Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-3038 EXPLOITDB text VERIFIED
IBM Lotus Notes Connector - Denial of Service via lnresobject.dll ActiveX Control
A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.
by Francis Provencher
EIP-2026-115028 EXPLOITDB text VERIFIED
Cerberus FTP 3.0.1 - 'ALLO' Remote Overflow Denial of Service (Metasploit)
by Francis Provencher
CVE-2009-3973 EXPLOITDB text VERIFIED
Turnkey Arcade Script - SQL Injection
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.
by Red-D3v1L
EIP-2026-112573 EXPLOITDB text VERIFIED
TCPDB 3.8 - Remote Content Change Bypass
by Securitylab.ir
EIP-2026-110248 EXPLOITDB text VERIFIED
OpenAutoClassifieds 1.5.9 - SQL Injection
by Andrew Horton
CVE-2009-3972 EXPLOITDB text VERIFIED
Joomla! com_siirler 1.2 RC - SQL Injection
SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.
by v3n0m
CVE-2009-4958 EXPLOITDB text VERIFIED
EMO Breeder Manager - SQL Injection via video.php idd Parameter
SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter.
by Mr.SQL
EIP-2026-103777 EXPLOITDB text VERIFIED
HyperVM - File Permissions Credential Disclosure
by Xia Shing Zee
CVE-2009-4960 EXPLOITDB text VERIFIED
Lanai Core 0.6 - Path Traversal via Download Module f Parameter
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
by Khashayar Fereidani
EIP-2026-116523 EXPLOITDB text VERIFIED
War-FTPD 1.65 - MKD/CD Requests Denial of Service
by opt!x hacker
CVE-2009-3199 EXPLOITDB text VERIFIED
Uebimiau Webmail 3.2.0-2.0 - Unauthenticated Exposure of Sensitive Information via Direct Request
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.
by Septemb0x
CVE-2009-2965 EXPLOITDB text VERIFIED
Radvision Scopia - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Francesco Bianchino
CVE-2009-3970 EXPLOITDB text VERIFIED
PHP Dir Submit - Authenticated SQL Injection via aid Parameter
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
by Mr.tro0oqy
CVE-2009-3965 EXPLOITDB text VERIFIED
New 5 Star Rating 1.0 - SQL Injection
SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter.
by Bgh7
CVE-2009-3975 EXPLOITDB text VERIFIED
Moa Gallery 1.1.0 and 1.2.0 - SQL Injection via gallery_id Parameter
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
by Mr.tro0oqy
CVE-2009-4961 EXPLOITDB text VERIFIED
lanai-core 0.6 - Exposure of Sensitive Information via info.php
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
by Khashayar Fereidani
CVE-2009-3964 EXPLOITDB text VERIFIED
com_ninjamonials 1.1.0 - SQL Injection via testimID Parameter
SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.
by Chip d3 bi0s
CVE-2009-3971 EXPLOITDB text VERIFIED
jtips com_jtips - SQL Injection via Season Parameter
SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.
by Chip d3 bi0s
EIP-2026-107679 EXPLOITDB text VERIFIED
humanCMS - Authentication Bypass
by next
EIP-2026-107370 EXPLOITDB text VERIFIED
Geeklog 1.6.0sr1 - Arbitrary File Upload
by JaL0h
CVE-2009-2960 EXPLOITDB text VERIFIED
CuteFlow 2.10.3 and 2.11.0_c - Unauthenticated User Account Modification via Direct Request
CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.
by Hever Costa Rocha
CVE-2009-3966 EXPLOITDB text VERIFIED
Arcade Trade Script 1.0 - Auth Bypass
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.
by Mr.tro0oqy
EIP-2026-103766 EXPLOITDB text VERIFIED
BSD (Multiple Distributions) - 'setusercontext()' Multiple Vulnerabilities
by kingcope
EIP-2026-101383 EXPLOITDB text VERIFIED
Netgear WNR2000 FW 1.2.0.8 - Information Disclosure
by Jean Trolleur
EIP-2026-101312 EXPLOITDB text VERIFIED
Huawei SmartAX MT880 - Multiple Cross-Site Request Forgery Vulnerabilities
by Jerome Athias