Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4849 EXPLOITDB text VERIFIED
MobilePublisherPHP < 1.5_rc2 - Remote File Inclusion via abspath Parameter
PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
by Timq
CVE-2006-4897 EXPLOITDB text VERIFIED
CMtextS <= 1.0 - Unauthenticated Administrator Password Exposure via Insecure Web Root File
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.
by Kacper
CVE-2006-4892 EXPLOITDB text VERIFIED
Techno Dreams FAQ Manager Package 1.0 - SQL Injection
SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
CVE-2006-4891 EXPLOITDB text VERIFIED
Techno Dreams Articles & Papers Package <2.0 - SQL Injection
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
CVE-2006-4852 EXPLOITDB text VERIFIED
QuadComm Q-Shop <3.5 - SQL Injection
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter.
by ajann
CVE-2006-4973 EXPLOITDB text VERIFIED
DotNetNuke < 3.3.5 and 4.x < 4.3.5 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
by Secure Shapes
CVE-2006-4882 EXPLOITDB text VERIFIED
Julian Roberts Charon Cart 3 - SQL Injection
SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.
by ajann
CVE-2006-4890 EXPLOITDB text VERIFIED
UNAK-CMS <= 1.5 - Remote File Inclusion via dirroot Parameter
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) fckeditor/editor/dialog/fck_link.php.
by SHiKaA
CVE-2006-4881 EXPLOITDB text VERIFIED
David Bennett PHP-Post <= 1.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.php; the (3) txt_error and (4) txt_templatenotexist parameters in (c) template.php; the (5) split parameter in certain files, as demonstrated by (d) editprofile.php, (e) search.php, (f) index.php, and (g) pm.php; and the (6) txt_login parameter in (h) loginline.php; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) txt_logout parameter in (i) loginline.php.
by HACKERS PAL
CVE-2006-5254 EXPLOITDB text VERIFIED
Mark Van Bellen Detailed User Registration <4.1 - RCE
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by k1tk4t
CVE-2006-4848 EXPLOITDB text VERIFIED
Hitweb 3.0 - Remote File Inclusion via REP_CLASS Parameter
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php. NOTE: this issue has been disputed by a third party researcher, stating that REP_CLASS is initialized in an included file before being used
by ERNE
CVE-2006-4898 EXPLOITDB text VERIFIED
guanxiCRM <= 0.9.1 - Remote File Inclusion via appconf[rootpath] Parameter
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.
by SHiKaA
EIP-2026-105253 EXPLOITDB text VERIFIED
Artmedic Links 5.0 - 'index.php' Remote File Inclusion
by botan
CVE-2006-4870 EXPLOITDB text VERIFIED
AEDating < 4.1 - Remote File Inclusion via dir[inc] Parameter
Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.
by NeXtMaN
EIP-2026-103085 EXPLOITDB text VERIFIED
BusyBox 1.01 - HTTPd Directory Traversal
by bug-finder
EIP-2026-100639 EXPLOITDB text VERIFIED
ZilekPortal 1.0 - 'Haberdetay.asp' SQL Injection
by chernobiLe
CVE-2006-4855 EXPLOITDB text VERIFIED
Symantec Client Security - Denial of Service via Invalid Data to \Device\SymEvent Driver
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.
by David Matousek
CVE-2006-6943 EXPLOITDB text VERIFIED
phpMyAdmin < 2.9.1 - Path Disclosure via Multiple Scripts and Parameters
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.
by laurent gaffie
CVE-2006-6942 EXPLOITDB text VERIFIED
phpMyAdmin < 2.9.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
by laurent gaffie
CVE-2006-6942 EXPLOITDB text VERIFIED
phpMyAdmin < 2.9.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
by laurent gaffie
CVE-2006-6942 EXPLOITDB text VERIFIED
phpMyAdmin < 2.9.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
by laurent gaffie
CVE-2006-6942 EXPLOITDB text VERIFIED
phpMyAdmin < 2.9.1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.
by laurent gaffie
CVE-2006-4828 EXPLOITDB text VERIFIED
PhotoPost PHP Pro 4.0-4.6 - Remote File Inclusion via PP_PATH Parameter
PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.
by Saudi Hackrz
CVE-2006-4876 EXPLOITDB text VERIFIED
Jupiter CMS - SQL Injection via Login Username or Registration Parameters
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.
by HACKERS PAL
CVE-2006-4875 EXPLOITDB text VERIFIED
Jupiter CMS - Unrestricted File Upload in Gallery Upload Module
Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extensions, to gallery/albums/public.
by HACKERS PAL