Exploitdb Exploits

31,357 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-100511 EXPLOITDB text VERIFIED
QuickTeam 2.2 - SQL Injection
by drunken danish rednecks
CVE-2009-1547 EXPLOITDB HIGH text VERIFIED
Internet Explorer 5.01 SP4, 6, 6 SP1, 7 - Remote Code Execution via Crafted Data Stream Header
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
by Skylined
CVSS 8.8
CVE-2009-4556 EXPLOITDB text VERIFIED
Quick Heal AntiVirus Plus <2009 - Privilege Escalation
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.
by Maxim A. Kulakov
CVE-2009-4745 EXPLOITDB text VERIFIED
Dreamlevels DreamPoll 3.1 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.
by infosecstuff
CVE-2009-2733 EXPLOITDB text VERIFIED
Achievo < 1.4.0 - Cross-Site Scripting via Scheduler Title and Contract Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
by Ryan Dewhurst
CVE-2009-2983 EXPLOITDB text VERIFIED
Adobe Acrobat and Reader < 9.2 - Memory Corruption and Possible Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
by Skylined
EIP-2026-101063 EXPLOITDB text VERIFIED
Palm WebOS 1.0/1.1 - 'LunaSysMgr' Service Denial of Service
by Townsend Ladd Harris
EIP-2026-118539 EXPLOITDB text VERIFIED
Femitter HTTP Server 1.03 - Remote Source Disclosure
by Dr_IDE
EIP-2026-118312 EXPLOITDB text VERIFIED
Best Way GEM Engine - Multiple Vulnerabilities
by Luigi Auriemma
EIP-2026-106369 EXPLOITDB text VERIFIED
Dazzle Blast - Remote File Inclusion
by NoGe
EIP-2026-106089 EXPLOITDB text VERIFIED
Community Translate - Remote File Inclusion
by NoGe
CVE-2009-4531 EXPLOITDB text VERIFIED
jasper/httpdx <= 1.4.4 - Exposure of Sensitive Information via URI Dot Character
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.
by Dr_IDE
CVE-2009-4742 EXPLOITDB text VERIFIED
Docebo 3.6.0.3 - SQL Injection via FAQ Word Parameter
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.
by Andrea Fabrizi
CVE-2009-3711 EXPLOITDB text VERIFIED
httpdx 1.4 - Stack-based Buffer Overflow via Long HTTP GET Request
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
by Pankaj Kohli
EIP-2026-112630 EXPLOITDB text VERIFIED
The BMW - 'inventory.php' SQL Injection
by Dazz
EIP-2026-111644 EXPLOITDB text VERIFIED
QuickCart 3.x - Cross-Site Scripting / Cross-Site Request Forgery / Local File Inclusion / Directory Traversal
by kl3ryk
EIP-2026-110323 EXPLOITDB text VERIFIED
OpenSolution Quick.Cart - Local File Inclusion / Cross-Site Scripting
by kl3ryk
CVE-2009-4746 EXPLOITDB text VERIFIED
Dreamlevels DreamPoll 3.1 - Cross-Site Scripting via recordsPerPage Parameter
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.
by Mark from infosecstuff
CVE-2009-3710 EXPLOITDB text VERIFIED
RioRey RIOS 4.6.6 and 4.7.0 - Unauthenticated Privilege Escalation via Hardcoded SSH Credentials
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.
by Marek Kroemeke
CVE-2009-4747 EXPLOITDB text VERIFIED
All In One Control Panel AIOCP 1.4.001 - RCE
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.
by Hadi Kiamarsi
CVE-2009-2684 EXPLOITDB text VERIFIED
HP Printers - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
by Digital Security Research Group
EIP-2026-116608 EXPLOITDB text VERIFIED
XLPD 3.0 - Remote Denial of Service
by Francis Provencher
CVE-2009-3592 EXPLOITDB text VERIFIED
Qualiteam X-Cart - Stored Cross-Site Scripting via Email Parameter in Subscribe Action
Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbitrary web script or HTML via the email parameter in a subscribed action, a different vector than CVE-2005-1823.
by Paulo Santos
EIP-2026-110506 EXPLOITDB text VERIFIED
PBBoard 2.0.2 - Full Path Disclosure
by rUnViRuS
CVE-2009-3591 EXPLOITDB text VERIFIED
Dopewars 1.5.12 - Denial of Service via Invalid REQUESTJET Message
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location.
by Doug Prostko