Exploitdb Exploits
31,394 exploits tracked across all sources.
GenesisTrader 1.0 - Cross-Site Scripting via form.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters.
by Mr_KaLiMaN
GenesisTrader 1.0 - Info Disclosure
form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter.
by Mr_KaLiMaN
AR Memberscript - Remote File Inclusion via script_folder Parameter
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.
by ex0
phpmycms 0.3 - Remote File Inclusion via basic.inc.php basepath_start Parameter
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath_start parameter.
by v1per-haCker
mxBB kb_mods - Remote File Inclusion via module_root_path Parameter
PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by 3l3ctric-Cracker
OpenOffice.org 2.1 - Denial of Service via Crafted DOC File
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
by DiscoJonny
MxBB (MX-System) Portal <mx_modsdb 1.0.0 - RCE
PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by Lu7k
mxBB Knowledge Base Module 2.0.2 - Directory Traversal via phpEx Parameter
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the phpEx parameter.
by 3l3ctric-Cracker
BLOG:CMS <= 4.1.3 - Remote File Inclusion via DIR_ADMIN Parameter
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.
by HACKERS PAL
Winamp Web interface 7.5.13 - Multiple Vulnerabilities
by Luigi Auriemma
PHP ErrorDocs 1.0.0 - Remote File Inclusion via module_root_path Parameter
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by bd0rk
CMS Made Simple 1.0.2 - Cross-Site Scripting via cntnt01searchinput Parameter
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.
by Nicokiller
Barman 0.0.1r3 - Remote File Inclusion via basepath Parameter
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.
by DeltahackingTEAM
Netwin SurgeFTP 2.3a1 - 'SurgeFTPMGR.cgi' Multiple Input Validation Vulnerabilities
by Umesh Wanve
Lotfian Request For Travel 1.0 - 'ProductDetails.asp' SQL Injection
by ajann
Sophos Anti-Virus and Endpoint Security < 6.0.5 - Heap-Based Buffer Overflow via CHM LZX Decompression
Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that specifies a Window_size of 0.
by Damian Put
Sophos Anti-Virus and Endpoint Security < 6.0.5 - Remote Code Execution via Malformed CHM File
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
by Damian Put
Sophos Anti-Virus and Endpoint Security < 6.0.5 - Denial of Service via Malformed RAR Archive
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.
by Damian Put
EzHRS HR Assist <1.05 - SQL Injection
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.
by ajann
ProNews 1.5 - SQL Injection via lire-avis.php aa Parameter
SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
by Mr_KaLiMaN
ProNews 1.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php, and the (8) aa parameter to (b) lire-avis.php.
by Mr_KaLiMaN
ProNews 1.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php, and the (8) aa parameter to (b) lire-avis.php.
by Mr_KaLiMaN
MXBB Profile Control Panel 0.91c - Module Remote File Inclusion
by bd0rk
mxBB 0.91c - Remote File Inclusion via profilcp_constants.php module_root_path Parameter
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by bd0rk
Messageriescripthp 2.0 - SQL Injection
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
by Mr_KaLiMaN
By Source