Exploitdb Exploits
31,394 exploits tracked across all sources.
Active PHP BookMarks 1.1.2 - Multiple Remote File Inclusions
by ThE-LoRd-Of-CrAcKiNg
Microsoft Office 97 - HTMLMARQ.OCX Library Denial of Service
by Michal Bucko
Ace Helpdesk 2.31 - Cross-Site Scripting via Ticket View and Ticket Parameters
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
by SwEET-DeViL
Ace Helpdesk 2.31 - Cross-Site Scripting via Ticket View and Ticket Parameters
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
by SwEET-DeViL
a-ConMan 3.2 beta - Remote File Inclusion via cm_basedir Parameter
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the cm_basedir parameter.
by Matdhule
fipsgallery < 1.5 - SQL Injection via which Parameter
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.
by ajann
fipsforum < 2.6 - SQL Injection via kat Parameter
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.
by ajann
Neocrome Seditio < 1.10 - Authenticated SQL Injection via Double-Encoded ID Parameter
SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).
by nukedx
Seditio 1.10 - 'Users.Profile.Inc.php' SQL Injection
by Mustafa Can Bjorn
PHP Poll Creator < 1.04 - Remote File Inclusion via relativer_pfad Parameter
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.
by iss4m
PicturesPro Photo Cart 3.9 - Remote File Inclusion via admin_folder or path Parameter
Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.
by irvian
Pearl Forums 2.4 - Multiple Remote File Inclusions
by 3l3ctric-Cracker
my_little_weblog - Cross-Site Scripting via Action Parameter
Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.
by the_Edit0r
Neocrome Land Down Under 8.x and earlier - SQL Injection via polls.php id Parameter
SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by nukedx
CuteNews 1.4.5 - 'show_news.php' Cross-Site Scripting
by Alireza Hassani
CuteNews 1.4.5 - 'rss_title' Cross-Site Scripting
by Alireza Hassani
aBitWhizzy - Directory Traversal via f Parameter
Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.
by Security Access Point
Apple Mac OS X 10.4.8 - Denial of Service via Malformed UDTO HFS+ Disk Image
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.
by LMH
Link Exchange Lite 1.0 - Multiple SQL Injections
by laurent gaffie
JiRos Links Manager - SQL Injection via LinkID or CategoryID Parameter
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
by laurent gaffie
JiRos Links Manager - SQL Injection via LinkID or CategoryID Parameter
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
by laurent gaffie
CreaScripts Creadirectory - Cross-Site Scripting via cat Parameter or search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
by laurent gaffie
CreaScripts Creadirectory - SQL Injection via search.asp Category Parameter
SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.
by laurent gaffie
CreaScripts Creadirectory - Cross-Site Scripting via cat Parameter or search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
by laurent gaffie
Wabbit PHP Gallery 0.9 - Directory Traversal via Dir Parameter
Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.
by the_Edit0r
By Source