Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4780 EXPLOITDB text VERIFIED
phpBB XS < 0.58 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by AzzCoder
CVE-2006-4769 EXPLOITDB text VERIFIED
p4CMS 1.05 - Remote File Inclusion via abf_js.php abs_pfad Parameter
PHP remote file inclusion vulnerability in abf_js.php in p4CMS 1.05 allows remote attackers to execute arbitrary PHP code via a URL in the abs_pfad parameter.
by SHiKaA
CVE-2006-4884 EXPLOITDB text VERIFIED
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
CVE-2006-4884 EXPLOITDB text VERIFIED
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
CVE-2006-4884 EXPLOITDB text VERIFIED
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
EIP-2026-107758 EXPLOITDB text VERIFIED
IDevSpot iSupport 1.8 - 'index.php' Remote File Inclusion
by s3rv3r_hack3r
CVE-2006-4384 EXPLOITDB text VERIFIED
Apple QuickTime < 7.1.3 - Remote Code Execution via FLIC COLOR_64 Chunk
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
by Sowhat
CVE-2006-4731 EXPLOITDB text VERIFIED
SQL-Ledger <2.6.19 & LedgerSMB <1.0.0p1 - Path Traversal
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).
by Chris Murtagh
CVE-2006-4751 EXPLOITDB text VERIFIED
Laurentiu Matei XHP CMS 0.5.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.
by HACKERS PAL
CVE-2006-4764 EXPLOITDB text VERIFIED
Thomas LETE WTools <0.0.1-ALPH - RCE
PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
by ddoshomo
EIP-2026-111188 EXPLOITDB text VERIFIED
PHProg 1.0 - Multiple Input Validation Vulnerabilities
by cdg393
CVE-2006-4753 EXPLOITDB text VERIFIED
PHProg < 1.1 - Directory Traversal via Lang Parameter
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
by cdg393
CVE-2006-4754 EXPLOITDB text VERIFIED
PHProg < 1.1 - Cross-Site Scripting via Album Parameter
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
by cdg393
CVE-2006-4742 EXPLOITDB text VERIFIED
IDevSpot PhpLinkExchange 1.0 - Cross-Site Scripting via User Add Msg Parameter
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by s3rv3r_hack3r
CVE-2006-4750 EXPLOITDB text VERIFIED
openi-cms 1.0.1 - Remote File Inclusion via config[openi_dir] Parameter
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
by basher13
CVE-2006-4713 EXPLOITDB text VERIFIED
PSYWERKS PUMA 1.0 RC2 - Remote File Inclusion via config.php fpath Parameter
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
by Philipp Niedziela
CVE-2006-4722 EXPLOITDB text VERIFIED
OpenBB < 1.0.8 - Remote File Inclusion via root_path Parameter
PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) index.php and possibly (2) collector.php.
by Eddy_BAck0o
CVE-2006-4720 EXPLOITDB text VERIFIED
mcgallery_pro 2006 - Remote File Inclusion via random2.php path_to_folder Parameter
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
by Solpot
CVE-2006-4715 EXPLOITDB text VERIFIED
SpoonLabs Vivvo Article Management CMS <3.2 - SQL Injection
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by MercilessTurk
CVE-2006-4714 EXPLOITDB text VERIFIED
SpoonLabs Vivvo Article Management CMS <3.2 - RCE
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter.
by MercilessTurk
CVE-2006-4747 EXPLOITDB text VERIFIED
IdevSpot TextAds - Cross-Site Scripting via id Parameter in delete.php and error Parameter in error.php
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.
by s3rv3r_hack3r
CVE-2006-4747 EXPLOITDB text VERIFIED
IdevSpot TextAds - Cross-Site Scripting via id Parameter in delete.php and error Parameter in error.php
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.
by s3rv3r_hack3r
CVE-2006-4669 EXPLOITDB text VERIFIED
Somery < 0.4.6 - Remote File Inclusion via skindir Parameter
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.
by basher13
EIP-2026-119097 EXPLOITDB text VERIFIED
Sage 1.3.x - IMG Element Input Validation
by Kevin Kierznowski
CVE-2006-4708 EXPLOITDB text VERIFIED
Vikingboard 0.1b - Cross-Site Scripting via act and p Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.
by Hessam-x