Exploitdb Exploits

2,814 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-6134 EXPLOITDB perl VERIFIED
PHPKIT 1.6.4pl1 - SQL Injection
SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a different vector than CVE-2006-1773.
by Shadowleet
CVE-2007-3898 EXPLOITDB perl VERIFIED
Microsoft Windows - Info Disclosure
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
by Alla Berzroutchko
CVE-2007-3898 EXPLOITDB perl VERIFIED
Microsoft Windows - Info Disclosure
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
by Alla Berzroutchko
EIP-2026-110878 EXPLOITDB perl VERIFIED
PHP-Nuke Advertising Module 0.9 - 'modules.php' SQL Injection
by 0x90
CVE-2007-2217 EXPLOITDB perl VERIFIED
Kodak Image Viewer - Code Injection
Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
by grabarz
CVE-2007-5849 EXPLOITDB perl VERIFIED
CUPS <1.3.4 - RCE
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
by wei_wang
EIP-2026-118667 EXPLOITDB perl VERIFIED
IBM Lotus Domino 7.0.2FP1 - IMAP4 Server LSUB Command
by FistFuXXer
CVE-2007-5082 EXPLOITDB perl VERIFIED
Broadcom Brightstor Hierarchical Storage Manager - Memory Corruption
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to missing validation of a length parameter.
by Nice Name Crew
EIP-2026-114751 EXPLOITDB perl VERIFIED
IBM Lotus Domino 7.0.2 - IMAP4 LSUB Buffer Overflow
by Manuel Santamarina Suarez
CVE-2007-5511 EXPLOITDB perl VERIFIED
Oracle Database Server - SQL Injection
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.
by bunker
CVE-2007-5511 EXPLOITDB perl VERIFIED
Oracle Database Server - SQL Injection
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.
by bunker
CVE-2007-5731 EXPLOITDB perl VERIFIED
Apache Jakarta Slide - Path Traversal
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.
by kingcope
EIP-2026-103449 EXPLOITDB perl VERIFIED
DNS Recursion Bandwidth Amplification - Denial of Service (PoC)
by ShadowHatesYou
CVE-2007-5630 EXPLOITDB perl VERIFIED
Bbsprocess Bbportals - SQL Injection
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action.
by Max007
CVE-2007-5461 EXPLOITDB perl VERIFIED
Apache Tomcat - Path Traversal
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
by h3rcul3s
CVE-2007-5646 EXPLOITDB perl VERIFIED
Simple Machines Forum - SQL Injection
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
by Michael Brooks
CVE-2007-5637 EXPLOITDB perl VERIFIED
Nortel Business Communications Manager - Information Disclosure
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
by Daniel Stirnimann
CVE-2007-4980 EXPLOITDB perl VERIFIED
Gcaldaemon - Numeric Error
The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.
by ikki
CVE-2007-5488 EXPLOITDB perl VERIFIED
Asterisk-addons < 1.2.7 - SQL Injection
Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record.
by Humberto J. Abdelnur
CVE-2007-5466 EXPLOITDB perl VERIFIED
Extremail < 2.1.1 - Memory Corruption
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
by mu-b
CVE-2007-5467 EXPLOITDB perl VERIFIED
Extremail < 2.1.1 - Numeric Error
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.
by mu-b
CVE-2007-5467 EXPLOITDB perl VERIFIED
Extremail < 2.1.1 - Numeric Error
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.
by mu-b
CVE-2007-5461 EXPLOITDB perl VERIFIED
Apache Tomcat - Path Traversal
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
by eliteboy
EIP-2026-112684 EXPLOITDB perl VERIFIED
TikiWiki 1.9.8 - 'tiki-graph_formula.php' Command Execution
by str0ke
CVE-2007-5458 EXPLOITDB perl VERIFIED
Alorys-hebergement Kwsphp - SQL Injection
SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.
by s4mi