Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108647 EXPLOITDB text VERIFIED
Joomla! Component F!BB 1.5.96 RC - SQL Injection / HTML Injection
by Jeff Channell
EIP-2026-108633 EXPLOITDB text VERIFIED
Joomla! Component EasyBook 2.0.0rc4 - Multiple HTML Injection Vulnerabilities
by Jeff Channell
CVE-2009-3318 EXPLOITDB text VERIFIED
Roland Breedveld Album (com_album) 1.14 - Path Traversal via Target Parameter
Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.
by DreamTurk
CVE-2009-3313 EXPLOITDB text VERIFIED
FMyClone 2.3 - SQL Injection via comp Parameter
Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.
by learn3r hacker
CVE-2009-3309 EXPLOITDB text VERIFIED
CF ShopKart 5.4 beta - SQL Injection via index.cfm itemid Parameter
SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.
by learn3r hacker
CVE-2009-3233 EXPLOITDB text VERIFIED
changetrack 4.3 - OS Command Injection via Filename with CRLF and Shell Metacharacters
changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.
by Rick
CVE-2009-4880 EXPLOITDB text VERIFIED
glibc < 2.10.1 - Denial of Service via strfmon Format String Integer Overflow
Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.
by Maksymilian Arciemowicz
CVE-2008-6614 EXPLOITDB text VERIFIED
Implied By Design Micro CMS 3.5 - SQL Injection via Login Username or Password Parameter
Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field).
by learn3r hacker
CVE-2006-3144 EXPLOITDB text VERIFIED
Implied By Design Micro CMS <3.5 - RCE
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
by learn3r hacker
CVE-2009-3646 EXPLOITDB text VERIFIED
InterVations NaviCOPA Web Server 3.01 - Unauthenticated Source Code Exposure via ::$DATA Suffix
InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
by Dr_IDE
EIP-2026-112816 EXPLOITDB text VERIFIED
TuttoPHP Morris Guestbook - 'view.php' Cross-Site Scripting
by Moudi
CVE-2009-3311 EXPLOITDB text VERIFIED
RSSMediaScript - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Moudi
CVE-2009-3312 EXPLOITDB text VERIFIED
phppollscript < 1.3 - Remote Code Execution via include_class Parameter
PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.
by cr4wl3r
CVE-2009-3320 EXPLOITDB text VERIFIED
Zenas PaoLink 1.0 - Cross-Site Scripting via PATH_INFO
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Moudi
CVE-2009-3493 EXPLOITDB text VERIFIED
Zenas PaoBacheca Guestbook 2.1 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
by Moudi
CVE-2009-3493 EXPLOITDB text VERIFIED
Zenas PaoBacheca Guestbook 2.1 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
by Moudi
CVE-2009-3647 EXPLOITDB text VERIFIED
YABSoft Mega File Hosting Script 1.2 - Cross-Site Scripting via emaullinks.php moudi Parameter
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Moudi
CVE-2009-3669 EXPLOITDB text VERIFIED
com_foobla_suggestions 1.5.11 - SQL Injection via idea_id Parameter
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.
by Chip d3 bi0s
CVE-2009-3314 EXPLOITDB text VERIFIED
Elite Gaming Ladders 3.2 - SQL Injection via Platform Parameter
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.
by snakespc
CVE-2009-3667 EXPLOITDB text VERIFIED
AdsDX 3.05 - SQL Injection via Username Parameter
SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands via the Username.
by snakespc
CVE-2009-3234 EXPLOITDB text VERIFIED
Linux Kernel 2.6.31-rc1 - Buffer Overflow via perf_counter_open System Call
Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.
by Xiao Guangrong
EIP-2026-118685 EXPLOITDB text VERIFIED
Installshield 2009 15.0.0.53 Premier - 'ISWiAutomation15.dll' ActiveX Arbitrary File Overwrite
by the_Edit0r
EIP-2026-118332 EXPLOITDB text VERIFIED
BRS Webweaver 1.33 - '/Scripts' Access Restriction Bypass
by Usman Saeed
EIP-2026-117800 EXPLOITDB text VERIFIED
Protector Plus AntiVirus 8/9 - Local Privilege Escalation
by Maxim A. Kulakov
CVE-2009-3863 EXPLOITDB text VERIFIED
Novell Groupwise Client 7.0.3.1294 - Buffer Overflow
Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.
by Francis Provencher