Exploitdb Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-4446 EXPLOITDB text VERIFIED
phpInstantGallery 1.1 - Cross-Site Scripting via PATH_INFO
Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by indoushka
EIP-2026-110934 EXPLOITDB text
phPay 2.2a - Backup
by indoushka
EIP-2026-110924 EXPLOITDB text
phpAuction - Cross-Site Scripting
by indoushka
EIP-2026-110780 EXPLOITDB text VERIFIED
PHP Uploader Downloader 2.0 - Cross-Site Scripting
by indoushka
EIP-2026-110779 EXPLOITDB text VERIFIED
PHP Uploader Downloader 2.0 - Arbitrary File Upload
by indoushka
EIP-2026-110701 EXPLOITDB text VERIFIED
PHP Football 1.0 - Cross-Site Scripting
by indoushka
CVE-2005-0952 EXPLOITDB text VERIFIED
PaFileDB 3.1 - Cross-Site Scripting via id Parameter
Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by indoushka
EIP-2026-110371 EXPLOITDB text VERIFIED
osCommerce 2.2rc2a - Bypass/Create and Download Backup
by indoushka
EIP-2026-109992 EXPLOITDB text
Nuked-klaN SP4 - Remote File Inclusion
by indoushka
EIP-2026-109989 EXPLOITDB text VERIFIED
Nuked-klaN 1.7.7 - Remote File Inclusion
by indoushka
EIP-2026-109787 EXPLOITDB text VERIFIED
MyShoutPro 1.2 Final - Cross-Site Scripting
by indoushka
EIP-2026-109758 EXPLOITDB text
MyCart shopping cart - Arbitrary File Upload
by indoushka
EIP-2026-109397 EXPLOITDB text VERIFIED
Mega Upload 1.45 - Arbitrary File Upload
by indoushka
EIP-2026-109191 EXPLOITDB text VERIFIED
Lizard Cart - Arbitrary File Upload
by indoushka
EIP-2026-109038 EXPLOITDB text
kooora 3.0 - AR Cross-Site Scripting
by indoushka
CVE-2009-4451 EXPLOITDB text VERIFIED
kandalf upper 0.1 - Unauthenticated Arbitrary File Upload and Remote Code Execution via upper.php
Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in fileup/.
by indoushka
EIP-2026-107832 EXPLOITDB text
Info Fisier 1.0 - Arbitrary File Upload
by wlhaan hacker
EIP-2026-107804 EXPLOITDB text VERIFIED
IMG2ASCII - Cross-Site Scripting
by indoushka
EIP-2026-107790 EXPLOITDB text
Image File Upload - Arbitrary File Upload
by indoushka
EIP-2026-107660 EXPLOITDB text
HowMany 2.6 - Remote File Inclusion
by indoushka
CVE-2009-4456 EXPLOITDB text VERIFIED
Green Desktiny <2.3.1 - SQL Injection
SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.
by kaMtiEz
EIP-2026-107335 EXPLOITDB text VERIFIED
Gallery 2.3 - Remote File Inclusion
by indoushka
EIP-2026-107225 EXPLOITDB text VERIFIED
FreeForum 1.7 - Remote File Inclusion
by indoushka
EIP-2026-107224 EXPLOITDB text VERIFIED
FreeForum 1.7 - Cross-Site Scripting
by indoushka
CVE-2009-4461 EXPLOITDB text VERIFIED
FlatPress 0.909 - Cross-Site Scripting via PATH_INFO to contact.php, login.php, and search.php
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.
by indoushka