Exploitdb Exploits
31,394 exploits tracked across all sources.
Trawler Web CMS < 1.8.1 - Remote File Inclusion via Multiple PHP Script Parameters
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_red2 parameter to (a) _msdazu_pdata/redaktion/artikel/up/index.php; (b) addtort.php, (c) colorpik2.php, (d) colorpik3.php, (e) extras_menu.php, (f) farbpalette.php, (g) lese_inc.php, and (h) newfile.php in _msdazu_share/richtext/; the (2) path_scr_dat2 parameter to (i)_msdazu_share/share/insert1.php; the (3) path_red parameter to (j) _msdazu_share/extras/downloads/index.php; and unspecified parameters in other files.
by k1tk4t
Rhode Island Open Meetings Filing System - Remote Code Execution via PROJECT_ROOT Parameter
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php, (3) entityproperties/session.php, or (4) inc/mail.php.
by Mehmet Ince
Johannes Erdfelt Kawf < 1.0 - Remote File Inclusion via Config Parameter
Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php.
by o0xxdark0o
Microsoft Windows XP - 'cmd.exe' Buffer Overflow (PoC)
by Alberto Cortes
Web Group Communication Center < 0.5.6b - SQL Injection via quiz.php qzid Parameter
SQL injection vulnerability in quiz.php in Web Group Communication Center (WGCC) 0.5.6b and earlier allows remote attackers to execute arbitrary SQL commands via the qzid parameter.
by ajann
Lou Portail 1.4.1 - Remote File Inclusion via g_admin_rep Parameter
PHP remote file inclusion vulnerability in admin/admin_module.php in Lou Portail 1.4.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the g_admin_rep parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by MP
Segue CMS < 1.5.7 - Remote File Inclusion via themesdir Parameter
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter.
by nuffsaid
Zorum < 3.5 - Remote File Inclusion via appDirName Parameter
PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appDirName parameter.
by MoHaNdKo
Simple Machines Forum 1.1 RC2 - Cross-Site Scripting via Index.php Action Parameter
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
by b0rizQ
Segue CMS < 1.5.9 - Remote File Inclusion via Theme Parameter
Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a different vector than CVE-2006-5497. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by nuffsaid
powerphlogger < 2.0.9 - Remote Code Execution via rel_path Parameter
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.
by x_w0x
PHP-Nuke pandaBB module - Remote Code Execution via adminpath or basepath Parameter
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.
by nukedclx
phpPowerCards 2.10 - Code Injection
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as demonstrated by creating a new .php file that permits remote file inclusion, and then requesting this file.
by nuffsaid
PHP Live Helper 1.17 - Multiple Remote File Inclusions
by Matdhule
Php AMX 0.9.0 - Remote File Inclusion via plug_path Parameter
PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.
by MP
LoCal Calendar System 1.1 - Remote File Inclusion via LIBDIR Parameter
PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbitrary PHP code via a URL in the LIBDIR parameter.
by o0xxdark0o
Cerberus Helpdesk <3.2.1 - Info Disclosure
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.
by jonepet
Kinesis Interactive Cinema System - SQL Injection via txtUsername or txtPassword Parameters
SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to execute arbitrary SQL commands via the (1) txtUsername (user) or (2) txtPassword (pass) parameters.
by fireboy
Webgenius Goop Gallery 2.0 - 'index.php' Cross-Site Scripting
by Lostmon
phpmybibli < 3.0.1 - Remote Code Execution via Path Parameter Injection
Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path, (2) javascript_path, and (3) include_path parameters in (a) cart.php; the (4) class_path parameter in (b) index.php; the (5) javascript_path parameter in (c) edit.php; the (6) include_path parameter in (d) circ.php; unspecified parameters in (e) select.php; and unspecified parameters in other files.
by the_day
phplist 2.10.2 - Cross-Site Scripting via p Parameter
Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.
by b0rizQ
Lodel CMS 0.7.3 - Remote File Inclusion via calcul-page.php home Parameter
PHP remote file inclusion vulnerability in calcul-page.php in Lodel (patchlodel) 0.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.
by The_BeKiR
PHP Outburst Easynews <4.4.1 - Auth Bypass
admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the ability to execute arbitrary code, via the en_login_id parameter.
by nuffsaid
Dev Web Manager System 1.5 - 'index.php' Cross-Site Scripting
by CorryL
By Source