Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-3565 EXPLOITDB text VERIFIED
McAfee IntruShield Network Security Manager < 5.1.11.6 - Cross-Site Scripting via Login.jsp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.
by Daniel King
CVE-2009-3566 EXPLOITDB text VERIFIED
McAfee IntruShield Network Security Manager < 5.1.11.8.1 - Cross-Site Scripting via Session Cookie
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
by Daniel King
EIP-2026-115517 EXPLOITDB text VERIFIED
Kingsoft Internet Security 9 - Denial of Service
by Francis Provencher
CVE-2009-3850 EXPLOITDB text VERIFIED
Blender 2.34, 2.35a, 2.40, 2.49b - Remote Code Execution via ScriptLink SDNA onLoad Action
Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
by Core Security
EIP-2026-111414 EXPLOITDB text VERIFIED
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (1)
by Abysssec
EIP-2026-106874 EXPLOITDB text VERIFIED
eNdonesia CMS 8.4 - Local File Inclusion
by s4r4d0
CVE-2009-3244 EXPLOITDB text VERIFIED
Adobe Shockwave Player < 11.5.1.601 - Heap-Based Buffer Overflow via PlayerVersion Property
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.
by Francis Provencher
CVE-2009-3913 EXPLOITDB text VERIFIED
Xerox Fiery Webtools - SQL Injection
SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter.
by Bernardo Trigo
CVE-2009-4873 EXPLOITDB text VERIFIED
Rhino Software Serv-U Web Client 9.0.0.5 - Stack-Based Buffer Overflow via Long Session Cookie
Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.
by Nikolas Rangos
CVE-2009-3911 EXPLOITDB text VERIFIED
TFTgallery 0.13 - Cross-Site Scripting via Sample Parameter
Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter.
by blake
CVE-2009-3912 EXPLOITDB text VERIFIED
TFTgallery 0.13 - Path Traversal via Album Parameter
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.
by blake
CVE-2009-3856 EXPLOITDB text VERIFIED
Twilight CMS < 4.1 - Cross-Site Scripting via News Calendar Parameter
Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information.
by Vladimir Vorontsov
EIP-2026-104047 EXPLOITDB text VERIFIED
PacketVideo Twonky Server 4.4.17/5.0.65 - Cross-Site Scripting / HTML Injection
by Davide Canali
CVE-2009-3904 EXPLOITDB text VERIFIED
CubeCart 4.3.4 - Unauthenticated Administrative Access Bypass via Empty Session ID or Headers
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3) User-Agent header.
by Bogdan Calin
EIP-2026-100674 EXPLOITDB text VERIFIED
OpenBSD 4.6 / NetBSD 5.0.1 - 'printf(1)' Format String Parsing Denial of Service
by Maksymilian Arciemowicz
EIP-2026-100668 EXPLOITDB text VERIFIED
BSD (Multiple Distributions) - 'printf(3)' Memory Corruption
by Maksymilian Arciemowicz
EIP-2026-100503 EXPLOITDB text VERIFIED
PSArt 1.2 - SQL Injection
by Securitylab Research
CVE-2009-3489 EXPLOITDB HIGH text VERIFIED
Adobe Photoshop Elements 8.0 - Incorrect Permission Assignment for Critical Resource in Active File Monitor Service
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
by bellick
CVSS 7.8
EIP-2026-114374 EXPLOITDB text VERIFIED
Wowd - 'index.html' Multiple Cross-Site Scripting Vulnerabilities
by Lostmon
EIP-2026-104346 EXPLOITDB text VERIFIED
Mura CMS 5.1 - Root Path Disclosure
by Vladimir Vorontsov
CVE-2009-3902 EXPLOITDB text VERIFIED
Cherokee Web Server <0.5.4 - Path Traversal
Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.
by Dr_IDE
EIP-2026-117634 EXPLOITDB text VERIFIED
Mozilla Firefox 3.5.3 - Local Download Manager Temp File Creation
by Jeremy Brown
CVE-2009-4039 EXPLOITDB text VERIFIED
Piwigo < 2.0.6 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
by Andrew Paterson
EIP-2026-110908 EXPLOITDB text VERIFIED
PHP168 6.0 - Command Execution
by Securitylab Security Research
CVE-2009-4512 EXPLOITDB text VERIFIED
Oscailt 3.3 - Unauthenticated Local File Inclusion via obj_id Parameter
Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj_id parameter.
by s4r4d0