Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-5429 EXPLOITDB text VERIFIED
BRIM < 1.2.1 - Remote File Inclusion via Renderer Parameter
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter in template.tpl.php in (1) templates/barrel/, (2) templates/sidebar/, (3) templates/text-only, (4) templates/slashdot/, (5) templates/penguin/, (6) templates/pda/, (7) templates/oerdec/, (8) templates/nifty/, (9) templates/mylook, and (10) templates/barry/.
by mdx
CVE-2006-5433 EXPLOITDB text VERIFIED
ALiCE-CMS 0.1 - Remote File Inclusion via CONFIG[local_root] Parameter
PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[local_root] parameter.
by nuffsaid
CVE-2006-4182 EXPLOITDB text VERIFIED
ClamAV < 0.88.5 - Remote Code Execution via Crafted PE File
Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.
by Damian Put
CVE-2006-5419 EXPLOITDB text VERIFIED
University of Glasgow Specimen Image Database - Remote File Inclusion via dir Parameter
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.
by Kw3[R]Ln
CVE-2006-5395 EXPLOITDB text VERIFIED
Microsoft Class Package Export Tool - Buffer Overflow
Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long string. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by mmd_000
CVE-2008-7152 EXPLOITDB text VERIFIED
Specimen Image Database - RCE
Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php.
by Kw3[R]Ln
CVE-2006-6760 EXPLOITDB text VERIFIED
phpmymanga <= 0.8.1 - Remote Code Execution via template.php Parameter Injection
Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) actionsPage or (2) formPage parameter.
by nuffsaid
CVE-2006-5434 EXPLOITDB text VERIFIED
P-News 1.16-1.17 - Remote File Inclusion via pn_lang Parameter
PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitrary PHP code via a URL in the pn_lang parameter.
by vegas78
CVE-2006-6631 EXPLOITDB text VERIFIED
osprey < 1.0 - Remote File Inclusion via lib_dir Parameter
PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter.
by Kw3[R]Ln
CVE-2006-5392 EXPLOITDB text VERIFIED
OpenDock FullCore < 4.4 - Remote File Inclusion via doc_directory Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts.
by Matdhule
CVE-2006-7104 EXPLOITDB text VERIFIED
MOStlyCE - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by The_BeKiR
CVE-2006-7120 EXPLOITDB text VERIFIED
maintain 3.0.0-RC2 - Remote File Inclusion via phphtmllib Parameter
PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. NOTE: this issue might be in phpHtmlLib. NOTE: CVE disputes this issue for proper installations of maintain, since $phphtmllib is set in includes.inc before being used in example6.php
by ERNE
CVE-2006-5210 EXPLOITDB text VERIFIED
IronWebMail <6.1.1 - Path Traversal
Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded "../" sequences ("%252e%252e/").
by Derek Callaway
CVE-2006-7129 EXPLOITDB text VERIFIED
ISS BlackICE PC Protection <3.6 - Auth Bypass
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.
by Matousec Transparent security
CVE-2006-7139 EXPLOITDB text VERIFIED
KMail 1.9.1 - Denial of Service via Malformed HTML Email with Table and Frameset Tags
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.
by nnp
CVE-2006-5388 EXPLOITDB text VERIFIED
WebSPELL <= 4.01.01 - SQL Injection via getsquad Parameter
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
by Kiba
CVE-2006-5386 EXPLOITDB text VERIFIED
NuralStorm Webmail <= 0.98b - Remote File Inclusion via DEFAULT_SKIN Parameter
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter.
by Kw3[R]Ln
CVE-2006-5493 EXPLOITDB text VERIFIED
DigitalHive 2.0 RC2 - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by SHiKaA
CVE-2006-5383 EXPLOITDB text VERIFIED
Def-Blog <= 1.0.1 - SQL Injection via Article Parameter
SQL injection vulnerability in comadd.php in Def-Blog 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.
by SHiKaA
CVE-2006-5400 EXPLOITDB text VERIFIED
CyberBrau 0.9.4 - Remote File Inclusion via Forum Track Path Parameter
PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by Kw3[R]Ln
CVE-2006-5910 EXPLOITDB text VERIFIED
Campware Campsite - Remote File Inclusion via g_documentRoot Parameter
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.
by Kw3[R]Ln
CVE-2006-5401 EXPLOITDB text VERIFIED
AROUNDMe < 0.5.2 - Remote File Inclusion via templatePath Parameter
PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter.
by Kw3[R]Ln
CVE-2006-7131 EXPLOITDB text VERIFIED
Jinzora 2.6 - Remote Code Execution
PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root parameter.
by ddoshomo
CVE-2006-5304 EXPLOITDB text VERIFIED
inccms_core < 1.0.0 - Remote File Inclusion via inc_dir Parameter
PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
by Kacper
EIP-2026-107544 EXPLOITDB text VERIFIED
H-Sphere WebShell 2.x - 'login.php' Cross-Site Scripting
by b0rizQ