EXPL-A-2006-005 exploitlabs.com Retro Advisory 002 - SHTTPD: SHTTPD is vulnerable to an overly long GET request.
9ecaa0cca2d02c7da5a4e9a9cc79e5eee2bc762ddd43342d7059ab4877555440
EXPL-A-2006-004 exploitlabs.com Advisory 049 - phpFormGenerator forces insecure usage of permissions for the application to work.
7409cc0d2a8c442311df468f57b9b2f314bdcfcc3caa612cba3fa534895c9ee8
exploitlabs.com Advisory 047 - AspTopSites is susceptible to SQL injection attacks. Details on exploitation provided.
ae0500296b7791f6b8c62c297a23bd0ff3f72a1806282d10ee61c8b5a66629a4
EXPL-A-2005-017 exploitlabs.com Advisory 046 - Dev hound suffers from multiple vulnerabilities including XSS and path disclosure.
91c0c40600c9b49ab6f372d2158ef227d46eba203d6428fb4507b65dbd700319
TellMe versions 1.2 and below are susceptible to cross site scripting attacks.
e0d8d19326916e2fc873564e971c288d15bf3ace0da18692fdb232e9bac8d1fb
Perldiver versions 1.x and 2.x suffer from cross site scripting flaws.
c119c3422a6ce54a1acc8dfdade412bb0bdd52b52a6876f319a899bcea72823c
Mac OS X Weblog Server version 10.4.0 is susceptible to cross site scripting attacks.
cd839b3975e97a7cc43a50f400458622d99c52a49dfd7c5d496467a705bb86ae
Site Studio guestbook does not filter HTML code from user-supplied input. A remote user can create a specially crafted entry that, when the page rendered, will cause arbitrary scripting to be executed by the user's browser.
d1ecee131bdc6efb5f7fa557e952149ebfb57fd6db7044011a2e7d9c08c7f7ee
H-Sphere allows for local username and password disclosure.
3ce67c3e92d804139dd783d5e61b2ca3af8105f347e031dc542d406b77434aa4
QuickBlogger version 1.4 and below is susceptible to a cross site scripting attack.
ff3e82e8c502f427c05bcddb61b4a211c3bbd510fcae82f3c5f0ed4868c38b20
Cool Cafe Chat 1.2.1 suffers from a SQL injection vulnerability via an unsanitized password variable.
6b78863a9257dee742b652723b329cb3ae31c28d7db77fd5ad0dc78f007e9109
XAMPP contains multiple vulnerabilities, including default usernames / passwords and Cross-site scripting issues. Example exploit URLs provided as part of advisory.
1c1cffe32942fde51d981767af0ae64e1987d397b5288232d1cce12aa159380c
Adventia Chat Server Pro 3.0 suffers from cross site scripting flaw.
f5be810e51ce7ac691078c31fe2d121af2db6850a6b2fbc89c05a553bf3508c8
E-Data 2.0 is susceptible to cross site scripting flaws in its search functionality.
820a3a8cc04faebb9fe783b48bdadd595291f8984a989a7e12280e2bbcad577e
EXPL-A-2005-002 exploitlabs.com Advisory 031 - The Samsung ADSL Modem ships with default root, admin, and user accounts and also allows for arbitrary file access on the underlying filesystem.
8781cdcc8a0e6d219a4402867b7c5194121711e509530df3a557353ae00e8bfe
EXPL-A-2005-001 exploitlabs.com Advisory 030 - A vulnerability in Microsoft Outlook Web Access allows malicious attackers to redirect the login to any URL they wish.
cc0fadb803b3aa16e9acd02377c86e4024ea510cee5b3e6bb7f1f5c8d1dfa1bf
SurgeMail 1.x is susceptible to a cross site scripting attack.
e147d20f72f67a6e383c4c5c6754d254d02006b048bfcbfb5ace73ccb50f3091
Exploitlabs.com Advisory 27 - Microsoft Windows Help and Support Center has a vulnerability due to an unspecified input validation error. This can be exploited via the HCP protocol on Microsoft Windows XP and Microsoft Windows 2003 through Internet Explorer or Outlook and allows for arbitrary code execution.
d988b8210aca1e91cb4d3d9dd5b3f573ea60e02d6175fb32fad685eae2dc0074