Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0872 EXPLOITDB text VERIFIED
Plain Old Webserver - Directory Traversal via URI
Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by Stefano Di Paola
EIP-2026-114395 EXPLOITDB text VERIFIED
WWWThreads 5.4 - 'Cat' Multiple Cross-Site Scripting Vulnerabilities
by Root3r_H3ll
EIP-2026-111643 EXPLOITDB text VERIFIED
Quickblogger 1.4 - Remote File Inclusion
by You_You
CVE-2006-5078 EXPLOITDB text VERIFIED
Kristian Niemi Polaring <0.04.03 - RCE
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.
by Drago84
EIP-2026-111259 EXPLOITDB text VERIFIED
PHP_news 2.0 - 'user_user.php?language' Remote File Inclusion
by Root3r_H3ll
EIP-2026-111258 EXPLOITDB text VERIFIED
PHP_news 2.0 - 'creat_news_all.php?language' Remote File Inclusion
by Root3r_H3ll
EIP-2026-111257 EXPLOITDB text VERIFIED
PHP_news 2.0 - '/admin/news.php?language' Remote File Inclusion
by Root3r_H3ll
EIP-2026-111256 EXPLOITDB text VERIFIED
PHP_news 2.0 - '/admin/catagory.php?language' Remote File Inclusion
by Root3r_H3ll
CVE-2006-5057 EXPLOITDB text VERIFIED
ktools.net PhotoStore - Cross-Site Scripting via gid or photogid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.
by meto5757
CVE-2006-5057 EXPLOITDB text VERIFIED
ktools.net PhotoStore - Cross-Site Scripting via gid or photogid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.
by meto5757
CVE-2006-5062 EXPLOITDB text VERIFIED
PBLang < 4.66z - Remote File Inclusion via temppath Parameter
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.
by SHiKaA
CVE-2006-5056 EXPLOITDB text VERIFIED
Opial Audio/Video Download Mgmt 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web script or HTML via the destination parameter in the Login view.
by meto5757
CVE-2006-5089 EXPLOITDB text VERIFIED
Jim Plush My-BIC 0.6.5 - Remote File Inclusion via mybic_server.php file Parameter
PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. CVE disputes this vulnerability because the file variable is defined before use in a way that prevents arbitrary inclusion
by Root3r_H3ll
CVE-2006-5077 EXPLOITDB text VERIFIED
Minerva Build 238 and earlier - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by SHiKaA
CVE-2006-5070 EXPLOITDB text VERIFIED
faceStones Personal <= 2.0.42 - Remote File Inclusion via GLOBALS[fsinit][objpath] Parameter
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.
by SHiKaA
CVE-2006-5920 EXPLOITDB text VERIFIED
Yuuki Yoshizawa Exporia 0.3.0 - RCE
PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap CVE-2006-5113
by Root3r_H3ll
CVE-2006-5087 EXPLOITDB text VERIFIED
evoBB < 0.3 - Remote File Inclusion via Path Parameter
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) track.php or (2) connect.php.
by SHiKaA
CVE-2006-5066 EXPLOITDB text VERIFIED
DanPHPSupport < 1.0 - Cross-Site Scripting via Page or Do Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.
by You_You
CVE-2006-5066 EXPLOITDB text VERIFIED
DanPHPSupport < 1.0 - Cross-Site Scripting via Page or Do Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.
by You_You
CVE-2006-5068 EXPLOITDB text VERIFIED
Brudaswen/BrudaNews <1.1-BrudaGB <1.1 - RCE
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
by SHiKaA
CVE-2006-5068 EXPLOITDB text VERIFIED
Brudaswen/BrudaNews <1.1-BrudaGB <1.1 - RCE
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.
by SHiKaA
CVE-2006-5064 EXPLOITDB text VERIFIED
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
CVE-2006-5064 EXPLOITDB text VERIFIED
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
CVE-2006-5064 EXPLOITDB text VERIFIED
birdblog 1.4 - Cross-Site Scripting via entryid, page, or uid Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
CVE-2006-5076 EXPLOITDB text VERIFIED
OpenConcept Back-End 0.4.5 - Remote File Inclusion via includes_path Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.
by Root3r_H3ll