Exploitdb Exploits
31,394 exploits tracked across all sources.
Plesk < 8.0.1 - Cross-Site Scripting via get_password.php or login_up.php3 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.
by David Vieira-Kurz
phppeanuts 1.1 - Remote File Inclusion via Include Parameter
PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.
by Hidayat Sagita
Koan Software Mega Mall - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
by laurent gaffie
Koan Software Mega Mall - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
by laurent gaffie
ContentNow 1.30 - Arbitrary File Upload / Cross-Site Scripting
by Timq
Aigaion <= 1.2.1 - Remote File Inclusion via DIR Parameter
Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.
by navairum
SiteXpress E-Commerce System - SQL Injection via dept.asp id Parameter
SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Aria-Security Team
Pilot Cart 7.2 - 'Pilot.asp' SQL Injection
by laurent gaffie
NetVIOS Portal - SQL Injection via NewsID Parameter
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.
by ajann
MGinternet Property Site Manager - XSS
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by laurent gaffie
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
Website Designs for Less Inventory Manager - SQL Injection via pictable picfield or where Parameter
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.
by laurent gaffie
Hpecs Shopping Cart - SQL Injection via Username, Password, or Search Parameter
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
by Security Access Point
High Performance Computers Solutions Shopping Cart - Multiple SQL Injections
by laurent gaffie
FunkyASP Glossary 1.0 - SQL Injection via Alpha Parameter
SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter.
by saps.audit
Evolve Merchant - 'viewcart.asp' SQL Injection
by laurent gaffie
DMXReady Site Engine Manager 1.0 - SQL Injection via mid Parameter
SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
by Aria-Security Team
MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.
by laurent gaffie
MGinternet Car Site Manager - Cross-Site Scripting via s Parameter
Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by laurent gaffie
MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.
by laurent gaffie
BlogMe 3.0 - SQL Injection via Username or Password Field
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: some of these details are obtained from third party information.
by Security Access Point
aspintranet - SQL Injection via default.asp a Parameter
SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQL commands via the a parameter.
by Aria-Security Team
ASP Smiley 1.0 - SQL Injection via Username Field
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field.
by ajann
By Source