Exploitdb Exploits

50,095 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-5000 EXPLOITDB text VERIFIED
MCLogin System <1.3 - SQL Injection
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.
by L0rd CrusAd3r
EIP-2026-107603 EXPLOITDB text
Holiday Travel Portal - Arbitrary File Upload
by Sid3^effects
EIP-2026-106853 EXPLOITDB text VERIFIED
EMO Realty Manager - SQL Injection
by L0rd CrusAd3r
EIP-2026-105685 EXPLOITDB text VERIFIED
CafeEngine 2.3 - SQL Injection
by Sid3^effects
EIP-2026-104694 EXPLOITDB python VERIFIED
Castripper 2.50.70 - '.pls' File Stack Buffer Overflow (DEP Bypass)
by mr_me
EIP-2026-101045 EXPLOITDB perl VERIFIED
Motorola SB5101 Hax0rware Rajko HTTPd - Remote Denial of Service (PoC)
by Dillon Beresford
EIP-2026-101044 EXPLOITDB perl VERIFIED
Motorola SB5101 - Hax0rware Event Reset Remote Overflow
by Dillon Beresford
EIP-2026-118765 EXPLOITDB text VERIFIED
McAfee Unified Threat Management Firewall 4.0.6 - 'page' Cross-Site Scripting
by Adam Baldwin
EIP-2026-118079 EXPLOITDB python VERIFIED
VUPlayer 2.49 - '.m3u' File Universal Buffer Overflow (DEP Bypass) (1)
by mr_me
CVE-2010-2343 EXPLOITDB perl VERIFIED
D.R. Software Audio Converter 8.1, 2007, and 8.05 - Stack-based Buffer Overflow via PLS Playlist File
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.
by chap0
CVE-2010-2343 EXPLOITDB perl VERIFIED
D.R. Software Audio Converter 8.1, 2007, and 8.05 - Stack-based Buffer Overflow via PLS Playlist File
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.
by sud0
CVE-2010-2343 EXPLOITDB python VERIFIED
D.R. Software Audio Converter 8.1, 2007, and 8.05 - Stack-based Buffer Overflow via PLS Playlist File
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.
by sud0
EIP-2026-115176 EXPLOITDB text VERIFIED
EA Battlefield 2 1.41 / Battlefield 2142 1.50 - Multiple Denial of Service Vulnerabilities
by Francis Lavoie-Renaud
EIP-2026-106212 EXPLOITDB text VERIFIED
cPanel 11.25 Image Manager - 'target' Local File Inclusion
by AnTi SeCuRe
CVE-2010-5037 EXPLOITDB text
SenseSites CommonSense CMS - SQL Injection
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
by Pokeng
EIP-2026-105573 EXPLOITDB text VERIFIED
BoastMachine 3.1 - 'key' Cross-Site Scripting
by High-Tech Bridge SA
EIP-2026-104292 EXPLOITDB text
JForum 2.1.8 BookMarks - Cross-Site Request Forgery / Cross-Site Scripting
by Adam Baldwin
CVE-2010-5042 EXPLOITDB text VERIFIED
DJ-ArtGallery 0.9.1 - XSS
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: some of these details are obtained from third party information.
by d0lc3
CVE-2010-5035 EXPLOITDB text VERIFIED
iScripts eSwap 2.0 - Cross-Site Scripting via txtHomeSearch Parameter
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.
by Sid3^effects
CVE-2010-2316 EXPLOITDB text VERIFIED
wmscms < 2.0 - Cross-Site Scripting via search, sbr, p, or sbl Parameters
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137.
by Ariko-Security
CVE-2010-2317 EXPLOITDB text VERIFIED
WmsCms < 2.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to default.asp; and the (6) sbr, (7) pr, and (8) psPrice parameters to printpage.asp.
by Ariko-Security
EIP-2026-113245 EXPLOITDB text VERIFIED
WebBiblio Subject Gateway System - Local File Inclusion
by AntiSecurity
CVE-2010-5044 EXPLOITDB text
Joomla! com_searchlog 3.1.0 - SQL Injection
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. NOTE: some of these details are obtained from third party information.
by XroGuE
EIP-2026-111812 EXPLOITDB text
RTRandomImage - Remote File Inclusion
by Sn!pEr.S!Te Hacker
EIP-2026-111767 EXPLOITDB text VERIFIED
ReVou Twitter Clone 2.0 Beta - SQL Injection / Cross-Site Scripting
by Sid3^effects