Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-1743 EXPLOITDB php VERIFIED
Pinnaclesys Pinnacle Studio - Path Traversal
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot backslash) sequence in a Hollywood FX Compressed Archive (.hfz) file. NOTE: this can be leveraged for code execution by decompressing a file to a Startup folder. NOTE: some of these details are obtained from third party information.
by Nine:Situations:Group
CVE-2009-1744 EXPLOITDB php VERIFIED
Pinnaclesys Pinnacle Studio - Path Traversal
InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file.
by Nine:Situations:Group
CVE-2009-1818 EXPLOITDB php VERIFIED
Maxcms - SQL Injection
SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action.
by Securitylab.ir
CVE-2009-1677 EXPLOITDB php VERIFIED
Bitweaver < 2.6 - Code Injection
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.
by Nine:Situations:Group
CVE-2009-1669 EXPLOITDB php VERIFIED
Smarty - Improper Input Validation
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.
by Nine:Situations:Group
CVE-2009-1678 EXPLOITDB php VERIFIED
Bitweaver < 2.6 - Path Traversal
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.
by Nine:Situations:Group
CVE-2010-3870 EXPLOITDB php VERIFIED
Php < 5.2.14 - Improper Input Validation
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
CVE-2009-1911 EXPLOITDB php VERIFIED
QuiXplorer <2.3.2 - Path Traversal
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
by EgiX
EIP-2026-103553 EXPLOITDB php VERIFIED
Mortbay Jetty 7.0.0-pre5 Dispatcher Servlet - Denial of Service
by ikki
CVE-2009-1659 EXPLOITDB php VERIFIED
Intelliants Elitius - Unrestricted File Upload
Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.
by G4N0K
EIP-2026-118209 EXPLOITDB php VERIFIED
Zoom Player Pro 3.30 - '.m3u' Local Buffer Overflow (SEH)
by Nine:Situations:Group
CVE-2009-1516 EXPLOITDB php VERIFIED
Icewarp Merak Mail Server - Memory Corruption
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.
by Nine:Situations:Group
EIP-2026-109128 EXPLOITDB php VERIFIED
LightBlog 9.9.2 - 'register.php' Remote Code Execution
by EgiX
EIP-2026-106509 EXPLOITDB php VERIFIED
Dokeos Lms 1.8.5 - 'whoisonline.php' PHP Code Injection
by EgiX
EIP-2026-107369 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'usersettings.php' SQL Injection
by Nine:Situations:Group::bookoo
EIP-2026-107367 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'savepreferences()/*blocks[]' SQL Injection
by Nine:Situations:Group
EIP-2026-118592 EXPLOITDB php VERIFIED
FTPDMIN 0.96 (Windows XP SP3) - 'RNFR' Remote Buffer Overflow
by surfista
EIP-2026-104702 EXPLOITDB php VERIFIED
PHP 5.2.9 cURL - 'Safe_mode' / 'open_basedir' Restriction Bypass
by Maksymilian Arciemowicz
EIP-2026-107368 EXPLOITDB php VERIFIED
Geeklog 1.5.2 - 'SEC_authenticate()' SQL Injection
by Nine:Situations:Group
EIP-2026-109064 EXPLOITDB php VERIFIED
Lanius CMS 0.5.2 - Arbitrary File Upload
by EgiX
CVE-2009-1282 EXPLOITDB php VERIFIED
Glfusion < 1.1.2 - SQL Injection
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.
by Nine:Situations:Group
CVE-2009-1283 EXPLOITDB php VERIFIED
Glfusion < 1.1.2 - Cryptographic Issue
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.
by Nine:Situations:Group
CVE-2009-1226 EXPLOITDB php VERIFIED
Podcast Generator < 1.1 - Access Control
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
by BlackHawk
CVE-2009-1230 EXPLOITDB php VERIFIED
Podcast Generator < 1.1 - Code Injection
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.
by BlackHawk
CVE-2009-1209 EXPLOITDB php VERIFIED
W3 Amaya - Memory Corruption
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
by Alfons Luja