Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4708 EXPLOITDB text VERIFIED
Vikingboard 0.1b - Cross-Site Scripting via act and p Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.
by Hessam-x
CVE-2006-4709 EXPLOITDB text VERIFIED
Vikingboard 0.1b - SQL Injection via Topic s Parameter
SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands via the s parameter.
by Hessam-x
CVE-2007-0704 EXPLOITDB text VERIFIED
Somery 0.4.6 - Remote File Inclusion via install.php skindir Parameter
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669. NOTE: the documentation says to remove install.php after installation.
by basher13
CVE-2006-4719 EXPLOITDB text VERIFIED
MyABraCaDaWeb 1.0.3 - Remote File Inclusion via Base Parameter
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) index.php or (2) pop.php.
by ddoshomo
CVE-2002-2217 EXPLOITDB text VERIFIED
Web Server Creator - Web Portal 0.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php.
by Mehmet Ince
CVE-2006-4656 EXPLOITDB text VERIFIED
Web Provence SL_Site < 1.0 - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.
by Kw3[R]Ln
CVE-2006-4681 EXPLOITDB text VERIFIED
IBM Director <5.10 - Path Traversal
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.
by Daniel Clemens
CVE-2006-4666 EXPLOITDB text VERIFIED
Stefan Ernst Newsscript 0.5 beta - RCE
Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.
by ddoshomo
CVE-2006-4746 EXPLOITDB text VERIFIED
Web Server Creator 0.1 - Remote File Inclusion via News Customize l Parameter
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
by Mehmet Ince
CVE-2006-4294 EXPLOITDB text VERIFIED
TWiki 4.0.0-4.0.4 - Directory Traversal via Filename Parameter
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
by Peter Thoeny
CVE-2006-5291 EXPLOITDB text VERIFIED
Alex Downloadengine - Code Injection
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition, so this issue is probably a duplicate of CVE-2006-4656.
by Kw3[R]Ln
CVE-2006-7081 EXPLOITDB text VERIFIED
PhpNews 1.0 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.
by the master
CVE-2006-4666 EXPLOITDB text VERIFIED
Stefan Ernst Newsscript 0.5 beta - RCE
Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.
by osm
CVE-2006-4670 EXPLOITDB text VERIFIED
PhotoKorn Gallery < 1.52 - Remote File Inclusion via dir_path Parameter
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php.
by Saudi Hackrz
CVE-2006-4672 EXPLOITDB text VERIFIED
ppalCart 2.5 EE - Remote Code Execution via proMod or docroot Parameter
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrary PHP code via a URL in the (1) proMod parameter to (a) index.php, or the (2) docroot parameter to (b) index.php or (c) mainpage.php.
by momo26
CVE-2006-4678 EXPLOITDB text VERIFIED
News Evolution 3.0.3 - Remote File Inclusion via _NE[AbsPath] Parameter
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php.
by ddoshomo
CVE-2006-4716 EXPLOITDB text VERIFIED
Fire Soft Board < rc3 - Remote File Inclusion via racine Parameter
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.
by ddoshomo
CVE-2006-4668 EXPLOITDB text VERIFIED
Rob Hensley AckerTodo 4.0 - Cross-Site Scripting via task_id Parameter
Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via the task_id parameter in an edit_task command.
by viz.security
CVE-2006-4637 EXPLOITDB text VERIFIED
ACGV News 0.9.1 - Remote Code Execution via PathNews Parameter
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.
by ddoshomo
CVE-2006-4648 EXPLOITDB text VERIFIED
BinGo News < 3.01 - Remote File Inclusion via bp_ncom.php bnrep Parameter
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.
by SHiKaA
CVE-2006-4643 EXPLOITDB text VERIFIED
Uni-Vert PhpLeague <0.82 - SQL Injection
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the id_joueur parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by DrEiNsTeIn
CVE-2006-4644 EXPLOITDB text VERIFIED
phpFullAnnu 5.1 - Remote File Inclusion via repmod Parameter
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the repmod parameter.
by SHiKaA
CVE-2006-4664 EXPLOITDB text VERIFIED
Premod Shadow < 2.7.1 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Kw3[R]Ln
CVE-2006-4649 EXPLOITDB text VERIFIED
BinGo News < 3.01 - Remote Code Execution via bnrep Parameter
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.
by SHiKaA
EIP-2026-105431 EXPLOITDB text VERIFIED
Beautifier 0.1 - 'Core.php' Remote File Inclusion
by the master