![]() 15 new exploits Joomla! Component PBBooking 1.0.4_3 - Multiple Blind SQL Injection Joomla! Component 'com_pbbooking' 1.0.4_3 - Multiple Blind SQL Injection Joomla! Component SimpleShop (com_SimpleShop) - SQL Injection Joomla! Component 'com_SimpleShop' - SQL Injection Joomla! Component Spielothek 1.6.9 - Multiple Blind SQL Injection Joomla! Component 'com_spielothek' 1.6.9 - Multiple Blind SQL Injection Joomla! Component CamelcityDB 2.2 - SQL Injection Joomla! Component 'com_camelcitydb2' 2.2 - SQL Injection Joomla! Component cgtestimonial 2.2 - Multiple Vulnerabilities Joomla! Component 'com_cgtestimonial' 2.2 - Multiple Vulnerabilities Joomla! Component com_neorecruit 1.4 - SQL Injection Joomla! Component 'com_neorecruit' 1.4 - SQL Injection Joomla! Component Teams - Multiple Blind SQL Injection Joomla! Component 'com_teams' - Multiple Blind SQL Injection Joomla! Component Yellowpages - SQL Injection Joomla! Component 'com_yellowpages' - SQL Injection Joomla! Component Amblog 1.0 - Multiple SQL Injections Joomla! Component 'com_amblog' 1.0 - Multiple SQL Injections Joomla! Component com_equipment - SQL Injection Joomla! Component Jgrid 1.0 - Local File Inclusion Joomla! Component OnGallery - SQL Injection Joomla! Component 'com_equipment' - SQL Injection Joomla! Component 'com_jgrid' 1.0 - Local File Inclusion Joomla! Component 'com_ongallery' - SQL Injection Joomla! Component com_Fabrik - SQL Injection Joomla! Component com_extcalendar - Blind SQL Injection Joomla! Component 'com_Fabrik' - SQL Injection Joomla! Component 'com_extcalendar' - Blind SQL Injection Joomla! Component com_zina - SQL Injection Joomla! Component Biblioteca 1.0 Beta - Multiple SQL Injections Joomla! Component 'com_zina' - SQL Injection Joomla! Component 'com_biblioteca' 1.0 Beta - Multiple SQL Injections Joomla! Component com_zoomportfolio - SQL Injection Joomla! Component 'com_zoomportfolio' - SQL Injection Joomla! Component com_remository - Arbitrary File Upload Joomla! Component 'com_remository' - Arbitrary File Upload Joomla! Component com_picsell - Local File Disclosure Joomla! Component com_jefaqpro - Multiple Blind SQL Injection Joomla! Component 'com_picsell' - Local File Disclosure Joomla! Component 'com_jefaqpro' - Multiple Blind SQL Injection Joomla! Component iJoomla! magazine 3.0.1 - Remote File Inclusion Joomla! Component 'com_magazine' 3.0.1 - Remote File Inclusion Joomla! Component Clantools 1.5 - Blind SQL Injection Joomla! Component Clantools 1.2.3 - Multiple Blind SQL Injection Joomla! Component 'com_clantools' 1.5 - Blind SQL Injection Joomla! Component 'com_clantools' 1.2.3 - Multiple Blind SQL Injection Joomla! Component Gantry Framework 3.0.10 - Blind SQL Injection Joomla! Component 'com_gantry' 3.0.10 - Blind SQL Injection Joomla! Component Aardvertiser 2.1 Free - Blind SQL Injection Joomla! Component 'com_aardvertiser' 2.1 - Blind SQL Injection Joomla! Component RSform! 1.0.5 - Multiple Vulnerabilities Joomla! Component 'com_forme' 1.0.5 - Multiple Vulnerabilities Joomla! Component com_jphone - Local File Inclusion Joomla! Component 'com_jphone' - Local File Inclusion Joomla! Component Mosets Tree 2.1.5 - Arbitrary File Upload Joomla! Component 'com_mtree' 2.1.5 - Arbitrary File Upload Joomla! Component com_jgen - SQL Injection Joomla! Component 'com_jgen' - SQL Injection Joomla! Component com_restaurantguide - Multiple Vulnerabilities Joomla! Component 'com_restaurantguide' - Multiple Vulnerabilities Joomla! Component com_elite_experts - SQL Injection Joomla! Component 'com_elite_experts' - SQL Injection Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injection