Exploitdb Exploits
31,394 exploits tracked across all sources.
FileCopa FTP Server 5.01 - Denial of Service via Crafted NOOP Commands
FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands.
by Asheesh kumar Mani Tripathi
QuikSoft EasyMail MailStore ActiveX emmailstore.dll 6.5.0.3 - Buffer Overflow via CreateStore Method
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.
by Francis Provencher
EasyMail Quicksoft 6.0.2.0 - ActiveX Remote Code Execution (PoC)
by Francis Provencher
Adobe Shockwave Player < 11.5.1.601 - Heap-Based Buffer Overflow via PlayerVersion Property
Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.
by Francis Provencher
Three Pillars Help Desk 3.0 - Authentication Bypass
by snakespc
Blueconstantmedia Com Djcatalog - SQL Injection
Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.
by Chip d3 bi0s
efront < 3.5.4 - Remote Code Execution via path Parameter
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
by cr4wl3r
Wireshark 1.2.0-1.2.1 - Denial of Service in TLS Dissector
Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.
by Buildbot Builder
Wireshark 0.99.6-1.0.8 and 1.2.0-1.2.1 - Denial of Service via OPCUA Service CallRequest Packets
Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.
by Buildbot Builder
Wireshark 1.2.0 and 1.2.1 - Denial of Service in GSM A RR Dissector
Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.
by Buildbot Builder
IP3 Networks NetAccess NA75 - Local Command Injection via Backtick Characters in CLI
na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).
by r00t
HotWeb Rentals - SQL Injection via PropId Parameter
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.
by R3d-D3V!L
FotoTagger 2.12.0.0 - '.XML' Buffer Overflow (PoC)
by the_Edit0r
Batch Picture Watemark 1.0 - '.jpg' Local Crash (PoC)
by the_Edit0r
TurtuShout 0.11 - SQL Injection via Name Field
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.
by jdc
BS Counter 2.5.3 - SQL Injection via Page Parameter
SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.
by Bgh7
Aurora CMS 1.0.2 - Remote Code Execution via AURORA_MODULES_FOLDER Parameter
PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter.
by EA Ngel
Neufbox NB4-R1.5.10-MAIN - Persistent Cross-Site Scripting
by 599eme Man
Paul Smith Computer Services vCAP <1.9.0 - Path Traversal
Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by securma massine
com_hbssearch - SQL Injection via h_id, id, or rid Parameters
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.
by K-159
Datavore Gyro 5.0 - Cross-Site Scripting via Home Component cid Parameter
Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.
by OoN_Boy
Xerver HTTP Server 4.32 - Exposure of Sensitive Information via ::$DATA Suffix
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
by Dr_IDE
Kolibri+ Web Server 2 - Source Code Disclosure
by SkuLL-HackeR
By Source