Exploitdb Exploits
31,394 exploits tracked across all sources.
b2evolution 1.8.2-1.9 beta - Cross-Site Scripting via app_name, baseurl, or ReqURI Parameters
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
by lotto fischer
b2evolution 1.8.2-1.9 beta - Cross-Site Scripting via app_name, baseurl, or ReqURI Parameters
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
by lotto fischer
Pensacola WEB Designs Xtremeasp Photogallery - SQL Injection
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.
by Aria-Security Team
Pensacola WEB Designs Xtremeasp Photogallery - XSS
Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. NOTE: vector 1 likely overlaps CVE-2006-3032.
by Aria-Security Team
Image Gallery with Access Database - SQL Injection via id, order, or page Parameter
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
by Aria-Security Team
Image Gallery with Access Database - SQL Injection via id, order, or page Parameter
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
by Aria-Security Team
BlueCollar i-Gallery 3.4 - Cross-Site Scripting via n or d Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field, or the myquery parameter, in search.asp. NOTE: some of these details are obtained from third party information.
by Aria-Security Team
TorrentFlux 2.2 - Unauthenticated Arbitrary File Deletion via delfile Parameter
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.
by r0ut3r
TorrentFlux 2.2 - Directory Traversal and Arbitrary File Write via Alias File Parameter
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.
by r0ut3r
SeleniumServer Web Server 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Greg Linares
Conxint FTP 2.2.603 - Multiple Directory Traversal Vulnerabilities
by Greg Linares
TorrentFlux 2.2 - Command Injection
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.
by r0ut3r
Hot Links - Exposure of Sensitive Information via Direct Request with Modified dl Parameter
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
by hack2prison
Yetihost Helm 3.2.10 - Multiple Cross-Site Scripting Vulnerabilities
by Aria-Security Team
SitesOutlet eCommerce Kit - Multiple SQL Injections
by laurent gaffie
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
CandyPress Store 3.5.2.14 - SQL Injection via Policy or Brand Parameter
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
by laurent gaffie
CandyPress Store 3.5.2.14 - SQL Injection via Policy or Brand Parameter
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
by laurent gaffie
ASPIntranet 2.1 - Multiple SQL Injections
by Aria-Security Team
BlogMe 3.0 - Stored Cross-Site Scripting via Name URL or Comments Field
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.
by Security Access Point
NetVIOS < 2.0 - SQL Injection via NewsID Parameter
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.
by ajann
otterware letterit2 - Remote File Inclusion via lang Parameter
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
by Security Access Point
Plesk < 8.0.1 - Cross-Site Scripting via get_password.php or login_up.php3 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.
by David Vieira-Kurz
By Source