Exploitdb Exploits
31,394 exploits tracked across all sources.
WX-Guestbook 1.1.208 - SQL Injection / HTML Injection
by learn3r
WX-Guestbook 1.1.208 - Cross-Site Scripting via sName Parameter
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
by learn3r
ProdLer < 2.0 - Remote Code Execution via sPath Parameter
PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.
by cr4wl3r
Loggix Project <= 9.4.5 - Remote Code Execution via pathToIndex Parameter
Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathToIndex parameter to (1) Calendar.php, (2) Comment.php, (3) Rss.php and (4) Trackback.php in lib/Loggix/Module/; and (5) modules/downloads/lib/LM_Downloads.php.
by cr4wl3r
Focusdev Com Surveymanager - SQL Injection
SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.
by kaMtiEz
Lhacky! Extensions Cave Joomla! Integrated Newsletters Component 0.2 - SQL Injection via newsid Parameter
SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.
by Chip d3 bi0s
JBudgetsMagic 0.3.2-0.4.0 - SQL Injection via bid Parameter
SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.
by kaMtiEz
DDL CMS 1.0 - Remote Code Execution via wwwRoot Parameter
Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php.
by HxH
CMScontrol 7.x - SQL Injection via id_menu Parameter
SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.
by ph1l1ster
BAROSmini 0.32.595 - Remote Code Execution via PHP File Inclusion
Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path parameter to (2) lib_users.php, (3) lib_stats.php, and (4) lib_slots.php in include/lib/.
by EA Ngel
Snort unified 1 IDS Logging - Alert Evasion & Logfile Corruption/Alert Falsify
by Pablo Rincón Crespo
FFmpeg 0.5 - Stack-based Buffer Overflow
FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.
by Will Dormann
Check Point Connectra R62 - '/Login/Login' Arbitrary Script Injection
by Stefan Friedli
Xerver 4.32 - Unauthenticated Administrator Access via Port 32123
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
by Dr_IDE
Xerver HTTP Server 4.32 - Path Traversal via chooseDirectory currentPath Parameter
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.
by Stack
Xerver 4.32 - Authenticated Denial of Service via Non-Numeric Web Port Assignment
Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the management interface. NOTE: this can be leveraged by non-authenticated attackers using CVE-2009-4657.
by Dr_IDE
Zainu 1.0 - SQL Injection via AlbumSongs Album ID Parameter
SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action.
by snakespc
ClearSite 4.50 - Remote Code Execution via cs_base_path Parameter
PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.
by EA Ngel
FSphp 0.2.1 - Remote File Inclusion via FSPHP_LIB Parameter
Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.
by NoGe
FanUpdate 2.2.1 - SQL Injection via show-cat.php listingid Parameter
SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
by (In)Security Romania
Xerver HTTP Server 4.32 - Cross-Site Scripting via currentPath Parameter
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.
by Stack
Avaya Intuity Audix LX R1.1 - Multiple Remote Vulnerabilities
by pagvac
OpenSiteAdmin 0.9.7 BETA - Remote Code Execution via Path Parameter
PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.
by EA Ngel
NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 - SQL Injection via Username Field
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.
by learn3r hacker
By Source