Exploitdb Exploits
31,394 exploits tracked across all sources.
Logoshows BBS 2.0 - SQL Injection via Username and Password Fields
Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
by Dns-Team
Logoshows BBS 2.0 - SQL Injection via globepersonnel_forum.asp forumid Parameter
SQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
by Ruzgarin_Oglu
IsolSoft Support Center 2.5 - Cross-Site Scripting via lang Parameter
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
by Moudi
Cromosoft Technologies Facil Helpdesk 2.3 Lite - XSS
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Moudi
Cromosoft Technologies Facil Helpdesk 2.3 Lite - XSS
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Moudi
e-soft24 Banner Exchange Script 1.0 - SQL Injection via click.php targetid Parameter
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
by 599eme Man
Alwasel 1.5 - SQL Injection via id Parameter
Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) show.php and (2) xml.php.
by SwEET-DeViL
LM Starmail Paidmail 2.0 - SQL Injection via ID Parameter
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by int_main();
Willscript Auction Website Script - 'category.php' SQL Injection
by 599eme Man
Waverider Systems Perlshop - Multiple Input Validation Vulnerabilities
by Shadow
TYPO3 4.0 - SQL Injection via showUid Parameter
SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid parameter is generally used in third-party TYPO3 extensions - not in TYPO3 Core.
by Ro0T-MaFia
Silurus Classifieds 1.0 - Cross-Site Scripting via ID and Keywords Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.
by Moudi
Silurus Classifieds 1.0 - Cross-Site Scripting via ID and Keywords Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.
by Moudi
Silurus Classifieds 1.0 - Cross-Site Scripting via ID and Keywords Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.
by Moudi
PHP Script Forum Hoster - Topic Delete / Cross-Site Scripting
by int_main();
Multi Website 1.5 - Cross-Site Scripting via Search Parameter
Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.
by 599eme Man
LM Starmail Paidmail 2.0 - Remote Code Execution via home.php page Parameter
PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by int_main();
Alkacon OpenCMS 7.x - Multiple Input Validation Vulnerabilities
by Katie French
AJ Auction Pro OOPD 3.0 - 'txtkeyword' Cross-Site Scripting
by 599eme Man
Accessories Me PHP Affiliate Script 1.4 - Cross-Site Scripting via Keywords or SearchIndex Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.
by Moudi
MyBackup 1.4.0 - Authenticated Remote Code Execution via main_content Parameter
PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in the main_content parameter.
by SirGod
sun-jester OpenNews 1.0 - SQL Injection via Username Parameter
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
by SirGod
Microsoft Windows <7 - Info Disclosure
Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
by Dan Kaminsky
tenrok 1.1.0 - File Disclosure / Remote Code Execution
by SirGod
Portel 2008 - 'decide.php?patron' Blind SQL Injection
by Chip d3 bi0s
By Source