Exploitdb Exploits

31,369 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-1334 EXPLOITDB text VERIFIED
IBM Tivoli Continuous Data Protection for Files 3.1.4.0 - Cross-Site Scripting via login/FilepathLogin.html
Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.
by Abdul-Aziz Hariri
EIP-2026-114518 EXPLOITDB text VERIFIED
Yellow Duck Weblog 2.1.0 - 'lang' Local File Inclusion
by ahmadbady
EIP-2026-114421 EXPLOITDB text VERIFIED
XEngineSoft PMS/MGS/NM/Ams 1.0 - Authentication Bypass
by Dr-HTmL
EIP-2026-114402 EXPLOITDB text VERIFIED
X10media Mp3 Search Engine < 1.6.2 - Admin Access
by THUNDER
EIP-2026-107249 EXPLOITDB text VERIFIED
FreznoShop 1.3.0 - 'id' SQL Injection
by NoGe
EIP-2026-106676 EXPLOITDB text VERIFIED
e107 Plugin userjournals_menu - 'blog.id' SQL Injection
by boom3rang
CVE-2009-0687 EXPLOITDB text VERIFIED
MidnightBSD - Denial of Service via Crafted IP Packets in PF Packet Filter
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
by Rembrandt
EIP-2026-100751 EXPLOITDB text VERIFIED
Banshee 1.4.2 DAAP Extension - '/apps/web/vs_diag.cgi' Cross-Site Scripting
by Anthony de Almeida Lopes
EIP-2026-100480 EXPLOITDB text VERIFIED
People-Trak - Login SQL Injection
by Mormoroth.net
CVE-2009-1369 EXPLOITDB text VERIFIED
moziloCMS 1.11 - Information Disclosure via Error Message Path Exposure
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.
by SirGod
CVE-2009-1368 EXPLOITDB text VERIFIED
moziloCMS 1.11 - Path Traversal via Page Parameter
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3.
by SirGod
CVE-2009-1367 EXPLOITDB text VERIFIED
moziloCMS 1.11 - Cross-Site Scripting via Search Query Parameter
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a.
by SirGod
EIP-2026-118353 EXPLOITDB text VERIFIED
Chance-i DiViS DVR System Web-Server - Directory Traversal
by DSecRG
EIP-2026-115041 EXPLOITDB text VERIFIED
Chance-i DiViS-Web DVR System - ActiveX Control Heap Overflow (PoC)
by DSecRG
EIP-2026-111729 EXPLOITDB text VERIFIED
RedaxScript 0.2.0 - 'Language' Local File Inclusion
by SirGod
EIP-2026-110794 EXPLOITDB text VERIFIED
PHP-Agenda 2.2.5 - Remote File Overwriting
by Salvatore Fresta
CVE-2009-4209 EXPLOITDB text VERIFIED
moziloCMS 1.11.1 - Cross-Site Scripting via cat and file Parameters
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) file parameters in an editsite action, different vectors than CVE-2008-6127 and CVE-2009-1367.
by SirGod
EIP-2026-109202 EXPLOITDB text VERIFIED
Loggix Project 9.4.5 - 'refer_id' Blind SQL Injection
by Salvatore Fresta
EIP-2026-101000 EXPLOITDB text VERIFIED
Cisco ASA/PIX - Appliances Fail to Properly Check Fragmented TCP Packets
by Daniel Clemens
EIP-2026-100333 EXPLOITDB text VERIFIED
FunkyASP AD System 1.1 - Arbitrary File Upload
by ZoRLu
CVE-2009-1314 EXPLOITDB text VERIFIED
Web File Explorer 3.1 - Remote Code Execution via File Parameter in savefile Action
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.
by Osirys
CVE-2009-1323 EXPLOITDB text VERIFIED
Web File Explorer 3.1 - SQL Injection via id Parameter
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Osirys
EIP-2026-112057 EXPLOITDB text VERIFIED
Simbas CMS 2.0 - Authentication Bypass
by ThE g0bL!N
EIP-2026-109663 EXPLOITDB text VERIFIED
My Dealer CMS 2.0 - Authentication Bypass
by ThE g0bL!N
EIP-2026-106606 EXPLOITDB text VERIFIED
dynamic flash forum 1.0 Beta - Multiple Vulnerabilities
by Salvatore Fresta