Exploitdb Exploits
31,394 exploits tracked across all sources.
PhpShop Core 0.9.0 RC1 - 'PS_BASE' File Inclusion
by Cold Zero
MP3 Streaming DownSampler <3.0 - RCE
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter
by Mehmet Ince
Coalescent Systems freePBX <2.1.3 - RCE
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.
by Mehmet Ince
ee_tool < 0.4_1 - Remote File Inclusion via cgipath Parameter
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.
by Mehmet Ince
Web Wiz Forums - SQL Injection via KW Parameter
SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.
by almaster
TorrentFlux 2.1 - Directory Traversal via dir Parameter
Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.
by Christopher
PLS-Bannieres 1.21 - 'Bannieres.php' Remote File Inclusion
by Mahmood_ali
PHPTreeView 1.0 - 'TreeViewClass.php' Remote File Inclusion
by Prince Islam
Hosting Controller < 6.1 Hotfix 3.3 - SQL Injection via ForumID Parameter
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
by Soroush Dalili
ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode - Cross-Site Scripting via calendarID Parameter
Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.
by MizoZ
PhpLeague Univert PhpLeague 0.81 - RCE
Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/miniseul.php or (2) config.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ajaan
MPCS <1.0.0 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by v1per-haCker
MiniBILL 1.2.3 - Remote File Inclusion via config[page_dir] Parameter
PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a different vector than CVE-2006-4489.
by Mehmet Ince
MAXdev MD-Pro < 1.0.76 - Cross-Site Scripting via user.php op Parameter
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by r00t
ask_rave < 0.9b - Remote Code Execution via end.php footfile Parameter
PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.
by v1per-haCker
Textpattern 1.19 - Remote File Inclusion via txpcfg[txpath] Parameter
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.
by Bithedz
PHPMyConferences 8.0.2 - 'Init.php' Remote File Inclusion
by The-0utl4w
CommentIT - 'PathToComment' Remote File Inclusion
by Cold Zero
Comment IT 0.2 - 'PathToComment' Remote File Inclusion
by Cold Zero
ArticleBeach Script < 2.0 - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Bithedz
Cruiseworks 1.09 - 'Cws.exe' Doc Directory Traversal
by Tan Chew Keong
CruiseWorks 1.09c-1.09d - Remote Code Execution via Long Doc Parameter
Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter.
by Tan Chew Keong
UeberProject Management System <1.0 - RCE
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.
by Mehmet Ince
Boesch It-consulting Simpnews < 2.34 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by security@vigilon.com
Boesch It-consulting Simpnews < 2.34 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by security@vigilon.com
By Source