Exploitdb Exploits

459 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-100979 EXPLOITDB bash VERIFIED
Addonics NAS Adapter - (Authenticated) Denial of Service
by h00die
CVE-2008-5619 EXPLOITDB bash VERIFIED
Chuggnutt HTML to Text Converter <5.2.10 - RCE
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.
by Hunger
EIP-2026-114399 EXPLOITDB bash VERIFIED
Wysi Wiki Wyg 1.0 - Remote Password Retrieve
by StAkeR
CVE-2008-5394 EXPLOITDB bash VERIFIED
Debian GNU/Linux - Local Privilege Escalation
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
by Paul Szabo
EIP-2026-103816 EXPLOITDB bash VERIFIED
Sudo 1.6.9p18 - 'Defaults SetEnv' Local Privilege Escalation
by kingcope
CVE-2008-2936 EXPLOITDB bash VERIFIED
Postfix - Access Control
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
by RoMaNSoFt
CVE-2007-5962 EXPLOITDB bash VERIFIED
vsftpd <2.0.5 - DoS
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
by Martin Nagy
CVE-2008-0310 EXPLOITDB bash VERIFIED
SCO Unixware - Path Traversal
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.
by qaaz
CVE-2008-1343 EXPLOITDB bash VERIFIED
SCO UnixWare 7.1.4 - Path Traversal
Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors.
by qaaz
CVE-2007-3103 EXPLOITDB bash VERIFIED
Fedoraproject Fedora Core - Symlink Following
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
by vl4dZ
CVE-2007-5958 EXPLOITDB bash VERIFIED
X.Org Xserver <1.4.1 - Info Disclosure
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.
by vl4dZ
CVE-2007-6307 EXPLOITDB bash VERIFIED
wwwstats 3.21 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header.
by Jesus Olmos Gonzalez
CVE-2007-6203 EXPLOITDB bash VERIFIED
Apache HTTP Server 2.0.x-2.2.x - XSS
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
by Adrian Pastor
CVE-2007-4952 EXPLOITDB bash VERIFIED
Omnistar Interactive Omnistar Article Manager - SQL Injection
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
by Cold Zero
CVE-2007-4003 EXPLOITDB bash VERIFIED
IBM AIX 5.3 SP6 - Code Injection
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.
by qaaz
CVE-2007-3621 EXPLOITDB bash VERIFIED
AsteriDex <3.0 - RCE
Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.
by Carl Livitt
CVE-2007-2815 EXPLOITDB bash VERIFIED
Microsoft IIS Web Server 5.0 - Auth Bypass
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
by Sha0
CVE-2007-2933 EXPLOITDB bash VERIFIED
Joomla! com_philaform <1.2.0.0 - SQL Injection
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.
by CypherXero
CVE-2007-2553 EXPLOITDB bash VERIFIED
HP Tru64 UNIX <5.1B-4 - Privilege Escalation
Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.
by Daniele Calore
CVE-2006-3747 EXPLOITDB bash VERIFIED
Apache HTTP Server < 1.3.37 - Numeric Error
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
by axis
CVE-2007-1057 EXPLOITDB bash VERIFIED
Nortel Application Switch 2424-1000 - Local Privilege Escalation
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.
by Jon Hart
CVE-2007-0977 EXPLOITDB bash VERIFIED
IBM Lotus Domino R5-R6 WebMail - Info Disclosure
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
by Marco Ivaldi
CVE-2006-5229 EXPLOITDB bash VERIFIED
Openbsd Openssh - Information Disclosure
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames than invalid ones, as demonstrated by sshtime. NOTE: as of 20061014, it appears that this issue is dependent on the use of manually-set passwords that causes delays when processing /etc/shadow due to an increased number of rounds.
by Marco Ivaldi
CVE-2007-0882 EXPLOITDB bash VERIFIED
Solaris 10-11 - Command Injection
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.
by kingcope
CVE-2007-0528 EXPLOITDB bash VERIFIED
Centrality Communications PA168 <1.54 - Info Disclosure
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).
by Adrian _pagvac_ Pastor