Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-4075 EXPLOITDB php VERIFIED
phpLDAPadmin <1.2.2 - RCE
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
by EgiX
CVE-2006-4278 EXPLOITDB php
SportsPHool 1.0 - RCE
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the mainnav parameter.
by cr4wl3r
EIP-2026-106530 EXPLOITDB php
Dolphin 7.0.7 - 'member_menu_queries.php' Remote PHP Code Injection
by EgiX
EIP-2026-107066 EXPLOITDB php
Feed on Feeds 0.5 - Remote PHP Code Injection
by EgiX
CVE-2012-0788 EXPLOITDB php VERIFIED
PHP <5.3.9 - DoS
The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
by anonymous
EIP-2026-108034 EXPLOITDB php
JAKCMS PRO 2.2.5 - Arbitrary File Upload
by EgiX
EIP-2026-102512 EXPLOITDB php VERIFIED
Nortel Contact Recording Centralized Archive 6.5.1 - SQL Injection
by rgod
CVE-2011-4535 EXPLOITDB php VERIFIED
Craig Peterson Turbopower Abbrevia < 3.05 - Memory Corruption
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
by mr_me
CVE-2007-3068 EXPLOITDB php
DVD X Studios Dvd X Player - Buffer Overflow
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.
by Rew
EIP-2026-106152 EXPLOITDB php
Contrexx ShopSystem 2.2 SP3 - 'catId' Blind SQL Injection
by Penguin
EIP-2026-106153 EXPLOITDB php VERIFIED
Contrexx ShopSystem 2.2 SP3 - Blind SQL Injection
by Penguin
EIP-2026-113704 EXPLOITDB php VERIFIED
WordPress Plugin E-Commerce 3.8.4 - SQL Injection
by IHTeam
EIP-2026-105799 EXPLOITDB php
cFTP 0.1 - 'r80' Arbitrary File Upload
by leviathan
EIP-2026-102467 EXPLOITDB php VERIFIED
CA ARCserve D2D r15 GWT RPC - Multiple Vulnerabilities
by rgod
EIP-2026-106976 EXPLOITDB php
ExtCalendar2 - Cookie Authentication Bypass / Backdoor Upload
by Lagripe-Dz
CVE-2011-2505 EXPLOITDB php VERIFIED
Phpmyadmin < 3.3.10.2 - Code Injection
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."
by Mango
CVE-2011-2506 EXPLOITDB php VERIFIED
Phpmyadmin < 3.3.10.2 - Code Injection
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.
by Mango
CVE-2011-10011 EXPLOITDB CRITICAL php VERIFIED
WeBid 1.0.2 - Code Injection
WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.
by EgiX
CVE-2011-1938 EXPLOITDB php VERIFIED
PHP <5.3.7 - Buffer Overflow
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.
by Jonathan Salwan
EIP-2026-103867 EXPLOITDB php VERIFIED
Atlassian JIRA 3.13.5 - File Download Security Bypass
by Ignacio Garrido
EIP-2026-109745 EXPLOITDB php VERIFIED
MyBloggie 2.1.6 - HTML Injection / SQL Injection
by Robin Verton
EIP-2026-110875 EXPLOITDB php VERIFIED
PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (1)
by pentesters.ir
EIP-2026-113167 EXPLOITDB php
w-Agora Forum 4.2.1 - Arbitrary File Upload
by Treasure Priyamal
EIP-2026-106698 EXPLOITDB php
Easy Media Script - SQL Injection
by Lagripe-Dz
CVE-2011-1938 EXPLOITDB php VERIFIED
PHP <5.3.7 - Buffer Overflow
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.
by Marek Kroemeke