Joomla! Component com_ezautos - SQL Injection Joomla! Component 'com_timetrack' 1.2.4 - Multiple SQL Injection Joomla! Component 'com_ezautos' - SQL Injection Joomla! Component je Guestbook 1.0 - Multiple Vulnerabilities Joomla! Component 'com_jeguestbook' 1.0 - Multiple Vulnerabilities Joomla! Component JE Job - SQL Injection Joomla! Component JE Directory - SQL Injection Joomla! Component 'com_jejob' - SQL Injection Joomla! Component 'com_jedirectory' - SQL Injection Joomla! Component Community Builder Enhenced (CBE) - Local File Inclusion / Remote Code Execution Joomla! Component 'com_cbe' - Local File Inclusion / Remote Code Execution Joomla! Component js Calendar 1.5.1 Joomla! - Multiple Vulnerabilities Joomla! Component 'com_jscalendar' 1.5.1 - Multiple Vulnerabilities Joomla! Component JE Ajax Event Calendar (com_jeajaxeventcalendar) - SQL Injection Joomla! Component 'com_jeajaxeventcalendar' - SQL Injection Joomla! Component com_jfuploader < 2.12 - Arbitrary File Upload Joomla! Component 'com_jfuploader' < 2.12 - Arbitrary File Upload Joomla! Component Flip Wall (com_flipwall) - SQL Injection Joomla! Component Sponsor Wall (com_sponsorwall) - SQL Injection Joomla! Component 'com_flipwall' - SQL Injection Joomla! Component 'com_sponsorwall' - SQL Injection sweetrice CMS 0.6.7 - Multiple Vulnerabilities SweetRice 0.6.7 - Multiple Vulnerabilities Joomla! Component ccInvoices (com_ccinvoices) - SQL Injection Joomla! Component 'com_ccinvoices' - SQL Injection Joomla! Component com_connect - Local File Inclusion Joomla! Component DCNews com_dcnews - Local File Inclusion Joomla! Component 'com_connect' - Local File Inclusion Joomla! Component 'com_dcnews' - Local File Inclusion Joomla! Component com_ckforms - Local File Inclusion Joomla! Component com_clan - SQL Injection Joomla! Component 'com_ckforms' - Local File Inclusion Joomla! Component 'com_clan' - SQL Injection Joomla! Component com_clanlist - SQL Injection Joomla! Component 'com_clanlist' - SQL Injection Joomla! Component ProDesk 1.5 - Local File Inclusion Joomla! Component 'com_pro_desk' 1.5 - Local File Inclusion Joomla! Component JQuarks4s 1.0.0 - Blind SQL Injection Joomla! Component 'com_jquarks4s' 1.0.0 - Blind SQL Injection Joomla! Component btg_oglas - HTML / Cross-Site Scripting Injection Joomla! Component com_markt - SQL Injection Joomla! Component com_img - Local File Inclusion Joomla! Component 'btg_oglas' - HTML / Cross-Site Scripting Injection Joomla! Component 'com_markt' - SQL Injection Joomla! Component 'com_img' - Local File Inclusion Joomla! Component com_jsupport - Cross-Site Scripting Joomla! Component com_jsupport - SQL Injection Joomla! Component 'com_jsupport' - Cross-Site Scripting Joomla! Component 'com_jsupport' - SQL Injection Joomla! Component ccBoard 1.2-RC - Multiple Vulnerabilities Joomla! Component 'com_ccboard' 1.2-RC - Multiple Vulnerabilities Joomla! Component com_alfurqan15x - SQL Injection Joomla! Component 'com_alfurqan15x' - SQL Injection Joomla! Component Maian Media (com_maianmedia) - SQL Injection Joomla! Component 'com_maianmedia' - SQL Injection Joomla! Component Template Mosets Tree 2.1.6 - Overwrite Cross-Site Request Forgery Joomla! Component 'com_mtree' 2.1.6 - Overwrite Cross-Site Request Forgery Joomla! Component com_jimtawl - Local File Inclusion Joomla! Component 'com_jimtawl' - Local File Inclusion Joomla! Component JE Auto 1.0 - SQL Injection Joomla! Component 'com_jeauto' 1.0 - SQL Injection Joomla! Component Billy Portfolio 1.1.2 - Blind SQL Injection Joomla! Component 'com_billyportfolio' 1.1.2 - Blind SQL Injection Joomla! Component JRadio (com_jradio) - Local