Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-5256 EXPLOITDB text VERIFIED
Claroline < 1.8.0 - Remote File Inclusion via includePath Parameter
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.
by k1tk4t
CVE-2006-5250 EXPLOITDB text VERIFIED
blueshoes_framework < 4.6_public - Remote File Inclusion via APP[path][lib] Parameter
PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APP[path][lib] parameter, a different vector than CVE-2006-2864.
by k1tk4t
CVE-2006-5320 EXPLOITDB text VERIFIED
Album Photo Sans Nom 1.6 - Directory Traversal via getimg.php img Parameter
Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter.
by DarkFig
EIP-2026-105067 EXPLOITDB text VERIFIED
Album Photo Sans Nom 1.6 - 'Getimg.php' Remote File Inclusion
by DarkFig
EIP-2026-105000 EXPLOITDB text VERIFIED
ae2 - 'standart.inc.php' Remote File Inclusion
by k1tk4t
CVE-2006-5220 EXPLOITDB text VERIFIED
WebYep 1.1.9 - Remote Code Execution via webyep_sIncludePath Parameter
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a) WYApplication.php, (b) WYDocument.php, (c) WYEditor.php, (d) WYElement.php, (e) WYFile.php, (f) WYHTMLTag.php, (g) WYImage.php, (h) WYLanguage.php, (i) WYLink.php, (j) WYPath.php, (k) WYPopupWindowLink.php, (l) WYSelectMenu.php, and (m) WYTextArea.php; (2) files in the programm/elements/ directory including (n) WYGalleryElement.php, (o) WYGuestbookElement.php, (p) WYImageElement.php, (q) WYLogonButtonElement.php, (r) WYLongTextElement.php, (s) WYLoopElement.php, (t) WYMenuElement.php, and (u) WYShortTextElement.php; and (3) programm/webyep.php.
by the_day
CVE-2006-5234 EXPLOITDB text VERIFIED
phpWebSite 0.10.2 - Remote File Inclusion via PHPWS_SOURCE_DIR Parameter
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable
by Crackers_Child
CVE-2006-5241 EXPLOITDB text VERIFIED
OpenDock Easy Gallery < 1.4 - Remote File Inclusion via doc_directory Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) file.php; (2) find_user.php, (3) lib_user.php, (4) lib_form_user.php, and (5) user.php in sw/lib_user/; (6) find_session.php and (7) session.php in sw/lib_session/; (8) comment.php and (9) lib_comment.php in sw/lib_comment/; and other unspecified PHP scripts.
by the_day
CVE-2006-5244 EXPLOITDB text VERIFIED
OpenDock Easy Blog < 1.4 - Remote File Inclusion via doc_directory Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_read_file.php, and (5) lib_form_file.php in sw/lib_up_file; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified vectors.
by the_day
CVE-2006-5244 EXPLOITDB text VERIFIED
OpenDock Easy Blog < 1.4 - Remote File Inclusion via doc_directory Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_read_file.php, and (5) lib_form_file.php in sw/lib_up_file; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified vectors.
by the_day
CVE-2006-5232 EXPLOITDB text VERIFIED
iSearch 2.16 - Remote File Inclusion via isearch_path Parameter
Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5) google_sitemap.php, (6) stats.php, or (7) auto_spider_img.php. NOTE: this issue has been disputed by a third party who shows that $isearch_path is set to a constant value. CVE analysis as of 20061010 is inconclusive, although the original researcher is known to make mistakes
by MoHaNdKo
CVE-2006-5239 EXPLOITDB text VERIFIED
expblog < 0.3.5 - Cross-Site Scripting via PHP_SELF or captcha_session_code Parameter
Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the captcha_session_code parameter in pre_details.php.
by Tamriel
CVE-2006-5251 EXPLOITDB text VERIFIED
Deep CMS 2.0a - Remote File Inclusion via ConfigDir Parameter
PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP code via a URL in the ConfigDir parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Crackers_Child
CVE-2006-5261 EXPLOITDB text VERIFIED
phpmynews < 1.4 - Remote File Inclusion via cfg_include_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) index.php3 in include/.
by Mehmet Ince
CVE-2006-5219 EXPLOITDB text VERIFIED
Moodle 1.6.2 - SQL Injection via Double-Encoded Tag Parameter
SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.
by disfigure
CVE-2006-5226 EXPLOITDB text VERIFIED
Freenews 1.1 - Remote File Inclusion via moteur.php chemin Parameter
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
by Mehmet Ince
EIP-2026-110982 EXPLOITDB text VERIFIED
phpBB Random User Registration Number 1.0 Mod - Remote File Inclusion
by bd0rk
CVE-2006-5230 EXPLOITDB text VERIFIED
freeforum < 0.9.7 - Remote File Inclusion via fpath Parameter
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
by Mehmet Ince
CVE-2006-5223 EXPLOITDB text VERIFIED
Nivisec User Viewed Posts Tracker <= 1.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2006-5228 EXPLOITDB text VERIFIED
ackerTodo <= 4.2 - SQL Injection via Google Gadget Login Parameters
Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters.
by Francesco Laurita
CVE-2006-5193 EXPLOITDB text VERIFIED
wikyblog <= 1.2.3 - Remote File Inclusion via includeDir Parameter
PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter.
by MoHaNdKo
CVE-2006-5207 EXPLOITDB text VERIFIED
phpMyTeam 2.0 - Remote File Inclusion via smileys_dir Parameter
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter.
by Mehmet Ince
CVE-2006-5224 EXPLOITDB text VERIFIED
Dimitri Seitz Security Suite IP Logger 1.0.0 - RCE
PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by SpiderZ
CVE-2006-5208 EXPLOITDB text VERIFIED
PHP Classifieds 7.1 - SQL Injection
Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.
by Kzar
CVE-2006-5222 EXPLOITDB text VERIFIED
Dimension of phpBB <= 0.2.6 - Remote File Inclusion via phpbb_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engine.php.
by SpiderZ