Exploitdb Exploits
31,394 exploits tracked across all sources.
Kolibri+ Web Server 2 - Arbitrary Source Code Disclosure (2)
by Dr_IDE
SZNews 2.7 - Remote Code Execution via printnews.php3 id Parameter
PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
by kurdish hackers team
Planet and Planet Venus - Cross-Site Scripting via IMG SRC Attribute
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.
by Steve Kemp
PHP-IPNMonitor - SQL Injection via maincat_id Parameter
SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.
by noname
Match Agency BiZ 1.0 - Cross-Site Scripting via Important Parameter or PID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.
by Moudi
Match Agency BiZ 1.0 - Cross-Site Scripting via Important Parameter or PID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.
by Moudi
com_hbssearch - Cross-Site Scripting via Adult Parameter
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.
by K-159
Joomla! Component com_mediaalert - 'id' SQL Injection
by Moudi
Image voting 1.0 - SQL Injection via Show Parameter
SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.
by SkuLL-HackeR
Datavore Gyro 5.0 - SQL Injection via cid Parameter in Home Component
SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.
by OoN_Boy
Mozilla Firefox <3.0.14 - Info Disclosure
Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.
by Dan Kaminsky
Linux kernel <2.6.30.4, <2.4.37.4 - Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
by Ramon de C Valle
CVSS 7.8
An image gallery 1.0 - Path Traversal via Path Parameter
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
by ThE g0bL!N
MYRE Holiday Rental Manager - SQL Injection
SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review action.
by Mr.SQL
Nullam Blog 0.1.2 - SQL Injection via i or v Parameter
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) i parameter or (2) v parameters in a register action.
by Salvatore Fresta
Nullam Blog 0.1.2 - Path Traversal via p or s Parameter
Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.
by Salvatore Fresta
Kolibri+ Web Server 2 - GET Denial of Service
by Usman Saeed
tourismscripts HotelBook - 'hotel_id' Multiple SQL Injections
by Mr.SQL
T-HTB Manager 0.5 - SQL Injection via id or name Parameter
Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a delete_category action, (2) the name parameter in an update_category action, and other vectors.
by Salvatore Fresta
Nullam Blog 0.1.2 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary web script or HTML via the e parameter in an error action.
by Salvatore Fresta
MYRE Holiday Rental Manager - Cross-Site Scripting via search.php cat_id1 Parameter
Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.
by Mr.SQL
Joomla! Component com_pressrelease - 'id' SQL Injection
by Moudi
Nicecoder iDesk - SQL Injection via download.php cat_id Parameter
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.
by Mr.SQL
Graffiti CMS 1.x - Arbitrary File Upload
by Alexander Concha
Drunken:Golem Gaming Portal 0.5.1 - RCE
PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.
by EA Ngel
By Source