File Inclusion Joomla! Component 'com_jradio' - Local File Inclusion Joomla! Component JE Auto (com_jeauto) - Local File Inclusion Joomla! Component 'com_jeauto' - Local File Inclusion Joomla! Component Jotloader 2.2.1 - Local File Inclusion Joomla! Component 'com_jotloader' 2.2.1 - Local File Inclusion Joomla! Component com_xgallery 1.0 - Local File Inclusion Joomla! Component 'com_xgallery' 1.0 - Local File Inclusion Joomla! Component com_ponygallery - Remote File Inclusion Joomla! Component com_adsmanager - Remote File Inclusion Joomla! Component 'com_ponygallery' - Remote File Inclusion Joomla! Component 'com_adsmanager' - Remote File Inclusion Joomla! Component com_xmovie 1.0 - Local File Inclusion Joomla! Component 'com_xmovie' 1.0 - Local File Inclusion Joomla! Component com_idoblog - SQL Injection Joomla! Component 'com_idoblog' - SQL Injection Joomla! Plugin Captcha 4.5.1 - Local File Disclosure Joomla! Plugin 'Captcha' 4.5.1 - Local File Disclosure Joomla! Component People 1.0.0 - SQL Injection Joomla! Component 'com_people' 1.0.0 - SQL Injection Joomla! Component People 1.0.0 - Local File Inclusion Joomla! Component 'com_people' 1.0.0 - Local File Inclusion Joomla! Component allCineVid 1.0.0 - Blind SQL Injection Joomla! Component 'com_allcinevid' 1.0.0 - Blind SQL Injection Joomla! Component B2 Portfolio 1.0.0 - Multiple SQL Injections Joomla! Component 'com_b2portfolio' 1.0.0 - Multiple SQL Injections Joomla! Component XCloner (com_xcloner-backupandrestore) - Remote Command Execution Joomla! Component 'com_xcloner-backupandrestore' - Remote Command Execution Joomla! Component com_booklibrary - SQL Injection Joomla! Component 'com_booklibrary' - SQL Injection Joomla! Component com_virtuemart 1.1.7 - Blind SQL Injection Joomla! Component 'com_virtuemart' 1.1.7 - Blind SQL Injection Joomla! Component JCE (com_jce) - Blind SQL Injection Joomla! Component 'com_jce' - Blind SQL Injection Joomla! Component com_versioning - SQL Injection Joomla! Component com_hello - SQL Injection Joomla! Component 'com_versioning' - SQL Injection Joomla! Component 'com_hello' - SQL Injection Joomla! Component com_question - SQL Injection Joomla! Component 'com_question' - SQL Injection Joomla! Component 1.0 jDownloads - Arbitrary File Upload Joomla! Component 1.0 'com_jdownloads' - Arbitrary File Upload Joomla! Component com_jmsfileseller - Local File Inclusion Joomla! Component 'com_jmsfileseller' - Local File Inclusion Joomla! Component com_joomnik - SQL Injection Joomla! Component 'com_joomnik' - SQL Injection Joomla! Plugin Scriptegrator 1.5 - File Inclusion Joomla! Component 'Scriptegrator' 1.5 - File Inclusion Joomla! Component A Cool Debate 1.0.3 - Local File Inclusion Joomla! Component com_team - SQL Injection Joomla! Component 'com_acooldebate' 1.0.3 - Local File Inclusion Joomla! Component 'com_team' - SQL Injection Joomla! Component Calc Builder - 'id' Blind SQL Injection Joomla! Component 'com_calcbuilder' - 'id' Parameter Blind SQL Injection Joomla! Component JoomlaXi - Persistent Cross-Site Scripting Joomla! Component 'JoomlaXi' - Persistent Cross-Site Scripting Joomla! Component mdigg - SQL Injection Joomla! Component 'mdigg' - SQL Injection Joomla! Component Xmap 1.2.11 - Blind SQL Injection Joomla! Component 'com_xmap' 1.2.11 - Blind SQL Injection Joomla! Component SOBI2 2.9.3.2 - Blind SQL Injections Joomla! Component 'com_sobi2' 2.9.3.2 - Blind SQL Injections Joomla! Component Appointment Booking Pro - Local File Inclusion Joomla! Component 'com_rsappt_pro2' - Local File Inclusion Joomla! Component JE K2 Story Submit - Local File Inclusion Joomla! Component 