Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-103654 EXPLOITDB text VERIFIED
Sniper Elite 1.0 - Null Pointer Dereference Denial of Service
by Luigi Auriemma
CVE-2009-2692 EXPLOITDB HIGH text VERIFIED
Linux kernel <2.6.30.4, <2.4.37.4 - Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
by Przemyslaw Frasunek
CVSS 7.8
CVE-2009-2692 EXPLOITDB HIGH text VERIFIED
Linux kernel <2.6.30.4, <2.4.37.4 - Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
by spender
CVSS 7.8
CVE-2009-2928 EXPLOITDB text VERIFIED
TGS Content Management 0.x - Cross-Site Scripting via login.php previous_page Parameter
Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.
by []ViZiOn
CVE-2009-2929 EXPLOITDB text VERIFIED
TGS Content Management 0.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters to cms/index.php; and the (12) cmd, (13) s_dir, (14) minutes, (15) s_mask, (16) test3_mp, (17) test15_file1, (18) submit, (19) brute_method, (20) ftp_server_port, (21) userfile14, (22) subj, (23) mysql_l, (24) action, and (25) userfile1 parameters to cms/frontpage_ception.php. NOTE: some of these parameters may be applicable only in nonstandard versions of the product, and cms/frontpage_ception.php may be cms/frontpage_caption.php in all released versions.
by []ViZiOn
CVE-2009-3182 EXPLOITDB text VERIFIED
Anantasoft Gazelle CMS 1.0 - Unauthenticated Arbitrary File Upload via File Manager
Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.
by RoMaNcYxHaCkEr
CVE-2009-2930 EXPLOITDB text VERIFIED
elka CMS - Cross-Site Scripting via Search Feature q Parameter
Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.
by Isfahan
EIP-2026-101473 EXPLOITDB text VERIFIED
THOMSON ST585 - 'user.ini' Arbitrary Disclosure
by aBo MoHaMeD
EIP-2026-112036 EXPLOITDB text VERIFIED
Shorty 0.7.1b - (Authentication Bypass) Insecure Cookie Handling
by Pedro Laguna
CVE-2009-3418 EXPLOITDB text VERIFIED
Plume CMS 1.2.3 - Authenticated SQL Injection via Manager Parameters
Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.
by Sense of Security
EIP-2026-107331 EXPLOITDB text VERIFIED
Gallarific 1.1 - '/gallery.php' Arbitrary Delete/Edit Category
by ilker Kandemir
EIP-2026-101142 EXPLOITDB text VERIFIED
2WIRE Routers - 'CD35_SETUP_01' Access Validation
by hkm
EIP-2026-101141 EXPLOITDB text VERIFIED
2WIRE Gateway - Authentication Bypass / Password Reset (1)
by hkm
CVE-2009-3020 EXPLOITDB text VERIFIED
Windows Server 2003 SP2 - Denial of Service via Crafted EOT Font File
win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
by webDEViL
CVE-2009-2762 EXPLOITDB text VERIFIED
WordPress < 2.8.3 - Unauthenticated Password Reset via Array Parameter Bypass
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
by laurent gaffié
CVE-2009-3042 EXPLOITDB text VERIFIED
ocs_inventory_ng 1.02.1 - SQL Injection via machine.php systemid Parameter
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
by Guilherme Marinheiro
CVE-2009-3417 EXPLOITDB text VERIFIED
IDoBlog 1.1 build 30 - SQL Injection via Userid Parameter
SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.
by kkr
CVE-2009-2195 EXPLOITDB text VERIFIED
Apple Safari < 4.0.3 - Remote Code Execution via Crafted Floating-Point Numbers
Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
by Apple
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4548 EXPLOITDB text VERIFIED
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
by Moudi
CVE-2009-4547 EXPLOITDB text VERIFIED
ViArt CMS 3.x - Cross-Site Scripting via category_id or forum_id Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ViArt CMS 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter to forums.php, or the forum_id parameter to (2) forum.php or (3) forum_topic_new.php.
by Moudi