Exploitdb Exploits
31,351 exploits tracked across all sources.
Alex Article-Engine 1.3.0 - 'FCKeditor' Arbitrary File Upload
by Batter
3Com Wireless 8760 Dual-Radio 11a/b/g PoE - Multiple Vulnerabilities
by Adrian Pastor
Pluck 4.5.3 - Remote Code Execution via g_pcltar_lib_dir Parameter
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the g_pcltar_lib_dir parameter.
by DSecRG
Musicbox 2.3.6-2.3.7 - SQL Injection via viewalbums.php artistId Parameter
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
by snakespc
Free Directory Script 1.1.1 - Remote Code Execution via API_HOME_DIR Parameter
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter.
by Ghost Hacker
E-topbiz Link Back Checker 1 - Unauthenticated Authentication Bypass via Auth Cookie
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
by x0r
mxCamArchive 2.2 - Unauthenticated Exposure of Sensitive Information via Direct Request
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
by ahmadbady
Exodus 0.10 - Argument Injection via Encoded Spaces in im:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.
by Nine:Situations:Group
QuadComm Q-Shop 3.0 - SQL Injection via UserID or Pwd Parameter
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to CVE-2004-2108.
by Bl@ckbe@rD
Exodus 0.10 - Argument Injection via Encoded Spaces in xmpp:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Nine:Situations:Group
Ultrastats 0.2.144 and 0.3.11 - SQL Injection via serverid Parameter
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
by eek
Simple Customer 1.2 - SQL Injection via Login Password Parameter
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.
by d3b4g
SaturnCMS - SQL Injection via Username Parameter in _userLoggedIn Function
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of these details are obtained from third party information.
by Hussin X
phpFan 3.3.4 - Remote Code Execution via Includepath Parameter
PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.
by ahmadbady
mxCamArchive 2.2 - Authenticated PHP Code Injection via Description Parameter
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.
by ahmadbady
Jadu Galaxies - SQL Injection via categoryID Parameter
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL commands via the categoryID parameter.
by ZoRLu
ScriptsEz FREEze Greetings 1.0 - Info Disclosure
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
by cOndemned
E-topbiz AdManager 4 - SQL Injection via View.php Group Parameter
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
by Hussin X
BoutikOne CMS - Stored Cross-Site Scripting via search_query Parameter
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
by d3v1l
QuadComm Q-Shop < 3.0 - Cross-Site Scripting via search.asp srkeys Parameter
Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter.
by Bl@ckbe@rD
Openasp 3.0 - SQL Injection via idpage Parameter
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.
by StAkeR
PHPStore Yahoo Answers - SQL Injection
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
by snakespc
PHPStore Wholesales - SQL Injection
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Hussin X
By Source