Exploitdb Exploits
31,394 exploits tracked across all sources.
Superfreaker Studios USupport 1.0 - SQL Injection via detail.asp id Parameter
SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
Superfreaker Studios UStore 1.0 - SQL Injection via ID Parameter
SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by ajann
Superfreaker Studios UPublisher 1.0 - SQL Injection via viewarticle.asp ID Parameter
SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by ajann
WordPress Core 2.0.5 - 'functions.php' Remote File Inclusion
by _ANtrAX_
Exophpdesk 1.2 - Remote File Inclusion via lang_file Parameter
PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.
by Firewall1954
NuStore 1.0 - SQL Injection via Products.asp SubCatagoryID Parameter
SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.
by ajann
WORK system e-commerce < 3.0.2 - Remote Code Execution via g_include Parameter
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2) module/forum/forum.php, (3) unspecified files under module/, and (4) unspecified files under administration/module/.
by SlimTim10
EncapsCMS 0.3.6 - Remote File Inclusion via Root Parameter
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
by Firewall
bitweaver <= 1.3.1 - Information Disclosure via SQL Error in sort_mode Parameter
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.
by laurent gaffie
bitweaver <= 1.3.1 - Information Disclosure via SQL Error in sort_mode Parameter
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.
by laurent gaffie
bitweaver <= 1.3.1 - Stored Cross-Site Scripting via Article Title, Blog Post Title, or Wiki Description
Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the message title field when submitting an article to articles/edit.php, (2) the message title field when submitting a blog post to blogs/post.php, or (3) the message description field when editing in the Sandbox in wiki/edit.php.
by laurent gaffie
bitweaver <= 1.3.1 - Information Disclosure via SQL Error in sort_mode Parameter
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.
by laurent gaffie
bitweaver <= 1.3.1 - Information Disclosure via SQL Error in sort_mode Parameter
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.
by laurent gaffie
Oracle Internet Directory 10.1.2.0.2 - 'oidldapd' Remote Memory Corruption
by Intevydis
Omnistar Article Manager - Multiple SQL Injections
by Benjamin Moss
MyAlbum < 3.02 - Remote Code Execution via Language File Inclusion
PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the langs_dir parameter.
by Silahsiz Kuvvetler
otterware letterit2 - Remote File Inclusion via lang Parameter
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
by v1per-haCker
SAMEDIA LandShop - SQL Injection via ls.php infield Parameter
SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. NOTE: the start, search_order, search_type, and search_area parameters are already covered by CVE-2005-4018.
by laurent gaffie
SAMEDIA LandShop - Cross-Site Scripting via ls.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.
by laurent gaffie
GimeScripts Shopping Catalog < 0.9.1 - Remote File Inclusion via Custom Parameter
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.
by v1per-haCker
bitweaver <= 1.3.1 - SQL Injection via Newsletter Edition tk Parameter
SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter.
by laurent gaffie
vBlog a0.1_nonfunc - Remote File Inclusion via cfgProgDir Parameter
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter in (1) secure.php or (2) checklogin.php in admin/auth/.
by DeltahackingTEAM
Speedywiki 2.0/2.1 - Multiple Input Validation Vulnerabilities
by laurent gaffie
PHPMyChat Plus 1.9 - Multiple Local File Inclusions
by ajann
By Source