Exploitdb Exploits
31,394 exploits tracked across all sources.
HAMweather 3.9.8 - 'template.php' Script Code Injection
by GulfTech Security
PHP Web Scripts Easy Banner Free - RCE
PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.
by abu ahmed
digiSHOP 4.0 - Cross-Site Scripting via cart.php sortBy or search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.
by meto5757
DeluxeBB <= 1.09 - Remote File Inclusion via cp/sig.php templatefolder Parameter
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.
by r0ut3r
Bulletin Board Ace < 3.5 - Remote Code Execution via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by SpiderZ
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
Yblog - Stored Cross-Site Scripting via id Parameter in funk.php
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
by You_You
vamp_webmail < 2.0_beta1 - Remote File Inclusion via no_url Parameter
PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter.
by Drago84
phpMyWebmin 1.0 - Remote File Inclusion via Target Parameter
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) upload_multi.php, different vectors than CVE-2006-5124.
by Mehmet Ince
PowerPortal 1.3a - Remote File Inclusion via index.php file_name[] Parameter
PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_name[] parameter.
by v1per-haCker
OlateDownload 3.4.0 - SQL Injection
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.
by Hessam-x
OlateDownload 3.4.0 - SQL Injection
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.
by Hessam-x
Kevin A. Gordon Open Geo Targeting - Remote File Inclusion via anp_path Parameter
PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitrary PHP code via a URL in the anp_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by RaVeR shi mozi
Forum82 < 2.5.2b - Remote File Inclusion via Repertorylevel Parameter
Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7) forum82lib.php3, and other unspecified scripts.
by Silahsiz Kuvvetler
phpMyWebmin 1.0 - Remote File Inclusion via URL Parameter Injection
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.
by Kernel-32
PHPSecurePages <= 0.28beta - Remote File Inclusion via cfgProgDir Parameter
PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.
by D_7J
Tagmin Control Center 2.1.B Build 2 - Remote Code Execution via Page Parameter
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Kernel-32
phpMyWebmin 1.0 - Directory Traversal via Window.php Target Parameter
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.
by Kernel-32
phpBB XS 2 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893.
by Mehmet Ince
Les Visiteurs (Visitors) 2.0 - 'config.inc.php' File Inclusion
by D_7J
SAP Internet Transaction Server 6.1-6.2 - Cross-Site Scripting via ~urlmime or ~command Parameter
Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003-0749.
by ILION Research
Web//News 1.4 - 'parser.php' Remote File Inclusion (2)
by ThE-WoLf-KsA
By Source