Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6694 EXPLOITDB text VERIFIED
E-Uploader Pro 1.0 - Directory Traversal and Arbitrary PHP Code Execution via Language Parameter
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php.
by Kacper
CVE-2006-6976 EXPLOITDB text VERIFIED
CentiPaid < 1.4.2 - Remote Code Execution via absolute_path Parameter
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a URL in the absolute_path parameter.
by Kw3[R]Ln
CVE-2006-4421 EXPLOITDB text VERIFIED
Yapig - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers to inject arbitrary web script or HTML via the D_REFRESH_URL parameter.
by Kuon
CVE-2006-5413 EXPLOITDB text VERIFIED
SuperMod 3.0.0 - Remote File Inclusion via sourcedir Parameter
Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter to (1) Offline.php, (2) Sources/Admin.php, (3) Sources/Offline.php, or (4) content/portalshow.php.
by SilenZ
EIP-2026-114458 EXPLOITDB text VERIFIED
Xoops 2.2.3 - 'search.php' Cross-Site Scripting
by b0rizQ
EIP-2026-111672 EXPLOITDB text VERIFIED
RamaCMS - 'ADODB.Inc.php' Remote File Inclusion
by Le CoPrA
CVE-2006-5310 EXPLOITDB text VERIFIED
Les Visiteurs 2.0.1 - Remote Code Execution via lvc_include_dir Parameter
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.
by k1tk4t
CVE-2006-5390 EXPLOITDB text VERIFIED
phpBB ACP User Registration Module - Remote Code Execution via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by bd0rk
CVE-2006-5308 EXPLOITDB text VERIFIED
Open Conference Systems <1.1.6 - RCE
Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter in (1) include/theme.inc.php or (2) include/footer.inc.php.
by k1tk4t
CVE-2006-6632 EXPLOITDB text VERIFIED
Genepi <1.6 - Remote Code Execution
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the topdir parameter.
by Kw3[R]Ln
CVE-2006-5384 EXPLOITDB text VERIFIED
CDS Agenda < 4.2.9 - Remote Code Execution via SendAlertEmail.php AGE Parameter
PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AGE parameter.
by Drago84
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-6592 EXPLOITDB text VERIFIED
Bloq 0.5.4 - Remote File Inclusion via page[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.
by KorsaN
CVE-2006-5472 EXPLOITDB text VERIFIED
Softerra PHP Developer Library <1.5.3 - RCE
PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter in (1) lib/registry.lib.php, (2) lib/sqlcompose.lib.php, and (3) lib/sqlsearch.lib.php.
by MP
CVE-2006-5294 EXPLOITDB text VERIFIED
phplist < 2.10.3 - Cross-Site Scripting via Unsubscribe Email Parameter
Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter.
by Michiel Dethmers
CVE-2006-5458 EXPLOITDB text VERIFIED
Hinton Design phpht Topsites < 1.0 - Remote File Inclusion via phpht_real_path Parameter
PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter.
by Mehmet Ince
CVE-2006-7147 EXPLOITDB text VERIFIED
phpBB Import Tools Mod 0.1.4 - Remote Code Execution via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by boecke
CVE-2006-5312 EXPLOITDB text VERIFIED
Ajax Shoutbox < 0.0.5 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by boecke
CVE-2006-7091 EXPLOITDB text VERIFIED
phpht Topsites FREE 1.022b - Remote File Inclusion via config.php fullpath Parameter
PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Le CoPrA
CVE-2006-7156 EXPLOITDB text VERIFIED
Keyword Replacer < 1.0 - Remote File Inclusion via pathToFiles Parameter
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.
by Kw3[R]Ln
CVE-2006-6634 EXPLOITDB text VERIFIED
ExtCalThai Module < 0.9.1 - Remote File Inclusion via CONFIG_EXT or mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.
by k1tk4t