Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117601 EXPLOITDB text VERIFIED
Millenium MP3 Studio 2.0 - 'mpf' Local Buffer Overflow
by dellnull
EIP-2026-115858 EXPLOITDB text VERIFIED
Mozilla Firefox + Adobe - Memory Corruption (PoC)
by Skylined
CVE-2009-4523 EXPLOITDB text VERIFIED
Zainu 1.0 - Cross-Site Scripting via SearchSong Keyword Parameter
Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchSongKeyword parameter in a SearchSong action.
by drunken danish rednecks
EIP-2026-107239 EXPLOITDB text VERIFIED
FreeSchool - 'key_words' Cross-Site Scripting
by drunken danish rednecks
CVE-2009-3806 EXPLOITDB text VERIFIED
dedecms 5.1 - SQL Injection via feedback_js.php arcurl Parameter
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
by Securitylab Security Research
EIP-2026-104936 EXPLOITDB text VERIFIED
AdaptBB 1.0 - 'q' Cross-Site Scripting
by drunken danish rednecks
CVE-2009-2734 EXPLOITDB text VERIFIED
Achievo < 1.4.0 - SQL Injection via Userid Parameter
SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.
by Ryan Dewhurst
CVE-2009-2733 EXPLOITDB text VERIFIED
Achievo < 1.4.0 - Cross-Site Scripting via Scheduler Title and Contract Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
by Ryan Dewhurst
EIP-2026-104390 EXPLOITDB text VERIFIED
Pentaho BI 1.x - Multiple Cross-Site Scripting / Information Disclosure Vulnerabilities
by euronymous
CVE-2009-3828 EXPLOITDB text VERIFIED
Everfocus EDR1600 - Unauthenticated Authentication Bypass
The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.
by Andrea Fabrizi
CVE-2009-4521 EXPLOITDB text VERIFIED
Eclipse BIRT < 2.3.2 - Cross-Site Scripting via __report Parameter
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.
by Michele Orru
CVE-2009-5098 EXPLOITDB text VERIFIED
HP Palm Pre WebOS <= 1.1 - Denial of Service via Long String After Refresh Tag
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.
by Townsend Harris
EIP-2026-100511 EXPLOITDB text VERIFIED
QuickTeam 2.2 - SQL Injection
by drunken danish rednecks
CVE-2009-1547 EXPLOITDB HIGH text VERIFIED
Internet Explorer 5.01 SP4, 6, 6 SP1, 7 - Remote Code Execution via Crafted Data Stream Header
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
by Skylined
CVSS 8.8
CVE-2009-4556 EXPLOITDB text VERIFIED
Quick Heal AntiVirus Plus <2009 - Privilege Escalation
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.
by Maxim A. Kulakov
CVE-2009-4745 EXPLOITDB text VERIFIED
Dreamlevels DreamPoll 3.1 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.
by infosecstuff
CVE-2009-2733 EXPLOITDB text VERIFIED
Achievo < 1.4.0 - Cross-Site Scripting via Scheduler Title and Contract Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
by Ryan Dewhurst
CVE-2009-2983 EXPLOITDB text VERIFIED
Adobe Acrobat and Reader < 9.2 - Memory Corruption and Possible Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
by Skylined
EIP-2026-101063 EXPLOITDB text VERIFIED
Palm WebOS 1.0/1.1 - 'LunaSysMgr' Service Denial of Service
by Townsend Ladd Harris
EIP-2026-118539 EXPLOITDB text VERIFIED
Femitter HTTP Server 1.03 - Remote Source Disclosure
by Dr_IDE
EIP-2026-118312 EXPLOITDB text VERIFIED
Best Way GEM Engine - Multiple Vulnerabilities
by Luigi Auriemma
EIP-2026-106369 EXPLOITDB text VERIFIED
Dazzle Blast - Remote File Inclusion
by NoGe
EIP-2026-106089 EXPLOITDB text VERIFIED
Community Translate - Remote File Inclusion
by NoGe
CVE-2009-4531 EXPLOITDB text VERIFIED
jasper/httpdx <= 1.4.4 - Exposure of Sensitive Information via URI Dot Character
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.
by Dr_IDE
CVE-2009-4742 EXPLOITDB text VERIFIED
Docebo 3.6.0.3 - SQL Injection via FAQ Word Parameter
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.
by Andrea Fabrizi