Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-5527 EXPLOITDB text VERIFIED
Intelimin InteliEditor <1.2.x - RCE
PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter.
by Mehmet Ince
EIP-2026-106230 EXPLOITDB text VERIFIED
Crafty Syntax Live Help 2.9.9 - Multiple Remote File Inclusions
by Crackers_Child
CVE-2006-5603 EXPLOITDB CRITICAL text VERIFIED
Snitz Forums 2000 3.4.06 - SQL Injection via RC Parameter
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Arham Muhammad
CVSS 9.8
CVE-2006-5547 EXPLOITDB text VERIFIED
Open Tibia Server Content Management System <1.0.4 - RCE
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][includes] parameter.
by GregStar
CVE-2006-5546 EXPLOITDB text VERIFIED
Open Tibia Server Content Management System <1.4.1 - RCE
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes] parameter.
by GregStar
CVE-2006-5512 EXPLOITDB text VERIFIED
Zwahlen Online Shop - Cross-Site Scripting via article.htm cat Parameter
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
by MC.Iglo
CVE-2006-5506 EXPLOITDB text VERIFIED
WiClear 0.10 - Remote Code Execution via Path Parameter in Multiple PHP Scripts
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.
by the master
CVE-2006-5566 EXPLOITDB text VERIFIED
Shop-Script - HTTP Response Splitting
CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3) search_with_change_category_ability, (4) logging, (5) feedback, (6) show_price, (7) register, (8) answer, (9) productID, and (10) inside parameters.
by Debasis Mohanty
CVE-2006-5528 EXPLOITDB text VERIFIED
SchoolAlumni Portal 2.26 - Directory Traversal via mod Parameter
Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.
by MP
CVE-2006-5529 EXPLOITDB text VERIFIED
SchoolAlumni Portal 2.26 - Cross-Site Scripting via Query Parameter in Katalog Module
Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained from third party information.
by MP
CVE-2006-5548 EXPLOITDB text VERIFIED
Open Tibia Server Content Management System <2.1.3 - RCE
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][directories][classes] parameter.
by GregStar
CVE-2006-5587 EXPLOITDB text VERIFIED
mdweb < 1.3 - Remote File Inclusion via chemin_appli Parameter
Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code via a URL in the chemin_appli parameter in (1) admin/inc/organisations/form_org.inc.php and (2) admin/inc/organisations/country_insert.php.
by Drago84
EIP-2026-108048 EXPLOITDB text VERIFIED
Jaws 0.5.2 - '/include/JawsDB.php' Remote File Inclusion
by Drago84
CVE-2006-5526 EXPLOITDB text VERIFIED
Fully Modded phpBB < 2021.4.40 - Remote File Inclusion via foing_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.
by 020
CVE-2006-5535 EXPLOITDB text VERIFIED
cpanel - Cross-Site Scripting via Theme and Template Parameters
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to scripts2/editzonetemplate.
by Crackers_Child
CVE-2006-5535 EXPLOITDB text VERIFIED
cpanel - Cross-Site Scripting via Theme and Template Parameters
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to scripts2/editzonetemplate.
by Crackers_Child
EIP-2026-105869 EXPLOITDB text VERIFIED
ClanLite - 'conf-php.php' Remote File Inclusion
by x_w0x
CVE-2006-5512 EXPLOITDB text VERIFIED
Zwahlen Online Shop - Cross-Site Scripting via article.htm cat Parameter
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
by Crackers_Child
CVE-2006-5536 EXPLOITDB text VERIFIED
D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 - Directory Traversal via getpage Parameter
Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.
by jose.palanco
CVE-2006-5485 EXPLOITDB text VERIFIED
SpeedBerg 1.2beta1 - Remote File Inclusion via SPEEDBERG_PATH Parameter
Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP code via a URL in the SPEEDBERG_PATH parameter to (1) entrancePage.tpl.php, (2) generalToolBox.tlb.php, (3) myToolBox.tlb.php, (4) scriplet.inc.php, (5) simplePage.tpl.php, (6) speedberg.class.php, and (7) standardPage.tpl.php.
by k1tk4t
CVE-2006-5543 EXPLOITDB text VERIFIED
PHP Generator of Object SQL Database - RCE
PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by Mehmet Ince
CVE-2006-5521 EXPLOITDB text VERIFIED
Net_DNS < 0.03 - Remote File Inclusion via phpdns_basedir Parameter
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.
by Drago84
CVE-2006-5519 EXPLOITDB text VERIFIED
MambWeather < 1.8.1 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by h4ntu
CVE-2006-5523 EXPLOITDB text VERIFIED
ez-ticket 0.0.1 - Remote File Inclusion via ezt_root_path Parameter
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.
by the master
CVE-2004-1423 EXPLOITDB text VERIFIED
php-calendar < 0.10.1 - Remote Code Execution via phpc_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.
by Mehmet Ince