Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6634 EXPLOITDB text VERIFIED
ExtCalThai Module < 0.9.1 - Remote File Inclusion via CONFIG_EXT or mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.
by k1tk4t
CVE-2006-5291 EXPLOITDB text VERIFIED
Alex Downloadengine - Code Injection
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition, so this issue is probably a duplicate of CVE-2006-4656.
by v1per-haCker
CVE-2006-5307 EXPLOITDB text VERIFIED
AFGB GUESTBOOK 2.2 - Remote File Inclusion via Htmls Parameter
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php.
by mdx
EIP-2026-104841 EXPLOITDB text VERIFIED
4Images 1.7 - 'details.php' Cross-Site Scripting
by Christian Marthen
CVE-2006-5282 EXPLOITDB text VERIFIED
sh-news < 3.1 - Remote File Inclusion via scriptpath Parameter
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php.
by v1per-haCker
CVE-2006-5281 EXPLOITDB text VERIFIED
n@board < 3.1.9e - Remote File Inclusion via Skin Parameter
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skin parameter.
by mdx
CVE-2006-5283 EXPLOITDB text VERIFIED
Minichat 6.0 - Remote File Inclusion via ftag.php mostrar Parameter
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.
by Zickox
EIP-2026-107356 EXPLOITDB text VERIFIED
Gcards 1.13 - 'Addnews.php' Remote File Inclusion
by DeatH VirUs
EIP-2026-106504 EXPLOITDB text VERIFIED
Dokeos 1.6.4 - Multiple Remote File Inclusions Vulnerabilities
by viper-haCker
EIP-2026-103530 EXPLOITDB text VERIFIED
Kmail 1.9.1 - IMG SRC Remote Denial of Service
by nnp
CVE-2006-5315 EXPLOITDB text VERIFIED
registroTL main.php - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter.
by DarkFig
CVE-2006-5289 EXPLOITDB text VERIFIED
vtiger CRM <= 4.2 - Remote File Inclusion via calpath Parameter
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or (3) modules/Calendar/calendar.php.
by the_day
CVE-2006-5314 EXPLOITDB text VERIFIED
TribunaLibre 3.12 Beta - Remote File Inclusion via mostrar Parameter
PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.
by DarkFig
CVE-2006-5249 EXPLOITDB text VERIFIED
TagIt! Tagboard 2.1.B Build 2 - Remote Code Execution via configpath Parameter
PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitrary PHP code via a URL in the configpath parameter.
by k1tk4t
EIP-2026-112329 EXPLOITDB text VERIFIED
Softerra PHP Developer Library 1.5.3 - 'Grid3.lib.php' Remote File Inclusion
by k1tk4t
CVE-2006-5316 EXPLOITDB text VERIFIED
registroTL - Unauthenticated Sensitive Information Exposure via Direct Database Download
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat.
by DarkFig
CVE-2006-5471 EXPLOITDB text VERIFIED
Softerra PHP Developer Library < 1.5.3 - Remote File Inclusion via cfg_dir or lib_dir Parameters
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) cfg_dir and (2) lib_dir parameters.
by k1tk4t
EIP-2026-109804 EXPLOITDB text VERIFIED
MySQLDumper 1.21 - 'sql.php' Cross-Site Scripting
by Crackers_Child
CVE-2006-7130 EXPLOITDB text VERIFIED
Jinzora < 2.1 - Remote Code Execution via Include Path Parameter
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770.
by k1tk4t
CVE-2006-5318 EXPLOITDB text VERIFIED
Nayco JASmine - Remote File Inclusion via Section Parameter
PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter.
by DarkFig
CVE-2006-5262 EXPLOITDB text VERIFIED
Hastymail < 1.5 - Authenticated IMAP Command Injection via CRLF in Mailbox Name
CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.
by Vicente Aguilera Diaz
CVE-2006-5319 EXPLOITDB text VERIFIED
Foafgen 0.3 - Directory Traversal via foaf Parameter
Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.
by DarkFig
CVE-2006-5292 EXPLOITDB text VERIFIED
Exhibit Engine 1.5 RC 4 - Remote File Inclusion via toroot Parameter
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.
by Kacper
CVE-2006-5317 EXPLOITDB text VERIFIED
eboli - Remote File Inclusion via index.php contentSpecial Parameter
PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.
by DarkFig
CVE-2006-5259 EXPLOITDB text VERIFIED
Compteur 2 - Remote File Inclusion via param_editor.php folder Parameter
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folder parameter.
by DarkFig