Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6451 EXPLOITDB text VERIFIED
Plesk < 8.0.1 - Cross-Site Scripting via get_password.php or login_up.php3 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.
by David Vieira-Kurz
CVE-2006-5948 EXPLOITDB text VERIFIED
phppeanuts 1.1 - Remote File Inclusion via Include Parameter
PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.
by Hidayat Sagita
CVE-2006-7170 EXPLOITDB text VERIFIED
Koan Software Mega Mall - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
by laurent gaffie
CVE-2006-7170 EXPLOITDB text VERIFIED
Koan Software Mega Mall - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
by laurent gaffie
EIP-2026-106147 EXPLOITDB text VERIFIED
ContentNow 1.30 - Arbitrary File Upload / Cross-Site Scripting
by Timq
CVE-2006-5930 EXPLOITDB text VERIFIED
Aigaion <= 1.2.1 - Remote File Inclusion via DIR Parameter
Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.
by navairum
CVE-2006-5936 EXPLOITDB text VERIFIED
SiteXpress E-Commerce System - SQL Injection via dept.asp id Parameter
SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Aria-Security Team
EIP-2026-100485 EXPLOITDB text VERIFIED
Pilot Cart 7.2 - 'Pilot.asp' SQL Injection
by laurent gaffie
CVE-2007-1566 EXPLOITDB text VERIFIED
NetVIOS Portal - SQL Injection via NewsID Parameter
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.
by ajann
CVE-2006-6708 EXPLOITDB text VERIFIED
MGinternet Property Site Manager - XSS
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by laurent gaffie
CVE-2006-6709 EXPLOITDB text VERIFIED
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
CVE-2006-6709 EXPLOITDB text VERIFIED
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
CVE-2006-6709 EXPLOITDB text VERIFIED
MGinternet Property Site Manager - SQL Injection
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.
by laurent gaffie
CVE-2006-5943 EXPLOITDB text VERIFIED
Website Designs for Less Inventory Manager - SQL Injection via pictable picfield or where Parameter
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.
by laurent gaffie
CVE-2006-5962 EXPLOITDB text VERIFIED
Hpecs Shopping Cart - SQL Injection via Username, Password, or Search Parameter
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
by Security Access Point
EIP-2026-100348 EXPLOITDB text VERIFIED
High Performance Computers Solutions Shopping Cart - Multiple SQL Injections
by laurent gaffie
CVE-2006-5946 EXPLOITDB text VERIFIED
FunkyASP Glossary 1.0 - SQL Injection via Alpha Parameter
SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter.
by saps.audit
EIP-2026-100315 EXPLOITDB text VERIFIED
Evolve Merchant - 'viewcart.asp' SQL Injection
by laurent gaffie
CVE-2006-7118 EXPLOITDB text VERIFIED
DMXReady Site Engine Manager 1.0 - SQL Injection via mid Parameter
SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
by Aria-Security Team
CVE-2006-5945 EXPLOITDB text VERIFIED
MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.
by laurent gaffie
CVE-2006-5944 EXPLOITDB text VERIFIED
MGinternet Car Site Manager - Cross-Site Scripting via s Parameter
Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by laurent gaffie
CVE-2006-5945 EXPLOITDB text VERIFIED
MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.
by laurent gaffie
CVE-2006-5976 EXPLOITDB text VERIFIED
BlogMe 3.0 - SQL Injection via Username or Password Field
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: some of these details are obtained from third party information.
by Security Access Point
CVE-2006-5987 EXPLOITDB text VERIFIED
aspintranet - SQL Injection via default.asp a Parameter
SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQL commands via the a parameter.
by Aria-Security Team
CVE-2006-5952 EXPLOITDB text VERIFIED
ASP Smiley 1.0 - SQL Injection via Username Field
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field.
by ajann