Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106185 EXPLOITDB text VERIFIED
Cour Supreme - SQL Injection
by CrAzY CrAcKeR
EIP-2026-104539 EXPLOITDB text VERIFIED
Novell Edirectory 8.8 SP5 - Cross-Site Scripting
by Francis Provencher
CVE-2009-3898 EXPLOITDB text VERIFIED
nginx <0.7.63, <0.8.17 - Path Traversal
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
by kingcope
CVE-2009-3469 EXPLOITDB text VERIFIED
IBM Lotus Connections 2.0.1 - Cross-Site Scripting via Simple Search Name Parameter
Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
by IBM
CVE-2009-3495 EXPLOITDB text VERIFIED
Vastal I-Tech DVD Zone - SQL Injection via view_mag.php mag_id Parameter
SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.
by OoN_Boy
CVE-2009-3496 EXPLOITDB text VERIFIED
Vastal I-Tech DVD Zone - Cross-Site Scripting via view_mag.php mag_id Parameter
Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via the mag_id parameter.
by OoN_Boy
EIP-2026-112970 EXPLOITDB text VERIFIED
Vastal I-Tech Cosmetics Zone - 'view_products.php' SQL Injection
by OoN_Boy
CVE-2009-3491 EXPLOITDB text VERIFIED
Kinfusion SportFusion 0.2.2-0.2.3 - SQL Injection via cid[0] Parameter
SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.
by kaMtiEz
CVE-2009-3438 EXPLOITDB text VERIFIED
JoomlaFacebook (com_facebook) - SQL Injection via id Parameter
SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.
by kaMtiEz
EIP-2026-108665 EXPLOITDB text VERIFIED
Joomla! Component GroupJive 1.8 B4 - Remote File Inclusion
by M3NW5
CVE-2009-3438 EXPLOITDB text VERIFIED
JoomlaFacebook (com_facebook) - SQL Injection via id Parameter
SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.
by kaMtiEz
CVE-2009-3434 EXPLOITDB text VERIFIED
com_tupinambis 1.0 - SQL Injection via Proyecto Parameter
SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.
by Don Tukulesto
EIP-2026-107562 EXPLOITDB text VERIFIED
HB CMS 1.7 - SQL Injection
by Securitylab Security Research
EIP-2026-105615 EXPLOITDB text VERIFIED
BPStudent 1.0 - Blind SQL Injection
by OoN Boy
CVE-2009-3502 EXPLOITDB text VERIFIED
BPowerHouse BPMusic 1.0 - SQL Injection via music_id Parameter
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
by OoN Boy
CVE-2009-3705 EXPLOITDB text VERIFIED
Achievo < 1.4.0 - Remote Code Execution via Debugger Config Parameter
PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
by M3NW5
CVE-2009-3487 EXPLOITDB text VERIFIED
Juniper JUNOS 8.5R1.14 - Authenticated Cross-Site Scripting via J-Web Interface Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.
by Amir Azam
CVE-2009-3486 EXPLOITDB text VERIFIED
Juniper JUNOS 8.5R1.14 - Authenticated Cross-Site Scripting via J-Web Interface Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.
by Amir Azam
CVE-2009-3486 EXPLOITDB text VERIFIED
Juniper JUNOS 8.5R1.14 - Authenticated Cross-Site Scripting via J-Web Interface Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.
by Amir Azam
CVE-2009-3487 EXPLOITDB text VERIFIED
Juniper JUNOS 8.5R1.14 - Authenticated Cross-Site Scripting via J-Web Interface Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.
by Amir Azam
CVE-2009-3485 EXPLOITDB text VERIFIED
Juniper JUNOS 8.5R1.14 and 9.0R1.1 - Cross-Site Scripting via PATH_INFO to J-Web Default URI
Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI.
by Amir Azam
CVE-2009-3436 EXPLOITDB text VERIFIED
MaxWebPortal - SQL Injection via FORUM_ID or CAT_ID Parameter
Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.
by OoN_Boy
CVE-2009-3499 EXPLOITDB text VERIFIED
BPowerHouse BPLawyerCaseDocuments 1.0 - SQL Injection via employee.aspx cat Parameter
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by OoN Boy
CVE-2009-3503 EXPLOITDB text VERIFIED
BPHolidayLettings 1.0 - SQL Injection via search.aspx rid or tid Parameter
Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.
by OoN Boy
CVE-2009-3327 EXPLOITDB text VERIFIED
WX-Guestbook 1.1.208 - SQL Injection via QUERY or USERNAME Parameter
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
by learn3r