Exploitdb Exploits

2,809 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4584 EXPLOITDB perl VERIFIED
Tr Forum 2.0 - Unauthenticated Authentication Bypass and Admin Account Creation via Admin Insert Endpoint
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.
by DarkFig
CVE-2006-4586 EXPLOITDB perl VERIFIED
Tr Forum 2.0 - Privilege Escalation
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
by DarkFig
CVE-2006-4633 EXPLOITDB perl VERIFIED
SoftBB < 0.1 - Path Disclosure via Invalid page[] Parameter
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.
by DarkFig
CVE-2006-4601 EXPLOITDB perl VERIFIED
Annuaire 1Two 2.2 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by DarkFig
CVE-2006-4531 EXPLOITDB perl VERIFIED
Pheap CMS < 1.1 - Remote File Inclusion via lpref Parameter
PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter.
by Kacper
CVE-2006-4604 EXPLOITDB perl VERIFIED
Lanifex Database of Managed Objects < 2.3_beta - Remote File Inclusion via _incMgr Parameter
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote attackers to execute arbitrary PHP code via the _incMgr parameter.
by Kacper
CVE-2006-4426 EXPLOITDB perl VERIFIED
Albert-EasySite < 1.0a5 - Remote File Inclusion via PSA_PATH Parameter
PHP remote file inclusion vulnerability in AES/modules/auth/phpsecurityadmin/include/logout.php in AlberT-EasySite (AES) 1.0a5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter.
by Kacper
CVE-2006-4418 EXPLOITDB perl VERIFIED
Wikepage 2006.2a Opus 10 - Directory Traversal via lng Parameter
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.
by Hessam-x
CVE-2006-4368 EXPLOITDB perl VERIFIED
IntegraMOD Portal 2.x and earlier - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by nukedx
CVE-2006-4365 EXPLOITDB perl VERIFIED
VistaBB <= 2.0.33 - Remote File Inclusion via phpbb_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/functions_mod_user.php or (2) includes/functions_portal.php.
by nukedx
CVE-2006-4367 EXPLOITDB perl VERIFIED
All Topics Hack < 1.5.0 - SQL Injection via Start Parameter
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote attackers to execute arbitrary SQL commands via the start parameter.
by SpiderZ
CVE-2006-4369 EXPLOITDB perl VERIFIED
IntegraMOD Portal 2.x and earlier - Absolute Path Traversal via phpbb_root_path Parameter
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter.
by nukedx
CVE-2006-4364 EXPLOITDB perl VERIFIED
MDaemon < 9.0.6 - Heap-Based Buffer Overflow via Long USER or APOP Command
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings that contain '@' characters in the (1) USER and (2) APOP commands.
by Leon Juranic
EIP-2026-103563 EXPLOITDB perl VERIFIED
Mozilla Firefox 1.5.0.6 - FTP Request Remote Denial of Service
by Tomas Kempinsky
CVE-2006-4300 EXPLOITDB perl VERIFIED
SimpleBlog < 2.0 - SQL Injection via comments.asp id Parameter
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ASIANEAGLE
CVE-2006-4310 EXPLOITDB perl VERIFIED
Firefox 1.5.0.6 - Denial of Service via Crafted FTP Response
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.
by anonymous
CVE-2006-7210 EXPLOITDB perl VERIFIED
Microsoft Windows 2000, XP, and Server 2003 - Denial of Service via Crafted PNG IHDR Block
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
by Preddy
CVE-2006-4240 EXPLOITDB perl VERIFIED
Fusion News 3.7 - Remote File Inclusion via fpath Parameter
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
by O.U.T.L.A.W
CVE-2006-4210 EXPLOITDB perl VERIFIED
phpay 2.02-2.02.1 - Open Mail Relay via Modified Mail Parameters
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information.
by beford
CVE-2006-2502 EXPLOITDB perl VERIFIED
Cyrus IMAPD 2.3.2 - Stack-Based Buffer Overflow via Long USER Command
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
by K-sPecial
EIP-2026-111893 EXPLOITDB perl VERIFIED
SAPID CMS 1.2.3_rc3 - 'rootpath' Remote Code Execution
by simo64
CVE-2006-4114 EXPLOITDB perl VERIFIED
phpmyring < 4.2 - SQL Injection via idsite Parameter
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.
by simo64
CVE-2006-4455 EXPLOITDB perl VERIFIED
xchat < 2.6.7 - Denial of Service via PRIVMSG Command
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving the PRIVMSG command. NOTE: the vendor has disputed this vulnerability, stating that it does not affect 2.6.7 "or any recent version"
by Elo
CVE-2006-3819 EXPLOITDB perl VERIFIED
TWiki 4.0.0-4.0.4 - Remote Code Execution via Configure Script TYPEOF Parameter
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".
by Javier Olascoaga
CVE-2005-0716 EXPLOITDB perl VERIFIED
Mac OS X 10.3.5-10.3.6 - Local Buffer Overflow via CF_CHARSET_PATH Environment Variable
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.
by Kevin Finisterre