Exploitdb Exploits
31,394 exploits tracked across all sources.
Buddy Zone 1.5 - SQL Injection via view_sub_cat.php cat_id Parameter
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
by t0pP8uZz
b1gbb 2.24.0 - SQL Injection via id Parameter
Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.
by GoLd_M
PCSoft WinDEV 11 (01F110053p) - Stack-Based Buffer Overflow via WDP Project File Used DLL Field
Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the "used DLL" field in a WDP project file.
by Jerome Athias
WebChat 0.78 - SQL Injection via login.php rid Parameter
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.
by r00t
GL-SH Deaf Forum < 6.4.4 - Remote File Inclusion via Directory Traversal
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php.
by Katatafish
b1gBB 2.24.0 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
by GoLd_M
Oracle Application Server - Cross-Site Scripting via Secondary Login Page
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Kaushal Desai
Microsoft Excel 2003 SP2 - Info Disclosure
Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
by ZhenHan.Liu
QuickTicket 1.2 - Remote File Inclusion via Lang Parameter
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.
by Katatafish
QuickTalk forum 1.3 - Directory Traversal via Lang Parameter
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.
by Katatafish
Papoo 1.0.3 - 'Plugin.php' Authentication Bypass
by Nico Leidecker
eTicket 1.5.5 and 1.5.5.1 - Cross-Site Scripting via err and warn Parameters
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."
by Jesper Jurcenoks
Linksys WAG54GS 1.00.06 - Cross-Site Scripting via setup.cgi Parameters
Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter.
by Petko Petkov
CJG EXPLORER PRO 3.3 - Remote Code Execution via g_pcltar_lib_dir Parameter
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
by GoLd_M
eva-web 1.1-2.2 - Remote File Inclusion via aide or perso Parameter
Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.
by g00ns
elkagroup Image Gallery 1.0 - SQL Injection via pid Parameter
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
by t0pP8uZz
6ALBlog - SQL Injection via Newsid Parameter
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
by Crackers_Child
BugMall Shopping Cart 2.5 - SQL Injection via Basic Search Box
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
by t0pP8uZz
BugMall Shopping Cart <2.5 - Info Disclosure
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
by t0pP8uZz
WebCT Campus Edition 4.1.5.8 - Authenticated Cross-Site Scripting via Mail or Discussion Board Message
Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.
by Lupton
SiteDepth CMS 3.44 - Directory Traversal via ShowImage.php name Parameter
Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
by H4 / XPK
pagetool 1.07 - SQL Injection via News ID Parameter
SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.
by Katatafish
MyNews 0.10 - SQL Injection via authacc Cookie
SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.
by netVigilance
edocstore - SQL Injection via doc_id Parameter
SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.
by t0pP8uZz
Calendarix 0.7.20070307 - SQL Injection via Month/Year Parameters or Search String
Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.
by Jesper Jurcenoks
By Source