Exploitdb Exploits
31,394 exploits tracked across all sources.
Enthrallweb eCars 1.0 - SQL Injection
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.
by ajann
Dragon Business Directory - Pro <3.01.12 - SQL Injection
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by ajann
Calendar MX BASIC <1.0.2 - SQL Injection
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ajann
Keep It Simple Guest Book 5.1.1 - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.
by mdx
dreaxteam xt-news 0.1 - SQL Injection via id_news Parameter
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.
by Mr_KaLiMaN
Xt-News 0.1 - Cross-Site Scripting via id_news Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
by Mr_KaLiMaN
Xt-News 0.1 - Cross-Site Scripting via id_news Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
by Mr_KaLiMaN
Oracle Portal 9i and 10g - Cross-Site Scripting via tc Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.
by putosoft softputo
Keep It Simple Guest Book <5.1.1 - Path Traversal
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.
by mdx
EternalMart Guestbook 1.1 - Remote File Inclusion via emgb_admin_path Parameter
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.
by mdx
a-blog < 1.51 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
by Fukumori
Matteo Lucarelli 3editor CMS <0.42 - Path Traversal
Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.
by 3l3ctric-Cracker
WikiReader 1.12 - URL Field Local Buffer Overflow
by Umesh Wanve
FTPRush 1.0.0.610 - Buffer Overflow
Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. Also, it is not clear whether this issue crosses security boundaries.
by Umesh Wanve
Efkan Forum 1.0 - SQL Injection via Grup Parameter
SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter.
by ShaFuq31
PowerClan < 1.14a - Remote File Inclusion via footer.inc.php settings[footer] Parameter
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter.
by nuffsaid
PHP/Mysql Site Builder 0.0.2 - 'htm2PHP.php' File Disclosure
by the master
PgmReloaded < 0.8.5 - Remote Code Execution via PHP File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c) form_header.php.
by nuffsaid
Newxooper 0.9.1 - Remote File Inclusion via compteur/mapage.php chemin Parameter
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
by 3l3ctric-Cracker
mkportal - Cross-Site Request Forgery via img BBcode Tag
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.
by Demential
inertianews 0.02 beta - Remote Code Execution via inews_path Parameter
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.
by bd0rk
Valdersoft Shopping Cart <3.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.
by mdx
Typo3 <4.0.3, 3.7, 3.8, 4.1 beta - Authenticated Command Injection
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
by D. Fabian
textsend < 1.5 - Remote File Inclusion via ROOT_PATH Parameter
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.
by nuffsaid
Calacode @Mail Webmail 4.51 - Filtering Engine HTML Injection
by Philippe C. Caturegli
By Source