Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111208 EXPLOITDB text VERIFIED
PhpShop Core 0.9.0 RC1 - 'PS_BASE' File Inclusion
by Cold Zero
CVE-2006-5613 EXPLOITDB text VERIFIED
MP3 Streaming DownSampler <3.0 - RCE
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter
by Mehmet Ince
CVE-2006-7107 EXPLOITDB text VERIFIED
Coalescent Systems freePBX <2.1.3 - RCE
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.
by Mehmet Ince
CVE-2006-5623 EXPLOITDB text VERIFIED
ee_tool < 0.4_1 - Remote File Inclusion via cgipath Parameter
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.
by Mehmet Ince
CVE-2006-5635 EXPLOITDB text VERIFIED
Web Wiz Forums - SQL Injection via KW Parameter
SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.
by almaster
CVE-2006-5609 EXPLOITDB text VERIFIED
TorrentFlux 2.1 - Directory Traversal via dir Parameter
Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.
by Christopher
EIP-2026-111351 EXPLOITDB text VERIFIED
PLS-Bannieres 1.21 - 'Bannieres.php' Remote File Inclusion
by Mahmood_ali
EIP-2026-111227 EXPLOITDB text VERIFIED
PHPTreeView 1.0 - 'TreeViewClass.php' Remote File Inclusion
by Prince Islam
CVE-2006-5629 EXPLOITDB text VERIFIED
Hosting Controller < 6.1 Hotfix 3.3 - SQL Injection via ForumID Parameter
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
by Soroush Dalili
CVE-2006-4206 EXPLOITDB text VERIFIED
ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode - Cross-Site Scripting via calendarID Parameter
Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.
by MizoZ
CVE-2006-6416 EXPLOITDB text VERIFIED
PhpLeague Univert PhpLeague 0.81 - RCE
Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/miniseul.php or (2) config.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ajaan
CVE-2006-5624 EXPLOITDB text VERIFIED
MPCS <1.0.0 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by v1per-haCker
CVE-2006-5620 EXPLOITDB text VERIFIED
MiniBILL 1.2.3 - Remote File Inclusion via config[page_dir] Parameter
PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a different vector than CVE-2006-4489.
by Mehmet Ince
CVE-2006-5564 EXPLOITDB text VERIFIED
MAXdev MD-Pro < 1.0.76 - Cross-Site Scripting via user.php op Parameter
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by r00t
CVE-2006-5621 EXPLOITDB text VERIFIED
ask_rave < 0.9b - Remote Code Execution via end.php footfile Parameter
PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.
by v1per-haCker
CVE-2006-5615 EXPLOITDB text VERIFIED
Textpattern 1.19 - Remote File Inclusion via txpcfg[txpath] Parameter
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.
by Bithedz
EIP-2026-111156 EXPLOITDB text VERIFIED
PHPMyConferences 8.0.2 - 'Init.php' Remote File Inclusion
by The-0utl4w
EIP-2026-106080 EXPLOITDB text VERIFIED
CommentIT - 'PathToComment' Remote File Inclusion
by Cold Zero
EIP-2026-106076 EXPLOITDB text VERIFIED
Comment IT 0.2 - 'PathToComment' Remote File Inclusion
by Cold Zero
CVE-2006-5590 EXPLOITDB text VERIFIED
ArticleBeach Script < 2.0 - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Bithedz
EIP-2026-118392 EXPLOITDB text VERIFIED
Cruiseworks 1.09 - 'Cws.exe' Doc Directory Traversal
by Tan Chew Keong
CVE-2006-5571 EXPLOITDB text VERIFIED
CruiseWorks 1.09c-1.09d - Remote Code Execution via Long Doc Parameter
Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter.
by Tan Chew Keong
CVE-2006-5539 EXPLOITDB text VERIFIED
UeberProject Management System <1.0 - RCE
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.
by Mehmet Ince
CVE-2006-5530 EXPLOITDB text VERIFIED
Boesch It-consulting Simpnews < 2.34 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by security@vigilon.com
CVE-2006-5530 EXPLOITDB text VERIFIED
Boesch It-consulting Simpnews < 2.34 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by security@vigilon.com