Exploitdb Exploits
31,394 exploits tracked across all sources.
phpBB XS < 0.58 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by AzzCoder
p4CMS 1.05 - Remote File Inclusion via abf_js.php abs_pfad Parameter
PHP remote file inclusion vulnerability in abf_js.php in p4CMS 1.05 allows remote attackers to execute arbitrary PHP code via a URL in the abs_pfad parameter.
by SHiKaA
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
IDevSpot iSupport 1.8 - Cross-Site Scripting via suser, ticket_id, or cons_page_title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by s3rv3r_hack3r
IDevSpot iSupport 1.8 - 'index.php' Remote File Inclusion
by s3rv3r_hack3r
Apple QuickTime < 7.1.3 - Remote Code Execution via FLIC COLOR_64 Chunk
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
by Sowhat
SQL-Ledger <2.6.19 & LedgerSMB <1.0.0p1 - Path Traversal
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).
by Chris Murtagh
Laurentiu Matei XHP CMS 0.5.1 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.
by HACKERS PAL
Thomas LETE WTools <0.0.1-ALPH - RCE
PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
by ddoshomo
PHProg 1.0 - Multiple Input Validation Vulnerabilities
by cdg393
PHProg < 1.1 - Directory Traversal via Lang Parameter
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
by cdg393
PHProg < 1.1 - Cross-Site Scripting via Album Parameter
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
by cdg393
IDevSpot PhpLinkExchange 1.0 - Cross-Site Scripting via User Add Msg Parameter
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by s3rv3r_hack3r
openi-cms 1.0.1 - Remote File Inclusion via config[openi_dir] Parameter
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
by basher13
PSYWERKS PUMA 1.0 RC2 - Remote File Inclusion via config.php fpath Parameter
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
by Philipp Niedziela
OpenBB < 1.0.8 - Remote File Inclusion via root_path Parameter
PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) index.php and possibly (2) collector.php.
by Eddy_BAck0o
mcgallery_pro 2006 - Remote File Inclusion via random2.php path_to_folder Parameter
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
by Solpot
SpoonLabs Vivvo Article Management CMS <3.2 - SQL Injection
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by MercilessTurk
SpoonLabs Vivvo Article Management CMS <3.2 - RCE
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter.
by MercilessTurk
IdevSpot TextAds - Cross-Site Scripting via id Parameter in delete.php and error Parameter in error.php
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.
by s3rv3r_hack3r
IdevSpot TextAds - Cross-Site Scripting via id Parameter in delete.php and error Parameter in error.php
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.
by s3rv3r_hack3r
Somery < 0.4.6 - Remote File Inclusion via skindir Parameter
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.
by basher13
Sage 1.3.x - IMG Element Input Validation
by Kevin Kierznowski
Vikingboard 0.1b - Cross-Site Scripting via act and p Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.
by Hessam-x
By Source