Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110841 EXPLOITDB php VERIFIED
PHP-Nuke 5.6/6.x News Module - 'index.php' SQL Injection
by frog
CVE-2003-1245 EXPLOITDB php VERIFIED
Mambo 4.0.12 - Auth Bypass
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
by Simen Bergo
CVE-2003-1244 EXPLOITDB php VERIFIED
Phpbb - SQL Injection
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.
by David Zentner
CVE-2003-1435 EXPLOITDB php VERIFIED
Francisco Burzi Php-nuke - SQL Injection
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
by David Zentner
CVE-2002-2235 EXPLOITDB php VERIFIED
Jelsoft Vbulletin - Numeric Error
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
by Sp.IC
CVE-2004-1824 EXPLOITDB php VERIFIED
Jelsoft vBulletin <3.0 - XSS
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.
by Sp.IC
CVE-2002-1886 EXPLOITDB php VERIFIED
TightAuction 3.0 - Info Disclosure
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
by frog
CVE-2002-2021 EXPLOITDB php VERIFIED
Woltlab Burning Board - XSS
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
by SeazoN
CVE-2002-0484 EXPLOITDB php VERIFIED
PHP - Path Traversal
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
by Tozz
CVE-2004-0327 EXPLOITDB php VERIFIED
Skintech Phpnewsmanager - Path Traversal
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
by anonymous
CVE-2004-0327 EXPLOITDB php VERIFIED
Skintech Phpnewsmanager - Path Traversal
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
by anonymous
CVE-2004-0327 EXPLOITDB php VERIFIED
Skintech Phpnewsmanager - Path Traversal
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
by Dave Wilson
CVE-2001-1013 EXPLOITDB php VERIFIED
Apache - Info Disclosure
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
by Gabriel A Maggiotti
CVE-2001-1246 EXPLOITDB php VERIFIED
PHP <4.2 - Command Injection
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
by Wojciech Purczynski
CVE-2001-0746 EXPLOITDB php VERIFIED
Iplanet Web Server - Buffer Overflow
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.
by Gabriel Maggiotti
CVE-2001-0596 EXPLOITDB php VERIFIED
Netscape Communicator <4.77 - XSS
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.
by Florian Wesch
CVE-2000-0884 EXPLOITDB php VERIFIED
IIS 4.0-5.0 - Path Traversal
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
by BoloTron
CVE-2000-0136 EXPLOITDB php VERIFIED
Cart32 - Info Disclosure
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
by CDI
CVE-2000-0059 EXPLOITDB php VERIFIED
PHP3 - Command Injection
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
by Kristian Koehntopp