Exploitdb Exploits
31,394 exploits tracked across all sources.
ExtCalThai Module < 0.9.1 - Remote File Inclusion via CONFIG_EXT or mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.
by k1tk4t
Alex Downloadengine - Code Injection
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition, so this issue is probably a duplicate of CVE-2006-4656.
by v1per-haCker
AFGB GUESTBOOK 2.2 - Remote File Inclusion via Htmls Parameter
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php.
by mdx
4Images 1.7 - 'details.php' Cross-Site Scripting
by Christian Marthen
sh-news < 3.1 - Remote File Inclusion via scriptpath Parameter
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php.
by v1per-haCker
n@board < 3.1.9e - Remote File Inclusion via Skin Parameter
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skin parameter.
by mdx
Minichat 6.0 - Remote File Inclusion via ftag.php mostrar Parameter
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.
by Zickox
Gcards 1.13 - 'Addnews.php' Remote File Inclusion
by DeatH VirUs
Dokeos 1.6.4 - Multiple Remote File Inclusions Vulnerabilities
by viper-haCker
registroTL main.php - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter.
by DarkFig
vtiger CRM <= 4.2 - Remote File Inclusion via calpath Parameter
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or (3) modules/Calendar/calendar.php.
by the_day
TribunaLibre 3.12 Beta - Remote File Inclusion via mostrar Parameter
PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.
by DarkFig
TagIt! Tagboard 2.1.B Build 2 - Remote Code Execution via configpath Parameter
PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitrary PHP code via a URL in the configpath parameter.
by k1tk4t
Softerra PHP Developer Library 1.5.3 - 'Grid3.lib.php' Remote File Inclusion
by k1tk4t
registroTL - Unauthenticated Sensitive Information Exposure via Direct Database Download
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat.
by DarkFig
Softerra PHP Developer Library < 1.5.3 - Remote File Inclusion via cfg_dir or lib_dir Parameters
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) cfg_dir and (2) lib_dir parameters.
by k1tk4t
MySQLDumper 1.21 - 'sql.php' Cross-Site Scripting
by Crackers_Child
Jinzora < 2.1 - Remote Code Execution via Include Path Parameter
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770.
by k1tk4t
Nayco JASmine - Remote File Inclusion via Section Parameter
PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter.
by DarkFig
Hastymail < 1.5 - Authenticated IMAP Command Injection via CRLF in Mailbox Name
CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.
by Vicente Aguilera Diaz
Foafgen 0.3 - Directory Traversal via foaf Parameter
Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.
by DarkFig
Exhibit Engine 1.5 RC 4 - Remote File Inclusion via toroot Parameter
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.
by Kacper
eboli - Remote File Inclusion via index.php contentSpecial Parameter
PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.
by DarkFig
Compteur 2 - Remote File Inclusion via param_editor.php folder Parameter
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folder parameter.
by DarkFig
By Source