'com_jesubmit' - Local File Inclusion Joomla! Component mod_spo - SQL Injection Joomla! Component 'mod_spo' - SQL Injection Joomla! Component com_virtuemart 1.5 / 1.1.7 - Blind Time-Based SQL Injection (Metasploit) Joomla! Component 'com_virtuemart' 1.5 / 1.1.7 - Blind Time-Based SQL Injection (Metasploit) Joomla! Component com_obSuggest - Local File Inclusion Joomla! Component 'com_obSuggest' - Local File Inclusion Joomla! Component com_jdirectory - SQL Injection Joomla! Component 'com_jdirectory' - SQL Injection Joomla! Component TNR Enhanced Joomla! Search - SQL Injection Joomla! Component 'com_esearch' - SQL Injection Joomla! Component JoomTouch - Local File Inclusion Joomla! Component 'com_joomtouch' - Local File Inclusion Joomla! Extension JCE 2.0.10 - Multiple Vulnerabilities Joomla! Component 'com_jce' 2.0.10 - Multiple Vulnerabilities Joomla! Component simple file lister module 1.0 - Directory Traversal Joomla! Component 'mod_simpleFileLister' 1.0 - Directory Traversal Joomla! Component YJ Contact us - Local File Inclusion Joomla! Component 'com_yjcontactus' - Local File Inclusion Joomla! Component Time Returns (com_timereturns) 2.0 - SQL Injection Joomla! Component 'com_timereturns' 2.0 - SQL Injection Joomla! Component Techfolio 1.0 - SQL Injection Joomla! Component 'com_techfolio' 1.0 - SQL Injection Joomla! Component JEEMA Sms 3.2 - Multiple Vulnerabilities Joomla! Component Vik Real Estate 1.0 - Multiple Vulnerabilities Joomla! Component 'com_jeemasms' 3.2 - Multiple Vulnerabilities Joomla! Component 'com_vikrealestate' 1.0 - Multiple Vulnerabilities Joomla! Component HM-Community com_hmcommunity - Multiple Vulnerabilities Joomla! Component 'com_hmcommunity' - Multiple Vulnerabilities Joomla! Component Alameda (com_alameda) 1.0 - SQL Injection Joomla! Component 'com_alameda' 1.0 - SQL Injection Joomla! Component Jobprofile (com_jobprofile) - SQL Injection Joomla! Component 'com_jobprofile' - SQL Injection Joomla! Component QContacts 1.0.6 - SQL Injection Joomla! Component 'com_qcontacts' 1.0.6 - SQL Injection Joomla! Component com_dshop - SQL Injection Joomla! Component 'com_dshop' - SQL Injection Joomla! Component Discussions (com_discussions) - SQL Injection Joomla! Component 'com_discussions' - SQL Injection Joomla! Component The Estate Agent (com_estateagent) - SQL Injection Joomla! Component com_bearleague - SQL Injection Joomla! Component 'com_estateagent' - SQL Injection Joomla! Component 'com_bearleague' - SQL Injection Joomla! Component com_ponygallery - SQL Injection Joomla! Component 'com_ponygallery' - SQL Injection Joomla! Component com_jigsaw - 'Controller' Parameter Directory Traversal Joomla! Component 'com_jigsaw' - 'Controller' Parameter Directory Traversal Joomla! Component com_weblinks - 'Itemid' Parameter SQL Injection Joomla! Component 'com_weblinks' - 'Itemid' Parameter SQL Injection Joomla! Component com_fireboard - 'Itemid' Parameter SQL Injection Joomla! Component 'com_fireboard' - 'Itemid' Parameter SQL Injection Joomla! Component com_dirfrm - Multiple SQL Injections Joomla! Component 'com_dirfrm' - Multiple SQL Injections Joomla! Component Spain - 'nv' Parameter SQL Injection Joomla! Component 'com_spain' - 'nv' Parameter SQL Injection Joomla! Component com_tax - 'eid' Parameter SQL Injection Joomla! Component 'com_tax' - 'eid' Parameter SQL Injection Joomla! Component Club Manager - 'cm_id' Parameter SQL Injection Joomla! Component 'com_clubmanager' - 'cm_id' Parameter SQL Injection Joomla! / Mambo Component com_trade - 'PID' Parameter Cross-Site Scripting Joomla! / Mambo Component 'com_trade' - 'PID' Parameter Cross-Site Scripting