Exploitdb Exploits
31,394 exploits tracked across all sources.
Cilem Haber Free Edition - Cross-Site Scripting via hata Parameter
Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ShaFuck31
Phorum <= 3.2.11 - Remote File Inclusion via db_file Parameter
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
by Mr-m07
dol_storye - SQL Injection via id_doc or id_aut Parameter
Multiple SQL injection vulnerabilities in dettaglio.asp in dol storye allow remote attackers to execute arbitrary SQL commands via the (1) id_doc or (2) id_aut parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by WarGame
Microsoft Internet Explorer <6.0 SP1 - DoS
Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by Juan Pablo Lopez
Inside Systems Mail <= 2.0 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
by Vicente Aguilera Diaz
cutenews_aj-fork 167f - Remote File Inclusion via cutepath Parameter
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter.
by DeltahackingTEAM
Cerberus Helpdesk 0.97.3 2.0-2.7 3.2.1 3.3 - Cross-Site Scripting via Spellcheck js Parameter
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by En Douli
ac4p_mobile - Cross-Site Scripting via Taaa Parameter or Polls Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.
by SwEET-DeViL
ac4p_mobile - Cross-Site Scripting via Taaa Parameter or Polls Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.
by SwEET-DeViL
BlueSocket Secure Controller <5.2 - XSS
Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attackers to inject arbitrary web script or HTML via the ad_name parameter.
by Jesus Olmos Gonzalez
vt-forum_lite 1.3 and 1.5 - Cross-Site Scripting via StrMes Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.
by St@rExT
vt-forum_lite 1.3 and 1.5 - Cross-Site Scripting via StrMes Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.
by St@rExT
UApplication Uguestbook 1.0 - 'index.asp' SQL Injection
by Aria-Security Team
Longino Jacome php-Revista 1.1.2 - Code Injection
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the adodb parameter.
by Cold Zero
PHP Upload Center 2.0 - Remote File Inclusion via activate.php footerpage Parameter
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
by GregStar
Simple File Manager 0.24a - Path Traversal
Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.
by flame
PHPNews 1.3.0 - Cross-Site Scripting via URL, ID, Subject, Username, or Time Parameter
Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter.
by Detefix
mx_tinies 1.3.0 - Remote File Inclusion via module_root_path Parameter
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by bd0rk
CuteNews 1.3.6 - Cross-Site Scripting via Result Parameter
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
by Detefix
BBS E-Market Professional - Full Path Disclosure / File Inclusion
by y3dips
DUware DUdownload <1.1 - SQL Injection
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.
by Aria-Security Team
DuWare DuClassmate - SQL Injection via iCity Parameter
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.
by Aria-Security Team
Ultimate HelpDesk - Cross-Site Scripting via Index.asp Keyword Parameter
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
by ajann
Invision Gallery 2.0.7 - 'index.php?IMG' SQL Injection
by infection
Invision Community Blog Mod 1.2.4 - SQL Injection
SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
by anonymous
By Source