Exploitdb Exploits

2,814 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3311 EXPLOITDB perl VERIFIED
Xoops Articles Module < 1.02 - SQL Injection
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2007-3311 EXPLOITDB perl VERIFIED
Xoops Articles Module < 1.02 - SQL Injection
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
by WiLdBoY
EIP-2026-104025 EXPLOITDB perl VERIFIED
Oracle 10g KUPM$MCP.MAIN - SQL Injection (2)
by bunker
EIP-2026-104023 EXPLOITDB perl VERIFIED
Oracle 10g - KUPM$MCP.MAIN SQL Injection
by bunker
CVE-2007-1725 EXPLOITDB perl VERIFIED
Icebb - SQL Injection
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.
by Hessam-x
CVE-2007-1720 EXPLOITDB perl VERIFIED
Sb-websoft Addressbook - Path Traversal
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.
by bd0rk
CVE-2007-1725 EXPLOITDB perl VERIFIED
Icebb - SQL Injection
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.
by Hessam-x
CVE-2007-1726 EXPLOITDB perl VERIFIED
Icebb - Unrestricted File Upload
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/.
by Hessam-x
EIP-2026-110519 EXPLOITDB perl VERIFIED
PBlang 4.66z - Remote Create Admin
by Hessam-x
EIP-2026-110518 EXPLOITDB perl VERIFIED
PBlang 4.66z - Remote Code Execution
by Hessam-x
CVE-2007-1702 EXPLOITDB perl VERIFIED
PHP <1.07 - RCE
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Cold Zero
CVE-2007-1561 EXPLOITDB perl VERIFIED
Asterisk - Denial of Service
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.
by MADYNES
CVE-2004-1211 EXPLOITDB perl VERIFIED
David Harris Mercury - Memory Corruption
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.
by Jacopo Cervini
CVE-2007-1703 EXPLOITDB perl VERIFIED
Joomla Rwcards Component < 2.4.3 - SQL Injection
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
by ajann
CVE-2007-1704 EXPLOITDB perl VERIFIED
Joomla Car Manager < 1.1 - SQL Injection
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2007-1636 EXPLOITDB perl VERIFIED
Roseonlinecms - Path Traversal
Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.
by GoLd_M
CVE-2003-0001 EXPLOITDB perl VERIFIED
Freebsd - Information Disclosure
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
by Jon Hart
CVE-2003-0001 EXPLOITDB perl VERIFIED
Freebsd - Information Disclosure
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
by Jon Hart
CVE-2007-1645 EXPLOITDB perl VERIFIED
Futuresoft Tftp Server 2000 - Buffer Overflow
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
by Umesh Wanve
CVE-2007-1641 EXPLOITDB perl VERIFIED
Portailphp - SQL Injection
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter.
by Mehmet Ince
CVE-2007-1590 EXPLOITDB perl VERIFIED
Grandstream Budgetone 200 - Denial of Service
The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.
by MADYNES
CVE-2007-1578 EXPLOITDB perl VERIFIED
Atrium Software Mercur Imapd - Buffer Overflow
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
by mu-b
CVE-2006-3317 EXPLOITDB perl VERIFIED
phpRaid 3.0.6 - RCE
PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116.
by Cold Zero
CVE-2006-1781 EXPLOITDB perl VERIFIED
Circle R MTL <1.4.2 - RCE
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.
by fluffy_bunny
CVE-2007-1577 EXPLOITDB perl VERIFIED
Geblog - Path Traversal
Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
by GoLd_M