Joomla! Component com_jstore - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_jstore' - 'Controller' Parameter Local File Inclusion Joomla! Component Catalogue - SQL Injection / Local File Inclusion Joomla! Component 'com_catalogue' - SQL Injection / Local File Inclusion Joomla! Component AutoArticles 3000 - 'id' Parameter SQL Injection Joomla! Component 'com_a3000' - 'id' Parameter SQL Injection Joomla! Component Store Directory - 'id' Parameter SQL Injection Joomla! Component 'com_storedirectory' - 'id' Parameter SQL Injection Joomla! Component Annuaire - 'id' Parameter SQL Injection Joomla! Component 'com_annuaire' - 'id' Parameter SQL Injection Joomla! Component Jeformcr - 'id' Parameter SQL Injection Joomla! Component JExtensions Property Finder - 'sf_id' Parameter SQL Injection Joomla! Component 'com_jeformcr' - 'id' Parameter SQL Injection Joomla! Component 'com_jesectionfinder' - 'sf_id' Parameter SQL Injection Joomla! Component com_mailto - Multiple Cross-Site Scripting Vulnerabilities Joomla! Component Redirect 'com_redirect' 1.5.19 - Local File Inclusion Joomla! Component 'com_mailto' - Multiple Cross-Site Scripting Vulnerabilities Joomla! Component 'com_redirect' 1.5.19 - Local File Inclusion Joomla! Component Classified - SQL Injection Joomla! Component 'com_classified' - SQL Injection Joomla! Component com_frontenduseraccess - Local File Inclusion Joomla! Component 'com_frontenduseraccess' - Local File Inclusion Joomla! Component VirtueMart eCommerce 1.1.6 - SQL Injection Joomla! Component 'com_virtuemart' 1.1.6 - SQL Injection Joomla! Component com_clan_members - 'id' Parameter SQL Injection Joomla! Component 'com_clan_members' - 'id' Parameter SQL Injection Joomla! Component com_phocadownload - Local File Inclusion Joomla! Component 'com_phocadownload' - Local File Inclusion Joomla! Component com_cbcontact - 'contact_id' Parameter SQL Injection Joomla! Component 'com_cbcontact' - 'contact_id' Parameter SQL Injection Joomla! Component com_maplocator - 'cid' Parameter SQL Injection Joomla! Component 'com_maplocator' - 'cid' Parameter SQL Injection Joomla! Component com_shop - SQL Injection Joomla! Component 'com_shop' - SQL Injection Joomla! Component Virtual Money 'com_virtualmoney' 1.5 - SQL Injection Joomla! Component CCBoard - SQL Injection / Arbitrary File Upload Joomla! Component 'com_virtualmoney' 1.5 - SQL Injection Joomla! Component 'com_ccboard' - SQL Injection / Arbitrary File Upload Joomla! Component com_morfeoshow - 'idm' Parameter SQL Injection Joomla! Component 'com_morfeoshow' - 'idm' Parameter SQL Injection Joomla! Component com_jr_tfb - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_jr_tfb' - 'Controller' Parameter Local File Inclusion Joomla! Component com_voj - SQL Injection Joomla! Component 'com_voj' - SQL Injection Joomla! Component Foto - 'id_categoria' Parameter SQL Injection Joomla! Component 'com_foto' - 'id_categoria' Parameter SQL Injection Joomla! Component Juicy Gallery - 'picId' Parameter SQL Injection Joomla! Component com_hospital - SQL Injection Joomla! Component Controller - 'Itemid' Parameter SQL Injection Joomla! Component 'com_juicy' - 'picId' Parameter SQL Injection Joomla! Component 'com_hospital' - SQL Injection Joomla! Component 'com_controller' - 'Itemid' Parameter SQL Injection Joomla! Component com_resman - Cross-Site Scripting Joomla! Component com_newssearch - SQL Injection Joomla! Component 'com_newssearch' - SQL Injection Joomla! Component Slideshow Gallery - 'id' Parameter SQL Injection Joomla! Component 'com_xeslidegalfx' - 'id' Parameter SQL Injection Joomla! Component com_community - 