Exploitdb Exploits

50,095 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-2631 EXPLOITDB text VERIFIED
LibTIFF 3.9.0 - Denial of Service via Crafted TIFF File
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
by Tom Lane
EIP-2026-102171 EXPLOITDB python VERIFIED
iOS QuickOffice 3.1.0 - HTTP Method Remote Denial of Service
by Nishant Das Patnaik
CVE-2010-2332 EXPLOITDB python
Impact PDF Reader - Denial of Service via Malformed POST Request Body
Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.
by Nishant Das Patnaik
EIP-2026-101485 EXPLOITDB text VERIFIED
Trend Micro Interscan Web Security Virtual Appliance - Multiple Vulnerabilities
by Ivan Huertas
CVE-2010-5007 EXPLOITDB text VERIFIED
UTStats Beta 4 and earlier - Cross-Site Scripting via mid Parameter
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter.
by LuM Member
CVE-2010-2334 EXPLOITDB text VERIFIED
Yamamah Photo Gallery 1.00 - Path Traversal via Download Parameter
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.
by mat
CVE-2010-1300 EXPLOITDB text VERIFIED
Yamamah (Dove Photo Album) 1.00 - SQL Injection
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.
by CoBRa_21
CVE-2010-5009 EXPLOITDB text VERIFIED
UTStats Beta 4 and earlier - SQL Injection via pid Parameter in matchp Action
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.
by LuM Member
EIP-2026-111470 EXPLOITDB text
Pre Classified Listing - SQL Injection
by L0rd CrusAd3r
EIP-2026-111184 EXPLOITDB text
PHPplanner PHP Planner 0.4 - Multiple Vulnerabilities
by cp77fk4r
EIP-2026-106985 EXPLOITDB text VERIFIED
Eyeland Studio Inc. - SQL Injection
by Mr.P3rfekT
EIP-2026-106984 EXPLOITDB text VERIFIED
Eyeland Studio Inc. - 'game.php' SQL Injection
by CoBRa_21
CVE-2010-2333 EXPLOITDB perl VERIFIED
LiteSpeed Web Server < 4.0.15 - Unauthenticated Source Code Disclosure via Null Byte and .txt Extension
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
by kingcope
CVE-2010-2075 EXPLOITDB perl VERIFIED
UnrealIRCd 3.2.8.1 - Remote Code Execution via Trojaned DEBUG3_DOLOG_SYSTEM Macro
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
by anonymous
EIP-2026-100522 EXPLOITDB text VERIFIED
Real-time ASP Calendar - SQL Injection
by L0rd CrusAd3r
CVE-2010-5021 EXPLOITDB text VERIFIED
Digital Interchange Document Library <5.8.5 - SQL Injection
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.
by L0rd CrusAd3r
CVE-2010-5023 EXPLOITDB text VERIFIED
Digital Interchange Calendar <5.8.5 - SQL Injection
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.
by L0rd CrusAd3r
CVE-2010-2335 EXPLOITDB text
Yamamah Photo Gallery 1.00 - SQL Injection via News Parameter
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.
by anT!-Tr0J4n
CVE-2010-2310 EXPLOITDB python VERIFIED
SolarWinds TFTP Server 10.4.0.13 - Denial of Service via Long Write Request
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
by Nullthreat
EIP-2026-115599 EXPLOITDB perl VERIFIED
Media Player Classic 1.3.1774.0 - mpcpl Local Denial of Service (PoC)
by R3d-D3V!L
EIP-2026-115104 EXPLOITDB perl VERIFIED
CP3 Studio PC Version - Denial of Service
by chap0
CVE-2010-1300 EXPLOITDB text VERIFIED
Yamamah (Dove Photo Album) 1.00 - SQL Injection
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.
by TheMaStEr
CVE-2010-2336 EXPLOITDB text
Yamamah Photo Gallery 1.00 - Unauthenticated Source Code Disclosure via Download Parameter
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.
by anT!-Tr0J4n
EIP-2026-111183 EXPLOITDB text VERIFIED
phpplanner - Cross-Site Scripting / SQL Injection
by anT!-Tr0J4n
EIP-2026-107842 EXPLOITDB text
Infront - SQL Injection
by TheMaStEr