Exploitdb Exploits

2,814 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-3577 EXPLOITDB perl VERIFIED
Lifetype - SQL Injection
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.
by Alejandro Ramos
CVE-2006-3546 EXPLOITDB perl VERIFIED
Patrice Freydiere ImgSvr - DoS
Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.
by n00b
EIP-2026-117481 EXPLOITDB perl VERIFIED
Microsoft Excel - Universal Hlink Local Buffer Overflow
by SYS 49152
CVE-2006-3394 EXPLOITDB perl VERIFIED
BXCP 0.3.0.4 - SQL Injection
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.
by x23
CVE-2006-3381 EXPLOITDB perl VERIFIED
SturGeoN Upload - RCE
SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.
by Jihad BENABRA
EIP-2026-104581 EXPLOITDB perl VERIFIED
Apple Mac OSX 10.4.6 (PPC) - 'launchd' Local Format String
by Kevin Finisterre
EIP-2026-109501 EXPLOITDB perl VERIFIED
MKPortal 1.0.1 - 'index.php' Directory Traversal
by rUnViRuS
EIP-2026-104582 EXPLOITDB perl VERIFIED
Apple Mac OSX 10.4.6 (x86) - 'launchd' Local Format String
by Kevin Finisterre
EIP-2026-117484 EXPLOITDB perl VERIFIED
Microsoft Excel 2003 - Hlink Stack Buffer Overflow (SEH)
by FistFuXXer
CVE-2006-3309 EXPLOITDB perl VERIFIED
Scout Portal Toolkit <1.4.0 - SQL Injection
SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
by simo64
CVE-2006-1470 EXPLOITDB perl VERIFIED
OpenLDAP - DoS
OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
by Mu Security research
EIP-2026-109751 EXPLOITDB perl VERIFIED
MyBulletinBoard (MyBB) 1.1.3 - 'usercp.php' Create Admin
by Hessam-x
CVE-2006-6232 EXPLOITDB perl VERIFIED
DreamAccount 3.1 - RCE
PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by CrAsh_oVeR_rIdE
CVE-2006-3304 EXPLOITDB perl VERIFIED
DeluxeBB <1.07 - SQL Injection
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.
by Hessam-x
CVE-2006-6750 EXPLOITDB perl VERIFIED
XM Easy Personal FTP Server 5.0.1 - DoS
Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long PORT command. NOTE: this issue might be related to CVE-2006-2226.
by Jerome Athias
CVE-2006-3277 EXPLOITDB perl VERIFIED
MailEnable Standard <1.92-Enterprise <2.0 - DoS
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
by db0
EIP-2026-113101 EXPLOITDB perl VERIFIED
Vincent-Leclercq News 5.2 - 'Diver.php' SQL Injection
by DarkFig
EIP-2026-113165 EXPLOITDB perl VERIFIED
w-Agora 4.2.0 - 'inc_dir' Remote File Inclusion
by the_day
CVE-2006-3221 EXPLOITDB perl VERIFIED
DataLife Engine <4.1 - SQL Injection
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.
by RusH
CVE-2006-3086 EXPLOITDB perl VERIFIED
Microsoft Hyperlink Object Library - Buffer Overflow
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.
by kingcope
CVE-2006-7032 EXPLOITDB perl VERIFIED
FlashBB <1.1.5 - RCE
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.
by h4ntu
CVE-2006-2909 EXPLOITDB perl VERIFIED
PicoZip 4.01 - Buffer Overflow
Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.
by c0rrupt
CVE-2006-1193 EXPLOITDB perl VERIFIED
Microsoft Exchange Server 2000 - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
by Daniel Fabian
CVE-2006-2908 EXPLOITDB perl VERIFIED
MyBB 1.1.2 - RCE
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.
by Javier Olascoaga
EIP-2026-111687 EXPLOITDB perl VERIFIED
RCblog 1.03 - 'POST' Remote Command Execution
by Hessam-x