'userid' Parameter SQL Injection Joomla! Component 'com_community' - 'userid' Parameter SQL Injection Joomla! Component com_biitatemplateshop - 'groups' Parameter SQL Injection Joomla! Component 'com_biitatemplateshop' - 'groups' Parameter SQL Injection Joomla! Component com_expedition - 'id' Parameter SQL Injection Joomla! Component 'com_expedition' - 'id' Parameter SQL Injection Joomla! Component com_tree - 'key' Parameter SQL Injection Joomla! Component com_br - 'state_id' Parameter SQL Injection Joomla! Component com_shop - 'id' Parameter SQL Injection Joomla! Component 'com_tree' - 'key' Parameter SQL Injection Joomla! Component 'com_br' - 'state_id' Parameter SQL Injection Joomla! Component 'com_shop' - 'id' Parameter SQL Injection Joomla! Component Sgicatalog 1.0 - 'id' Parameter SQL Injection Joomla! Component 'com_sgicatalog' 1.0 - 'id' Parameter SQL Injection Joomla! Extension com_alfcontact 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities Joomla! Component 'com_alfcontact' 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities Joomla! Component Content - 'year' Parameter SQL Injection Joomla! Component 'com_content' - 'year' Parameter SQL Injection Joomla! Component com_tsonymf - 'idofitem' Parameter SQL Injection Joomla! Component 'com_tsonymf' - 'idofitem' Parameter SQL Injection Joomla! Component com_caproductprices - 'id' Parameter SQL Injection Joomla! Component 'com_caproductprices' - 'id' Parameter SQL Injection Joomla! Component HD Video Share 1.3 - 'id' Parameter SQL Injection Joomla! Component 'com_contushdvideoshare' 1.3 - 'id' Parameter SQL Injection Joomla! Component com_br - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_br' - 'Controller' Parameter Local File Inclusion Joomla! Component Full 'com_full' - 'id' Parameter SQL Injection Joomla! Component com_sanpham - Multiple SQL Injections Joomla! Component com_xball - 'team_id' Parameter SQL Injection Joomla! Component com_boss - 'Controller' Parameter Local File Inclusion Joomla! Component com_car - Multiple SQL Injections Joomla! Component com_some - 'Controller' Parameter Local File Inclusion Joomla! Component com_bulkenquery - 'Controller' Parameter Local File Inclusion Joomla! Component com_kp - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_full' - 'id' Parameter SQL Injection Joomla! Component 'com_sanpham' - Multiple SQL Injections Joomla! Component 'com_xball' - 'team_id' Parameter SQL Injection Joomla! Component 'com_boss' - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_car' - Multiple SQL Injections Joomla! Component 'com_some' - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_bulkenquery' - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_kp' - 'Controller' Parameter Local File Inclusion Joomla! Component com_jesubmit - 'index.php' Arbitrary File Upload Joomla! Component 'com_jesubmit' - 'index.php' Arbitrary File Upload Joomla! Component com_motor - 'cid' Parameter SQL Injection Joomla! Component com_products - Multiple SQL Injections Joomla! Component 'com_motor' - 'cid' Parameter SQL Injection Joomla! Component 'com_products' - Multiple SQL Injections Joomla! Component com_visa - Local File Inclusion / SQL Injection Joomla! Component com_firmy - 'Id' Parameter SQL Injection Joomla! Component 'com_visa' - Local File Inclusion / SQL Injection Joomla! Component 'com_firmy' - 'Id' Parameter SQL Injection Joomla! Component com_crhotels - 'catid' Parameter SQL Injection Joomla! Component com_propertylab - 'id' Parameter SQL Injection Joomla! Component 'com_crhotels' - 'catid' Parameter SQL Injection Joomla! Component 'com_propertylab' - 'id' Parameter SQL