Exploitdb Exploits
31,394 exploits tracked across all sources.
Joomla! Component F!BB 1.5.96 RC - SQL Injection / HTML Injection
by Jeff Channell
Joomla! Component EasyBook 2.0.0rc4 - Multiple HTML Injection Vulnerabilities
by Jeff Channell
Roland Breedveld Album (com_album) 1.14 - Path Traversal via Target Parameter
Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.
by DreamTurk
FMyClone 2.3 - SQL Injection via comp Parameter
Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.
by learn3r hacker
CF ShopKart 5.4 beta - SQL Injection via index.cfm itemid Parameter
SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.
by learn3r hacker
changetrack 4.3 - OS Command Injection via Filename with CRLF and Shell Metacharacters
changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.
by Rick
glibc < 2.10.1 - Denial of Service via strfmon Format String Integer Overflow
Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.
by Maksymilian Arciemowicz
Implied By Design Micro CMS 3.5 - SQL Injection via Login Username or Password Parameter
Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field).
by learn3r hacker
Implied By Design Micro CMS <3.5 - RCE
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
by learn3r hacker
InterVations NaviCOPA Web Server 3.01 - Unauthenticated Source Code Exposure via ::$DATA Suffix
InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
by Dr_IDE
TuttoPHP Morris Guestbook - 'view.php' Cross-Site Scripting
by Moudi
RSSMediaScript - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Moudi
phppollscript < 1.3 - Remote Code Execution via include_class Parameter
PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.
by cr4wl3r
Zenas PaoLink 1.0 - Cross-Site Scripting via PATH_INFO
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Moudi
Zenas PaoBacheca Guestbook 2.1 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
by Moudi
Zenas PaoBacheca Guestbook 2.1 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
by Moudi
YABSoft Mega File Hosting Script 1.2 - Cross-Site Scripting via emaullinks.php moudi Parameter
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Moudi
com_foobla_suggestions 1.5.11 - SQL Injection via idea_id Parameter
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.
by Chip d3 bi0s
Elite Gaming Ladders 3.2 - SQL Injection via Platform Parameter
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.
by snakespc
AdsDX 3.05 - SQL Injection via Username Parameter
SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands via the Username.
by snakespc
Linux Kernel 2.6.31-rc1 - Buffer Overflow via perf_counter_open System Call
Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.
by Xiao Guangrong
Installshield 2009 15.0.0.53 Premier - 'ISWiAutomation15.dll' ActiveX Arbitrary File Overwrite
by the_Edit0r
BRS Webweaver 1.33 - '/Scripts' Access Restriction Bypass
by Usman Saeed
Protector Plus AntiVirus 8/9 - Local Privilege Escalation
by Maxim A. Kulakov
Novell Groupwise Client 7.0.3.1294 - Buffer Overflow
Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.
by Francis Provencher
By Source