Exploitdb Exploits
31,394 exploits tracked across all sources.
Plain Old Webserver - Directory Traversal via URI
Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by Stefano Di Paola
WWWThreads 5.4 - 'Cat' Multiple Cross-Site Scripting Vulnerabilities
by Root3r_H3ll
Kristian Niemi Polaring <0.04.03 - RCE
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.
by Drago84
PHP_news 2.0 - 'user_user.php?language' Remote File Inclusion
by Root3r_H3ll
PHP_news 2.0 - 'creat_news_all.php?language' Remote File Inclusion
by Root3r_H3ll
PHP_news 2.0 - '/admin/news.php?language' Remote File Inclusion
by Root3r_H3ll
PHP_news 2.0 - '/admin/catagory.php?language' Remote File Inclusion
by Root3r_H3ll
ktools.net PhotoStore - Cross-Site Scripting via gid or photogid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.
by meto5757
ktools.net PhotoStore - Cross-Site Scripting via gid or photogid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.
by meto5757
PBLang < 4.66z - Remote File Inclusion via temppath Parameter
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.
by SHiKaA
Opial Audio/Video Download Mgmt 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web script or HTML via the destination parameter in the Login view.
by meto5757
Jim Plush My-BIC 0.6.5 - Remote File Inclusion via mybic_server.php file Parameter
PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. CVE disputes this vulnerability because the file variable is defined before use in a way that prevents arbitrary inclusion
by Root3r_H3ll
Minerva Build 238 and earlier - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by SHiKaA
faceStones Personal <= 2.0.42 - Remote File Inclusion via GLOBALS[fsinit][objpath] Parameter
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.
by SHiKaA
Yuuki Yoshizawa Exporia 0.3.0 - RCE
PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap CVE-2006-5113
by Root3r_H3ll
evoBB < 0.3 - Remote File Inclusion via Path Parameter
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) track.php or (2) connect.php.
by SHiKaA
DanPHPSupport < 1.0 - Cross-Site Scripting via Page or Do Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.
by You_You
DanPHPSupport < 1.0 - Cross-Site Scripting via Page or Do Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.
by You_You
Brudaswen/BrudaNews <1.1-BrudaGB <1.1 - RCE
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
by SHiKaA
Brudaswen/BrudaNews <1.1-BrudaGB <1.1 - RCE
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
by SHiKaA
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
OpenConcept Back-End 0.4.5 - Remote File Inclusion via includes_path Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.
by Root3r_H3ll
By Source