Exploitdb Exploits

31,351 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105077 EXPLOITDB text VERIFIED
Alex News-Engine 1.5.1 - Arbitrary File Upload
by Batter
EIP-2026-105074 EXPLOITDB text VERIFIED
Alex Article-Engine 1.3.0 - 'FCKeditor' Arbitrary File Upload
by Batter
EIP-2026-101147 EXPLOITDB text VERIFIED
3Com Wireless 8760 Dual-Radio 11a/b/g PoE - Multiple Vulnerabilities
by Adrian Pastor
CVE-2008-6253 EXPLOITDB text VERIFIED
Pluck 4.5.3 - Remote Code Execution via g_pcltar_lib_dir Parameter
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the g_pcltar_lib_dir parameter.
by DSecRG
CVE-2008-2125 EXPLOITDB text VERIFIED
Musicbox 2.3.6-2.3.7 - SQL Injection via viewalbums.php artistId Parameter
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
by snakespc
CVE-2008-6305 EXPLOITDB text VERIFIED
Free Directory Script 1.1.1 - Remote Code Execution via API_HOME_DIR Parameter
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter.
by Ghost Hacker
CVE-2008-6307 EXPLOITDB text VERIFIED
E-topbiz Link Back Checker 1 - Unauthenticated Authentication Bypass via Auth Cookie
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."
by x0r
CVE-2008-6955 EXPLOITDB text VERIFIED
mxCamArchive 2.2 - Unauthenticated Exposure of Sensitive Information via Direct Request
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
by ahmadbady
CVE-2008-6935 EXPLOITDB text VERIFIED
Exodus 0.10 - Argument Injection via Encoded Spaces in im:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.
by Nine:Situations:Group
CVE-2008-6258 EXPLOITDB text VERIFIED
QuadComm Q-Shop 3.0 - SQL Injection via UserID or Pwd Parameter
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to CVE-2004-2108.
by Bl@ckbe@rD
CVE-2008-6937 EXPLOITDB text VERIFIED
Exodus 0.10 - Argument Injection via Encoded Spaces in xmpp:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Nine:Situations:Group
CVE-2008-6260 EXPLOITDB text VERIFIED
Ultrastats 0.2.144 and 0.3.11 - SQL Injection via serverid Parameter
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
by eek
CVE-2008-6332 EXPLOITDB text VERIFIED
Simple Customer 1.2 - SQL Injection via Login Password Parameter
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.
by d3b4g
CVE-2008-6263 EXPLOITDB text VERIFIED
SaturnCMS - SQL Injection via Username Parameter in _userLoggedIn Function
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of these details are obtained from third party information.
by Hussin X
CVE-2008-6251 EXPLOITDB text VERIFIED
phpFan 3.3.4 - Remote Code Execution via Includepath Parameter
PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.
by ahmadbady
CVE-2008-6956 EXPLOITDB text VERIFIED
mxCamArchive 2.2 - Authenticated PHP Code Injection via Description Parameter
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.
by ahmadbady
CVE-2008-6254 EXPLOITDB text VERIFIED
Jadu Galaxies - SQL Injection via categoryID Parameter
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL commands via the categoryID parameter.
by ZoRLu
CVE-2008-5218 EXPLOITDB text VERIFIED
ScriptsEz FREEze Greetings 1.0 - Info Disclosure
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
by cOndemned
CVE-2008-6261 EXPLOITDB text VERIFIED
E-topbiz AdManager 4 - SQL Injection via View.php Group Parameter
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
by Hussin X
CVE-2008-5126 EXPLOITDB text VERIFIED
BoutikOne CMS - Stored Cross-Site Scripting via search_query Parameter
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
by d3v1l
CVE-2008-6259 EXPLOITDB text VERIFIED
QuadComm Q-Shop < 3.0 - Cross-Site Scripting via search.asp srkeys Parameter
Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the srkeys parameter.
by Bl@ckbe@rD
CVE-2008-6257 EXPLOITDB text VERIFIED
Openasp 3.0 - SQL Injection via idpage Parameter
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.
by StAkeR
CVE-2008-5490 EXPLOITDB text VERIFIED
PHPStore Yahoo Answers - SQL Injection
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
by snakespc
CVE-2008-5493 EXPLOITDB text VERIFIED
PHPStore Wholesales - SQL Injection
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Hussin X
EIP-2026-107157 EXPLOITDB text VERIFIED
FloSites Blog - Multiple SQL Injections
by Vrs-hCk