Injection Joomla! Component com_bbs - Multiple SQL Injections Joomla! Component 'com_bbs' - Multiple SQL Injections Joomla! Component com_cmotour - 'id' Parameter SQL Injection Joomla! Component 'com_cmotour' - 'id' Parameter SQL Injection Joomla! Component com_bnf - 'seccion_id' Parameter SQL Injection Joomla! Component 'com_bnf' - 'seccion_id' Parameter SQL Injection Joomla! Component Currency Converter - 'from' Parameter Cross-Site Scripting Joomla! Component 'mod_currencyconverter' - 'from' Parameter Cross-Site Scripting Joomla! Component X-Shop - 'idd' Parameter SQL Injection Joomla! Component Xcomp 'com_xcomp' - Local File Inclusion Joomla! Component 'com_x-shop' - 'idd' Parameter SQL Injection Joomla! Component 'com_xcomp' - Local File Inclusion Joomla! Component com_xvs - 'Controller' Parameter Local File Inclusion Joomla! Component 'com_xvs' - 'Controller' Parameter Local File Inclusion Joomla! Component Machine - Multiple SQL Injections Joomla! Component 'com_machine' - Multiple SQL Injections Joomla! Component CCNewsLetter Module 1.0.7 - 'id' Parameter SQL Injection Joomla! Component Video Gallery - Local File Inclusion / SQL Injection Joomla! Component 'mod_ccnewsletter' 1.0.7 - 'id' Parameter SQL Injection Joomla! Component 'com_videogallery' - Local File Inclusion / SQL Injection Joomla! Component Alphacontent - 'limitstart' Parameter SQL Injection Joomla! Component Joomsport - SQL Injection / Arbitrary File Upload Joomla! Component 'com_alphacontent' - 'limitstart' Parameter SQL Injection Joomla! Component 'com_joomsport' - SQL Injection / Arbitrary File Upload Joomla! Component Simple SWFupload - 'uploadhandler.php' Arbitrary File Upload Joomla! Component Art Uploader - 'upload.php' Arbitrary File Upload Joomla! Component DentroVideo - 'upload.php' Arbitrary File Upload Joomla! Component 'com_simpleswfupload' - 'uploadhandler.php' Arbitrary File Upload Joomla! Component 'mod_artuploader' - 'upload.php' Arbitrary File Upload Joomla! Component 'com_dv' - 'upload.php' Arbitrary File Upload PCMAN FTP Server 2.0.7 - 'ls' Command Buffer Overflow (Metasploit) PCMan FTP Server 2.0.7 - 'ls' Command Buffer Overflow (Metasploit) PCMAN FTP Server 2.0.7 - 'DELETE' Command Buffer Overflow PCMan FTP Server 2.0.7 - 'DELETE' Command Buffer Overflow MySQL / MariaDB / PerconaDB - 'mysql' System User Privilege Escalation / Race Condition MySQL / MariaDB / PerconaDB - 'root' Privilege Escalation MySQL / MariaDB / PerconaDB 5.5.x/5.6.x/5.7.x - 'mysql' System User Privilege Escalation / Race Condition PCMan FTP Server 2.0.7 - 'UMASK' Command Buffer Overflow Freefloat FTP Server 1.0 - 'DIR' Command Buffer Overflow Alienvault OSSIM/USM 5.3.1 - PHP Object Injection Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting Alienvault OSSIM/USM 5.3.1 - SQL Injection Microsoft Internet Explorer 9 - MSHTML CAttrArray Use-After-Free (MS14-056) Citrix Receiver/Receiver Desktop Lock 4.5 - Authentication Bypass SunellSecurity NVR / Camera - Denial Of Service Linux Kernel (Ubuntu / Fedora / Redhat) - 'Overlayfs' Privilege Escalation (Metasploit) MySQL / MariaDB / PerconaDB 5.5.x/5.6.x/5.7.x - 'root' Privilege Escalation Bassmaster 1.5.1 - Batch Arbitrary JavaScript Injection Remote Code Execution (Metasploit) LifeSize Room 5.0.9 - Multiple Vulnerabilities Microsoft Internet Explorer 11 - MSHTML CView::CalculateImageImmunity Use-After-Free SweetRice 1.5.1 - Cross-Site Request Forgery |
||
---|---|---|
platforms | ||
files.csv | ||
README.md | ||
searchsploit |
The Exploit Database Git Repository
This is the official repository of The Exploit Database, a project sponsored by Offensive Security.
