Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106618 EXPLOITDB text VERIFIED
E CMS 1.0 - 'index.php?s' SQL Injection
by Red-D3v1L
CVE-2009-3205 EXPLOITDB text VERIFIED
CBAuthority - SQL Injection via id Parameter in view_product Action
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.
by Angela Chang
EIP-2026-105451 EXPLOITDB text VERIFIED
Best Dating Script - Arbitrary File Upload
by jetli007
EIP-2026-105321 EXPLOITDB text VERIFIED
autonomous lan party 0.98.3 - Remote File Inclusion
by cr4wl3r
EIP-2026-105260 EXPLOITDB text VERIFIED
asaher pro 1.0.4 - Remote Database Backup
by alnjm33
EIP-2026-104830 EXPLOITDB text VERIFIED
2WIRE Gateway - Authentication Bypass / Password Reset (2)
by bugz
EIP-2026-103413 EXPLOITDB text VERIFIED
Apple Safari 4.0.2 - WebKit Parsing of Floating Point Numbers Buffer Overflow (PoC)
by Leon Juranic
EIP-2026-101502 EXPLOITDB text VERIFIED
ZTE ZXDSL 831 II Modem - Arbitrary Configuration Access
by SuNHouSe2
EIP-2026-101501 EXPLOITDB text VERIFIED
ZTE ZXDSL 831 II Modem - Arbitrary Add Admin
by SuNHouSe2
EIP-2026-101382 EXPLOITDB text VERIFIED
Netgear WNR2000 - Multiple Information Disclosure Vulnerabilities
by Jean Trolleur
CVE-2009-2692 EXPLOITDB HIGH text VERIFIED
Linux kernel <2.6.30.4, <2.4.37.4 - Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
by Zinx
CVSS 7.8
EIP-2026-119242 EXPLOITDB text VERIFIED
Valve Software Source Engine - Format String
by Luigi Auriemma
EIP-2026-111662 EXPLOITDB text VERIFIED
RadAFFILIATE Links - 'index.php' Cross-Site Scripting
by Moudi
CVE-2009-3593 EXPLOITDB text VERIFIED
Freelancers 1.0 - Cross-Site Scripting via id or jobid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php.
by Moudi
CVE-2009-3593 EXPLOITDB text VERIFIED
Freelancers 1.0 - Cross-Site Scripting via id or jobid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php.
by Moudi
CVE-2009-1872 EXPLOITDB text VERIFIED
Adobe ColdFusion < 8.0.1 - Cross-Site Scripting via startRow Parameter or Query String
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
by Alexander Polyakov
CVE-2009-1872 EXPLOITDB text VERIFIED
Adobe ColdFusion < 8.0.1 - Cross-Site Scripting via startRow Parameter or Query String
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
by Alexander Polyakov
CVE-2009-1872 EXPLOITDB text VERIFIED
Adobe ColdFusion < 8.0.1 - Cross-Site Scripting via startRow Parameter or Query String
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
by Alexander Polyakov
CVE-2009-1872 EXPLOITDB text VERIFIED
Adobe ColdFusion < 8.0.1 - Cross-Site Scripting via startRow Parameter or Query String
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
by Alexander Polyakov
EIP-2026-100285 EXPLOITDB text VERIFIED
DUWare DUgallery 3.0 - '/admin/edit.asp' Authentication Bypass
by spymeta
CVE-2009-2915 EXPLOITDB text VERIFIED
2fly Gift Delivery System 6.0 - SQL Injection via gameid Parameter
SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.
by Securitylab.ir
CVE-2009-2926 EXPLOITDB text VERIFIED
PHP Competition System BETA 0.84 - SQL Injection via Day or Pageno Parameter
Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.
by Mr.SQL
EIP-2026-109812 EXPLOITDB text VERIFIED
MyWeight 1.0 - Arbitrary File Upload
by Mr.tro0oqy
EIP-2026-107774 EXPLOITDB text VERIFIED
Ignition 1.2 - 'comment' Remote Code Injection
by Khashayar Fereidani
CVE-2009-2927 EXPLOITDB text VERIFIED
DigitalSpinners DS CMS 1.0 - SQL Injection via DetailFile.php nFileId Parameter
SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.
by Mr.tro0oqy