Exploitdb Exploits
31,394 exploits tracked across all sources.
IBM Lotus Notes Connector - Denial of Service via lnresobject.dll ActiveX Control
A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.
by Francis Provencher
Cerberus FTP 3.0.1 - 'ALLO' Remote Overflow Denial of Service (Metasploit)
by Francis Provencher
Turnkey Arcade Script - SQL Injection
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.
by Red-D3v1L
Joomla! com_siirler 1.2 RC - SQL Injection
SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.
by v3n0m
EMO Breeder Manager - SQL Injection via video.php idd Parameter
SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter.
by Mr.SQL
HyperVM - File Permissions Credential Disclosure
by Xia Shing Zee
Lanai Core 0.6 - Path Traversal via Download Module f Parameter
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
by Khashayar Fereidani
War-FTPD 1.65 - MKD/CD Requests Denial of Service
by opt!x hacker
Uebimiau Webmail 3.2.0-2.0 - Unauthenticated Exposure of Sensitive Information via Direct Request
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.
by Septemb0x
Radvision Scopia - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Francesco Bianchino
PHP Dir Submit - Authenticated SQL Injection via aid Parameter
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
by Mr.tro0oqy
New 5 Star Rating 1.0 - SQL Injection
SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter.
by Bgh7
Moa Gallery 1.1.0 and 1.2.0 - SQL Injection via gallery_id Parameter
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
by Mr.tro0oqy
lanai-core 0.6 - Exposure of Sensitive Information via info.php
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
by Khashayar Fereidani
com_ninjamonials 1.1.0 - SQL Injection via testimID Parameter
SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.
by Chip d3 bi0s
jtips com_jtips - SQL Injection via Season Parameter
SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.
by Chip d3 bi0s
CuteFlow 2.10.3 and 2.11.0_c - Unauthenticated User Account Modification via Direct Request
CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.
by Hever Costa Rocha
Arcade Trade Script 1.0 - Auth Bypass
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.
by Mr.tro0oqy
BSD (Multiple Distributions) - 'setusercontext()' Multiple Vulnerabilities
by kingcope
Netgear WNR2000 FW 1.2.0.8 - Information Disclosure
by Jean Trolleur
Huawei SmartAX MT880 - Multiple Cross-Site Request Forgery Vulnerabilities
by Jerome Athias
By Source