Exploitdb Exploits
31,394 exploits tracked across all sources.
(Multiple Products) - 'banner.swf' Cross-Site Scripting
by MustLive
Zigurrat Farsi CMS - '/manager/textbox.asp' SQL Injection
by Isfahan
ParsCMS - SQL Injection via RP Parameter
Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.
by Isfahan
phppool media Domain Verkaus and Auktions Portal - SQL Injection
SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Easy Laster
PhpMyLogon 2 - SQL Injection via Username Parameter
SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
by blake
Joomla! Component com_nfnaddressbook - SQL Injection
by snakespc
DirectAdmin 1.33.6 - 'CMD_DB_VIEW' Cross-Site Scripting
by r0t
Geekhelps ADMP 1.01 - Path Traversal
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php in themes/. NOTE: some of these details are obtained from third party information.
by ITSecTeam
Systemsoftware Community Black Forum - SQL Injection
SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.
by Easy Laster
Joomla! Component com_seek - 'id' SQL Injection
by DevilZ TM
Joomla! Component com_sbsfile - Local File Inclusion
by DevilZ TM
Joomla! Component com_d-greinar - 'maintree' Cross-Site Scripting
by DevilZ TM
Geekhelps ADMP 1.01 - SQL Injection
SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.
by ITSecTeam
Phpkobo AdFreely <1.01 - Path Traversal
Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG_CODE parameter to common.inc.php in (1) codelib/cfg/, (2) codelib/sys/, (3) staff/, and (4) staff/app/; and (5) staff/file.php. NOTE: some of these details are obtained from third party information.
by ITSecTeam
pMyAdmin 3.3.5.1 - 'db_create.php' Cross-Site Scripting
by Liscker
By Source