Exploitdb Exploits
31,394 exploits tracked across all sources.
Novell eDirectory 8.8 SP5 - 'dconserv.dlm' Cross-Site Scripting
by Francis Provencher
Cerberus FTP server 3.0.6 - Denial of Service
by Francis Provencher
Adobe Photoshop Elements 8.0 - Incorrect Permission Assignment for Critical Resource in Active File Monitor Service
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
by pyrokinesis
CVSS 7.8
Interspire Knowledge Manager 5 - Path Traversal
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Infected Web
Flatpress 0.804 < 0.812.1 - Local File Inclusion
by Giuseppe Fuggiano
e107 0.7.x - CAPTCHA Security Bypass / Cross-Site Scripting
by MustLive
FrontRange HEAT 8.01 - SQL Injection via Call Logging Username and Password Parameters
Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
by 0 0
PHP 5.3 - 'preg_match()' Full Path Disclosure
by David Vieira-Kurz
Xen 3.0.3, 3.3.0, 3.3.1 - Unauthenticated Boot Parameter Modification via pyGrub
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.
by Jan Lieskovsky
Cisco ACE Web Application Firewall and ACE XML Gateway < 6.1 - Information Disclosure via Unhandled HTTP Request
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.
by nitr0us
Activedition - '/activedition/aelogin.asp' Multiple Cross-Site Scripting Vulnerabilities
by Richard Brain
Fastball (com_fastball) 1.1.0-1.2 - SQL Injection via League Parameter
SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.
by kaMtiEz
e107 < 0.7.16 - Cross-Site Scripting via HTTP Referer Header
Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.
by MustLive
Avast! AntiVirus 4.8.1351.0 - Denial of Service / Privilege Escalation
by Evilcry
Vastal I-Tech Agent Zone - 'view_listing.php' SQL Injection
by OoN_Boy
OSSIM < 2.1.2 - Cross-Site Scripting via Option Parameter
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
by Alexey Sintsov
By Source