Exploitdb Exploits
31,394 exploits tracked across all sources.
Akarru Social BookMarking Engine <0.4.4.120 - RCE
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter.
by ddoshomo
Sponge News < 2.2 - Remote File Inclusion via sndir Parameter
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
by SHiKaA
SoftBB <= 0.1 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by ThE__LeO
Sky GUNNING MySpeach <= 3.0.2 - Remote File Inclusion via my_ms[root] Parameter
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter.
by SHiKaA
GrapAgenda < 0.11 - Remote File Inclusion via index.php page Parameter
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.
by Kurdish Security
C-News < 1.0.1 - Remote File Inclusion via path Parameter
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by SHiKaA
AnnonceV 1.1 - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Kurdish Security
acgv_news < 0.9.1 - Remote File Inclusion via PathNews Parameter
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter.
by SHiKaA
dsocks <1.4 - Remote Code Execution
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long node name.
by Michael Adams
ZIXForum 1.12 - SQL Injection via ReplyNew.asp RepId Parameter
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter.
by Chironex Fleckeri
Easy Address Book Web Server 1.2 - DoS
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.
by Revnic Vasile
MyHeadlines < 4.3.1 - Cross-Site Scripting via myh_op Parameter
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.
by Thomas Pollet
In-portal In-Link 2.3.4 - 'ADODB_DIR.php' Remote File Inclusion
by Saudi Hackrz
In-link 2.3.4 - 'ADODB_DIR' Remote File Inclusion
by Saudi Hackrz
FlashChat < 4.6.1_beta - Remote Code Execution via dir[inc] Parameter
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cmses/aedatingCMS.php, (2) inc/cmses/aedatingCMS2.php, or (3) inc/cmses/aedating4CMS.php.
by NeXtMaN
8pixel.net Simple Blog <= 2.3 - SQL Injection via id Parameter
Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism.
by Vipsta/MurderSkillz
yappa-ng - Remote File Inclusion
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
by SHiKaA
Muratsoft Haber Portal 3.6 - SQL Injection
SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
by ASIANEAGLE
dyncms < 6 - Remote File Inclusion via x_admindir Parameter
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the x_admindir parameter.
by SHiKaA
Autentificator 2.01 - SQL Injection via User Parameter
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary SQL commands via the user parameter.
by SirDarckCat
BlackICE PC Protection < 3.6 - Denial of Service via NtOpenSection API
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.
by David Matousek
vbzoom - Cross-Site Scripting via UserID Parameter
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.
by Crack_MaN
By Source