Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4874 EXPLOITDB text VERIFIED
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.
by HACKERS PAL
CVE-2006-4874 EXPLOITDB text VERIFIED
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.
by HACKERS PAL
CVE-2006-4874 EXPLOITDB text VERIFIED
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.
by HACKERS PAL
CVE-2006-4874 EXPLOITDB text VERIFIED
Jupiter CMS - Stored Cross-Site Scripting via Multiple Language Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.
by HACKERS PAL
EIP-2026-106160 EXPLOITDB text VERIFIED
Coppermine Photo Gallery 1.2.2b (Nuke Addon) - Remote File Inclusion
by 3l3ctric-Cracker
CVE-2006-4850 EXPLOITDB text VERIFIED
BolinOS < 4.5.5 - Remote File Inclusion via gBRootPath Parameter
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter.
by Mehmet Ince
EIP-2026-100620 EXPLOITDB text VERIFIED
Web Wiz Forums 7.01 - 'members.asp' Cross-Site Scripting
by Crack_MaN
CVE-2006-4853 EXPLOITDB text VERIFIED
Haberx 1.02-1.1 - SQL Injection via kategorix.asp id Parameter
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.
by Fix TR
EIP-2026-100298 EXPLOITDB text VERIFIED
EasyPage 7 - 'Default.aspx' SQL Injection
by s3rv3r_hack3r
CVE-2006-4845 EXPLOITDB text VERIFIED
TeamCal Pro < 2.8.001 - Remote File Inclusion via tc_config[app_root] Parameter
PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tc_config[app_root] parameter.
by PSYCH@
CVE-2006-4834 EXPLOITDB text VERIFIED
phpQuiz 0.01 - Remote File Inclusion via index.php pagename Parameter
PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.
by Solpot
EIP-2026-110624 EXPLOITDB text VERIFIED
PhotoPost Pro 4.6 - Multiple Remote File Inclusions
by Saudi Hackrz
CVE-2006-4858 EXPLOITDB text VERIFIED
mamboxchange serverstat_component < 0.4.4 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Mehmet Ince
CVE-2006-4836 EXPLOITDB text VERIFIED
DCP-Portal SE 6.0 - SQL Injection via Username Parameter
SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.php vector is already covered by CVE-2005-4227.
by HACKERS PAL
CVE-2006-4838 EXPLOITDB text VERIFIED
DCP-Portal SE 6.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php, and the root_url, (3) page_top_name, (4) page_name, and (5) page_options parameters in (b) admin/inc/header.inc.php.
by HACKERS PAL
CVE-2006-4838 EXPLOITDB text VERIFIED
DCP-Portal SE 6.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php, and the root_url, (3) page_top_name, (4) page_name, and (5) page_options parameters in (b) admin/inc/header.inc.php.
by HACKERS PAL
CVE-2006-4829 EXPLOITDB text VERIFIED
blojsom 2.31 - Cross-Site Scripting via Blog Post Parameters
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post.
by Avinash Shenoi
EIP-2026-104924 EXPLOITDB text VERIFIED
ActiveCampaign KnowledgeBuilder 2.2 - Remote File Inclusion
by igi
EIP-2026-104588 EXPLOITDB text VERIFIED
Apple Mac OSX 10.x - KExtLoad Format String
by Adriel T. Desautels
CVE-2006-4866 EXPLOITDB text VERIFIED
macOS - Local Buffer Overflow in kextload via Long Extension Argument
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
by Adriel T. Desautels
CVE-2006-3636 EXPLOITDB text VERIFIED
Mailman - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
by Moritz Naumann
CVE-2006-4857 EXPLOITDB text VERIFIED
ClickTech ClickBlog 2.0 - SQL Injection
SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters.
by ajann
CVE-2006-4826 EXPLOITDB text VERIFIED
Shadowed Portal < 5.599 - Remote Code Execution via PHP File Inclusion in bottom.php
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
by mad_hacker
CVE-2006-4885 EXPLOITDB text VERIFIED
Shadowed Portal < 5.599 - Remote File Inclusion via Root Parameter in Footer and Header
PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.
by mad_hacker
CVE-2006-4824 EXPLOITDB text VERIFIED
Quicksilver Forums < 1.2.1 - Remote File Inclusion via set[include_path] Parameter
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.
by mdx