The Exploit Database is an archive of public exploits and corresponding vulnerable software, developed for use by penetration testers and vulnerability researchers. Its aim is to serve as the most comprehensive collection of exploits gathered through direct submissions, mailing lists, and other public sources, and present them in a freely-available and easy-to-navigate database. The Exploit Database is a repository for exploits and proof-of-concepts rather than advisories, making it a valuable resource for those who need actionable data right away.
This repository is updated daily with the most recently added submissions. Any additional resources can be found in our binary sploits repository.
Included with this repository is the searchsploit utility, which will allow you to search through the exploits using one or more terms. For more information, please see the SearchSploit manual.
root@kali:~# searchsploit -h
Usage: searchsploit [options] term1 [term2] ... [termN]
==========
Examples
==========
searchsploit afd windows local
searchsploit -t oracle windows
searchsploit -p 39446
=========
Options
=========
-c, --case [Term] Perform a case-sensitive search (Default is inSEnsITiVe).
-e, --exact [Term] Perform an EXACT match on exploit title (Default is AND) [Implies "-t"].
-h, --help Show this help screen.
-j, --json [Term] Show result in JSON format.
-m, --mirror [EDB-ID] Mirror (aka copies) an exploit to the current working directory.
-o, --overflow [Term] Exploit titles are allowed to overflow their columns.
-p, --path [EDB-ID] Show the full path to an exploit (and also copies the path to the clipboard if possible).
-t, --title [Term] Search JUST the exploit title (Default is title AND the file's path).
-u, --update Check for and install any exploitdb package updates (deb or git).
-w, --www [Term] Show URLs to Exploit-DB.com rather than the local path.
-x, --examine [EDB-ID] Examine (aka opens) the exploit using $PAGER.
--colour Disable colour highlighting in search results.
--id Display the EDB-ID value rather than local path.
--nmap [file.xml] Checks all results in Nmap's XML output with service version (e.g.: nmap -sV -oX file.xml).
Use "-v" (verbose) to try even more combinations
=======
Notes
=======
* You can use any number of search terms.
* Search terms are not case-sensitive (by default), and ordering is irrelevant.
* Use '-c' if you wish to reduce results by case-sensitive searching.
* And/Or '-e' if you wish to filter results by using an exact match.
* Use '-t' to exclude the file's path to filter the search results.
* Remove false positives (especially when searching using numbers - i.e. versions).
* When updating from git or displaying help, search terms will be ignored.
root@kali:~#
root@kali:~# searchsploit afd windows local
--------------------------------------------------------------------------------- ----------------------------------
Exploit Title | Path
| (/usr/share/exploitdb/platforms)
--------------------------------------------------------------------------------- ----------------------------------
Microsoft Windows 2003/XP - 'afd.sys' Privilege Escalation (K-plugin) | ./windows/local/6757.txt
Microsoft Windows XP - 'afd.sys' Local Kernel Denial of Service | ./windows/dos/17133.c
Microsoft Windows XP/2003 - 'afd.sys' Privilege Escalation (MS11-080) | ./windows/local/18176.py
Microsoft Windows - 'AfdJoinLeaf' Privilege Escalation (MS11-080) | ./windows/local/21844.rb
Microsoft Windows - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040) | ./win_x86/local/39446.py
Microsoft Windows 7 (x64) - 'afd.sys' Privilege Escalation (MS14-040) | ./win_x86-64/local/39525.py
--------------------------------------------------------------------------------- ----------------------------------
root@kali:~#
root@kali:~# searchsploit -p 39446
Exploit: Microsoft Windows - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
URL: https://www.exploit-db.com/exploits/39446/
Path: /usr/share/exploitdb/platforms/win_x86/local/39446.py
Copied EDB-ID 39446's path to the clipboard.
root@kali:~#
SearchSploit requires either "CoreUtils" or "utilities" (e.g. bash
, sed
, grep
, awk
, etc.) for the core features to work. The self updating function will require git
, and the Nmap XML option to work, will require xmllint
(found in the libxml2-utils
package in Debian-based systems).