Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-3711 EXPLOITDB text VERIFIED
httpdx 1.4 - Stack-based Buffer Overflow via Long HTTP GET Request
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
by Pankaj Kohli
EIP-2026-112630 EXPLOITDB text VERIFIED
The BMW - 'inventory.php' SQL Injection
by Dazz
EIP-2026-111644 EXPLOITDB text VERIFIED
QuickCart 3.x - Cross-Site Scripting / Cross-Site Request Forgery / Local File Inclusion / Directory Traversal
by kl3ryk
EIP-2026-110323 EXPLOITDB text VERIFIED
OpenSolution Quick.Cart - Local File Inclusion / Cross-Site Scripting
by kl3ryk
CVE-2009-4746 EXPLOITDB text VERIFIED
Dreamlevels DreamPoll 3.1 - Cross-Site Scripting via recordsPerPage Parameter
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.
by Mark from infosecstuff
CVE-2009-3710 EXPLOITDB text VERIFIED
RioRey RIOS 4.6.6 and 4.7.0 - Unauthenticated Privilege Escalation via Hardcoded SSH Credentials
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.
by Marek Kroemeke
CVE-2009-4747 EXPLOITDB text VERIFIED
All In One Control Panel AIOCP 1.4.001 - RCE
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.
by Hadi Kiamarsi
CVE-2009-2684 EXPLOITDB text VERIFIED
HP Printers - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
by Digital Security Research Group
EIP-2026-116608 EXPLOITDB text VERIFIED
XLPD 3.0 - Remote Denial of Service
by Francis Provencher
CVE-2009-3592 EXPLOITDB text VERIFIED
Qualiteam X-Cart - Stored Cross-Site Scripting via Email Parameter in Subscribe Action
Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbitrary web script or HTML via the email parameter in a subscribed action, a different vector than CVE-2005-1823.
by Paulo Santos
EIP-2026-110506 EXPLOITDB text VERIFIED
PBBoard 2.0.2 - Full Path Disclosure
by rUnViRuS
CVE-2009-3591 EXPLOITDB text VERIFIED
Dopewars 1.5.12 - Denial of Service via Invalid REQUESTJET Message
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location.
by Doug Prostko
CVE-2009-3901 EXPLOITDB text VERIFIED
e-Courier CMS - Cross-Site Scripting via UserGUID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors.
by BugsNotHugs
CVE-2009-3709 EXPLOITDB text VERIFIED
Konae Alleycode HTML Editor 2.21 - Stack-Based Buffer Overflow via TITLE Tag
Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to execute arbitrary code via a long value in a TITLE tag.
by Rafael Sousa
CVE-2009-3644 EXPLOITDB text VERIFIED
Soundset (com_soundset) 1.0 - SQL Injection via cat_id Parameter
SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.
by kaMtiEz
CVE-2009-3645 EXPLOITDB text VERIFIED
JoomlaCache CB Resume Builder - SQL Injection via group_id Parameter
SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.
by kaMtiEz
EIP-2026-108232 EXPLOITDB text VERIFIED
Joomla! Component CB Resume Builder - 'group_id' SQL Injection
by kaMtiEz
EIP-2026-101405 EXPLOITDB text VERIFIED
Palm Pre WebOS 1.1 - Remote File Access
by Townsend Ladd Harris
CVE-2009-4743 EXPLOITDB text VERIFIED
AfterLogic WebMail Pro <4.7.10 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters.
by Sébastien Duquette
EIP-2026-110909 EXPLOITDB text VERIFIED
PHP168 Template Editor - 'Filename' Directory Traversal
by esnra
EIP-2026-107371 EXPLOITDB text VERIFIED
Geeklog 1.6.0sr2 - Arbitrary File Upload
by JaL0h
EIP-2026-111732 EXPLOITDB text VERIFIED
redcat media - SQL Injection
by s4va
CVE-2009-2898 EXPLOITDB text VERIFIED
SpringSource Hyperic HQ 3.2.x-4.2-beta1 - Authenticated Cross-Site Scripting via Alerts List Description Field
Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.
by CoreLabs
EIP-2026-118614 EXPLOITDB text VERIFIED
Google Apps - mailto URI handler cross-browser Remote command Execution
by pyrokinesis
CVE-2009-3658 EXPLOITDB HIGH text VERIFIED
AOL SuperBuddy ActiveX Control - Use-After-Free via SetSuperBuddy Method
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
by Trotzkista
CVSS 8.8