Exploitdb Exploits
50,095 exploits tracked across all sources.
VU Web Visitor Analyst - SQL Injection via redir.asp Username or Password Parameter
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.
by L0rd CrusAd3r
BrightSuite Groupware 5.4 - SQL Injection
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.
by L0rd CrusAd3r
nginx 0.7.52-0.7.65 and 0.8-0.8.39 on Windows - Unauthenticated Arbitrary File Read via ::$DATA URI Suffix
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
by Dr_IDE
Symantec Sygate Personal Firewall 5.6 build 2808 - Buffer Overflow via ActiveX SetRegString Method
Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method.
by Lincoln
Steamcast < 0.9.75 - Remote Code Execution via HTTP User-Agent Header
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.
by Metasploit
nginx 0.7.52-0.7.67 - Denial of Service via Encoded Directory Traversal Sequence
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
by Dr_IDE
nginx 0.7.52-0.7.65 and 0.8-0.8.39 on Windows - Unauthenticated Arbitrary File Read via ::$DATA URI Suffix
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
by Jose A. Vazquez
Power Tab Editor 1.7 build 80 - Stack-based Buffer Overflow via Long Font Name in .ptb File
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name.
by sud0
Adobe InDesign CS3 10.0 - Buffer Overflow via Crafted .indd File
Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted .indd file.
by LiquidWorm
Site to Store Automobile - Motorcycle Boat SQL Injection
by L0rd CrusAd3r
Site for Real Estate - Brokers SQL Injection
by L0rd CrusAd3r
Parallels System Automation (PSA) - Local File Inclusion
by Pouya Daneshmand
Development Site Professional Liberal - Company Institutional SQL Injection
by L0rd CrusAd3r
DaLogin 2.2 and 2.2.5 - SQL Injection via new.php id Parameter
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
by hc0
ardeaCore PHP Framework 2.2 - Remote File Inclusion via pathForArdeaCore Parameter
PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. NOTE: some of these details are obtained from third party information.
by cr4wl3r
anecms_blog < 1.3 - SQL Injection via PATH_INFO
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
by High-Tech Bridge SA
anecms_blog < 1.3 - Stored Cross-Site Scripting via Comment Variable
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.
by High-Tech Bridge SA
Savy Soda Documents - Mobile Office Suite '.XLS' Denial of Service
by Matthew Bergin
By Source