Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-5076 EXPLOITDB text VERIFIED
OpenConcept Back-End 0.4.5 - Remote File Inclusion via includes_path Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.
by Root3r_H3ll
CVE-2006-5058 EXPLOITDB text VERIFIED
Call of Duty <1.5b - Buffer Overflow
Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command.
by Luigi Auriemma
CVE-2006-5065 EXPLOITDB text VERIFIED
zoomstats < 1.0.2 - Remote File Inclusion via GLOBALS[lib][db][path] Parameter
PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.
by Drago84
CVE-2006-5053 EXPLOITDB text VERIFIED
Web-News < 1.6.3 - Remote File Inclusion via content_page Parameter
PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content_page parameter.
by Drago84
EIP-2026-112732 EXPLOITDB text VERIFIED
ToendaCMS 1.0.4 - 'Media.php' Directory Traversal
by MoHaJaLi
CVE-2006-5055 EXPLOITDB text VERIFIED
syntaxCMS 1.1.1-1.3 - Remote Code Execution via init_path Parameter
PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter.
by MoHaJaLi
CVE-2006-5061 EXPLOITDB text VERIFIED
Advanced-Clan-Script < 3.4 - Remote File Inclusion via mcf.php content Parameter
PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
by xdh
CVE-2006-5060 EXPLOITDB text VERIFIED
Jamroom 3.0.16 - Cross-Site Scripting via Forgot Parameter in Login Page
Cross-site scripting (XSS) vulnerability in login.php in Jamroom 3.0.16 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the forgot parameter in the forgot mode.
by meto5757
CVE-2006-5054 EXPLOITDB text VERIFIED
iyzi_forum < 1_beta_2 - SQL Injection via uye_nu Parameter
SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.
by Fix TR
EIP-2026-109776 EXPLOITDB text VERIFIED
MyPhotos 0.1.3b - 'index.php' Remote File Inclusion
by Root3r_H3ll
CVE-2006-5120 EXPLOITDB text VERIFIED
Red Mombin 0.7 - Cross-Site Scripting in index.php and process_login.php
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.
by Armorize Technologies
CVE-2006-5120 EXPLOITDB text VERIFIED
Red Mombin 0.7 - Cross-Site Scripting in index.php and process_login.php
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.
by Armorize Technologies
CVE-2006-5028 EXPLOITDB text VERIFIED
SWsoft Plesk 7.5 Reload and 7.6 - Directory Traversal via File Parameter
Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.
by GuanYu
EIP-2026-109792 EXPLOITDB text VERIFIED
mysource 2.14.8/2.16 - Multiple Vulnerabilities
by Patrick Webster
CVE-2006-5019 EXPLOITDB text VERIFIED
Google Mini <4.4.102.M.36 - Info Disclosure
Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.
by Patrick Webster
CVE-2006-5031 EXPLOITDB text VERIFIED
CakePHP <1.1.8.3544 - Path Traversal
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.
by GulfTech Security
CVE-2006-5023 EXPLOITDB text VERIFIED
xweblog < 2.1 - SQL Injection via kategori Parameter
SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kategori parameter.
by Muhacir
CVE-2006-4899 EXPLOITDB text VERIFIED
CA eTrust Security Command Center <SP1 CR2 - Info Disclosure
The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.
by Patrick Webster
CVE-2006-4901 EXPLOITDB text VERIFIED
Computer Associates (CA) eTrust Security Command Center <r8-SP1 CR2...
Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend.exe with the desired arguments.
by Patrick Webster
CVE-2006-4900 EXPLOITDB text VERIFIED
CA eTrust Security Command Center < SP1 CR2 - Path Traversal
Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.
by Patrick Webster
CVE-2006-4989 EXPLOITDB text VERIFIED
Patrick Michaelis Wili-CMS - Information Disclosure via Direct Request
Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in example-view/admin_templates/, which reveals the path in various error messages.
by HACKERS PAL
CVE-2006-5020 EXPLOITDB text VERIFIED
SolidState < 0.4 - Remote File Inclusion via base_path Parameter
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) DomainsPage.class.php, (25) EditAccountPage.class.php, (26) EditDomainPage.class.php, (27) EditDomainServicePage.class.php, (28) EditHostingServicePage.class.php, (29) EditPaymentPage.class.php, (30) EditProductPage.class.php, (31) EditServerPage.class.php, (32) EmailInvoicePage.class.php, (33) ExecuteOrderPage.class.php, (34) ExpiredDomainsPage.class.php, (35) FulfilledOrdersPage.class.php, (36) GenerateInvoicesPage.class.php, (37) HomePage.class.php, (38) InactiveAccountsPage.class.php, (39) IPManagerPage.class.php, (40) LoginPage.class.php, (41) LogPage.class.php, (42) ModulesPage.class.php, (43) NewAccountPage.class.php, (44) NewDomainServicePage.class.php, (45) NewProductPage.class.php, (46) OutstandingInvoicesPage.class.php, (47) PendingAccountsPage.class.php, (48) PendingOrdersPage.class.php, (49) PrintInvoicePage.class.php, (50) ProductsPage.class.php, (51) RegisterDomainPage.class.php, (52) RegisteredDomainsPage.class.php, (53) ServersPage.class.php, (54) ServicesHostingServicesPage.class.php, (55) ServicesNewHostingPage.class.php, (56) ServicesPage.class.php, (57) ServicesWebHostingPage.class.php, (58) SettingsPage.class.php, (59) TaxesPage.class.php, (60) TransferDomainPage.class.php, (61) ViewAccountPage.class.php, (62) ViewDomainServicePage.class.php, (63) ViewHostingServicePage.class.php, (64) ViewInvoicePage.class.php, (65) ViewLogMessagePage.class.php, (66) ViewOrderPage.class.php, (67) ViewProductPage.class.php, (68) ViewServerPage.class.php, (69) WelcomeEmailPage.class.php; and (70) modules/RegistrarModule.class.php, (71) modules/SolidStateModule.class.php, (72) modules/authorizeaim/authorizeaim.class.php, and (73) modules/authorizeaim/pages/AAIMConfigPage.class.php.
by Kacper
CVE-2006-5022 EXPLOITDB text VERIFIED
Joshua Wilson pNews System 1.1.0 - RCE
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.
by CvIr.System
CVE-2006-4966 EXPLOITDB text VERIFIED
chumpsoft phpQuestionnaire <3.12 - RCE
PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] parameter.
by Solpot
CVE-2006-5032 EXPLOITDB text VERIFIED
PHPartenaire 1.0 - Remote File Inclusion via dix.php3 url_phpartenaire Parameter
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.
by DaDIsS