Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0130 EXPLOITDB text VERIFIED
iGeneric iG Calendar 1.0 - SQL Injection via User.php ID Parameter
SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Michael Brooks
CVE-2007-0119 EXPLOITDB text VERIFIED
EditTag 1.2 - Cross-Site Scripting via Plain Parameter
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.
by NetJackal
CVE-2007-0119 EXPLOITDB text VERIFIED
EditTag 1.2 - Cross-Site Scripting via Plain Parameter
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.
by NetJackal
CVE-2007-0119 EXPLOITDB text VERIFIED
EditTag 1.2 - Cross-Site Scripting via Plain Parameter
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.
by NetJackal
CVE-2007-0118 EXPLOITDB text VERIFIED
EditTag 1.2 - Path Traversal via File Parameter
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.
by NetJackal
CVE-2007-0118 EXPLOITDB text VERIFIED
EditTag 1.2 - Path Traversal via File Parameter
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.
by NetJackal
CVE-2007-0118 EXPLOITDB text VERIFIED
EditTag 1.2 - Path Traversal via File Parameter
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.
by NetJackal
CVE-2007-0118 EXPLOITDB text VERIFIED
EditTag 1.2 - Path Traversal via File Parameter
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.
by NetJackal
CVE-2007-0144 EXPLOITDB text VERIFIED
Digitizing Quote And Ordering System 1.0 - Authenticated Cross-Site Scripting via search.asp ordernum Parameter
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.
by ajann
CVE-2007-0140 EXPLOITDB text VERIFIED
Kolayindir Download - SQL Injection via down.asp id Parameter
SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ShaFuck31
CVE-2007-0135 EXPLOITDB text VERIFIED
Aratix < 0.2.2_beta_11 - Remote File Inclusion via current_path Parameter
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.
by nuffsaid
EIP-2026-106919 EXPLOITDB text VERIFIED
eTicket 1.5.5 - 'newticket.php' Multiple Cross-Site Scripting Vulnerabilities
by Omer Singer
CVE-2007-0044 EXPLOITDB text VERIFIED
Adobe Acrobat Reader Plugin < 8.0.0 - Cross-Site Request Forgery via FDF/XML/XFDF AJAX Parameters
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
by Stefano Di Paola
CVE-2007-0129 EXPLOITDB text VERIFIED
LocazoList Classifieds < 2.01a_beta5 - SQL Injection via main.asp subcatID Parameter
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.
by ajann
CVE-2007-0092 EXPLOITDB text VERIFIED
e-smart_cart 1.0 - SQL Injection via product_id Parameter
SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.
by ajann
CVE-2007-0054 EXPLOITDB text VERIFIED
vCard PRO - Cross-Site Scripting via gbrowse.php sortby Parameter
Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.
by exexp
EIP-2026-112159 EXPLOITDB text VERIFIED
Simplog 0.9.3 - 'archive.php' SQL Injection
by Javor Ninov
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-0056 EXPLOITDB text VERIFIED
AShop Deluxe 4.5 and AShop Administration Panel - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.
by Hackers Center Security
CVE-2007-3364 EXPLOITDB text VERIFIED
MyServer 0.8.9 - Cross-Site Scripting via CGI Sample Page Body Content
Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content.
by Prili
CVE-2008-0096 EXPLOITDB text VERIFIED
Georgia SoftWorks SSH2 Server < 7.01.0003 - Remote Code Execution via Long Username or Password
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.
by Luigi Auriemma