Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107551 EXPLOITDB text VERIFIED
HAMweather 3.9.8 - 'template.php' Script Code Injection
by GulfTech Security
CVE-2006-5166 EXPLOITDB text VERIFIED
PHP Web Scripts Easy Banner Free - RCE
PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.
by abu ahmed
CVE-2006-5164 EXPLOITDB text VERIFIED
digiSHOP 4.0 - Cross-Site Scripting via cart.php sortBy or search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.
by meto5757
CVE-2006-5154 EXPLOITDB text VERIFIED
DeluxeBB <= 1.09 - Remote File Inclusion via cp/sig.php templatefolder Parameter
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.
by r0ut3r
CVE-2006-5187 EXPLOITDB text VERIFIED
Bulletin Board Ace < 3.5 - Remote Code Execution via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by SpiderZ
CVE-2006-5146 EXPLOITDB text VERIFIED
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
CVE-2006-5146 EXPLOITDB text VERIFIED
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
CVE-2006-5146 EXPLOITDB text VERIFIED
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
CVE-2006-5147 EXPLOITDB text VERIFIED
vamp_webmail < 2.0_beta1 - Remote File Inclusion via no_url Parameter
PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter.
by Drago84
CVE-2006-5181 EXPLOITDB text VERIFIED
phpMyWebmin 1.0 - Remote File Inclusion via Target Parameter
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) upload_multi.php, different vectors than CVE-2006-5124.
by Mehmet Ince
EIP-2026-110985 EXPLOITDB text VERIFIED
phpBB XS 0.58 - Multiple Remote File Inclusions
by xoron
CVE-2006-5126 EXPLOITDB text VERIFIED
PowerPortal 1.3a - Remote File Inclusion via index.php file_name[] Parameter
PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_name[] parameter.
by v1per-haCker
CVE-2006-5145 EXPLOITDB text VERIFIED
OlateDownload 3.4.0 - SQL Injection
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.
by Hessam-x
CVE-2006-5145 EXPLOITDB text VERIFIED
OlateDownload 3.4.0 - SQL Injection
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.
by Hessam-x
CVE-2006-5141 EXPLOITDB text VERIFIED
Kevin A. Gordon Open Geo Targeting - Remote File Inclusion via anp_path Parameter
PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitrary PHP code via a URL in the anp_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by RaVeR shi mozi
CVE-2006-5148 EXPLOITDB text VERIFIED
Forum82 < 2.5.2b - Remote File Inclusion via Repertorylevel Parameter
Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7) forum82lib.php3, and other unspecified scripts.
by Silahsiz Kuvvetler
CVE-2006-5124 EXPLOITDB text VERIFIED
phpMyWebmin 1.0 - Remote File Inclusion via URL Parameter Injection
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.
by Kernel-32
CVE-2005-2251 EXPLOITDB text VERIFIED
PHPSecurePages <= 0.28beta - Remote File Inclusion via cfgProgDir Parameter
PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.
by D_7J
CVE-2006-5093 EXPLOITDB text VERIFIED
Tagmin Control Center 2.1.B Build 2 - Remote Code Execution via Page Parameter
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Kernel-32
CVE-2006-5125 EXPLOITDB text VERIFIED
phpMyWebmin 1.0 - Directory Traversal via Window.php Target Parameter
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.
by Kernel-32
CVE-2006-5094 EXPLOITDB text VERIFIED
phpBB XS 2 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893.
by Mehmet Ince
EIP-2026-109103 EXPLOITDB text VERIFIED
Les Visiteurs 2.0 - Multiple Remote File Inclusions
by D_7J
EIP-2026-109102 EXPLOITDB text VERIFIED
Les Visiteurs (Visitors) 2.0 - 'config.inc.php' File Inclusion
by D_7J
CVE-2006-5114 EXPLOITDB text VERIFIED
SAP Internet Transaction Server 6.1-6.2 - Cross-Site Scripting via ~urlmime or ~command Parameter
Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003-0749.
by ILION Research
EIP-2026-113229 EXPLOITDB text VERIFIED
Web//News 1.4 - 'parser.php' Remote File Inclusion (2)
by ThE-WoLf-KsA