Exploitdb Exploits
31,394 exploits tracked across all sources.
VIRtech Netquery - Cross-Site Scripting via User-Agent HTTP Header
Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
by Tal Argoni
Mirapoint WebMail - Cross-Site Scripting via CSS Expression in IMG Width
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.
by LegendaryZion
Sun iPlanet Messaging Server Messenger Express - Cross-Site Scripting via CSS Expression
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.
by LegendaryZion
Gepi < 1.4.4 - Remote File Inclusion via gestion/savebackup.php filename Parameter
PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.
by Sumit Siddharth
Easy Web Portal 2.1.2 - Multiple Remote File Inclusions
by MEFISTO
Sun Java System Messenger Express 6 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.
by Handrix
ECI Telecom B-FOCuS Wireless - Info Disclosure
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.
by LegendaryZion
Microsoft Internet Explorer 6.0/7.0 - 'RemoveChild' Denial of Service
by Wojciech H
The Search Engine Project 0.942 - 'Configfunction.php' Remote File Inclusion
by Cyber Security
phpProfiles < 2.1_beta - Remote Code Execution via reqpath or usrinc Parameter
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php.
by v1per-haCker
IG Shop 1.4 - 'Change_Pass.php' Cross-Site Scripting
by SnipEr.X
FreeNews 2.1 - Directory Traversal via chemin Parameter
Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is not set to "1."
by MoHaNdKo
foresite CMS - Cross-Site Scripting via Search Query Parameter
Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.
by David Vieira-Kurz
Exhibit Engine < 1.22 - Remote File Inclusion via toroot Parameter
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
Exhibit Engine < 1.22 - Remote File Inclusion via toroot Parameter
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
Robert Ladstaetter ActionPoll 1.1.1 - RCE
PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
Robert Ladstaetter ActionPoll 1.1.0-1.1.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.
by Cyber Security
Techno Dreams Guest Book < 1.0 - SQL Injection via key Parameter
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
Techno Dreams Announcement - SQL Injection via MainAnnounce2.asp key Parameter
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
easy_notesmanager 0.0.1 - SQL Injection via Username Parameter or Search Page
SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."
by poplix
easy_notesmanager 0.0.1 - SQL Injection via Username Parameter or Search Page
SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."
by poplix
Simple Website Software <0.99 - RCE
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.
by Mehmet Ince
phpmyring < 4.2.1 - SQL Injection via cherche.php limite or mots Parameters
Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.
by ajann
Faq Administrator 2.1b - Remote File Inclusion via faq_reply.php Email Parameter
PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.
by v1per-haCker
By Source