal
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.
by Pouya Daneshmand