Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4645 EXPLOITDB text VERIFIED
Akarru Social BookMarking Engine <0.4.4.120 - RCE
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter.
by ddoshomo
CVE-2006-4647 EXPLOITDB text VERIFIED
Sponge News < 2.2 - Remote File Inclusion via sndir Parameter
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.
by SHiKaA
CVE-2006-4593 EXPLOITDB text VERIFIED
SoftBB <= 0.1 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by ThE__LeO
CVE-2006-4630 EXPLOITDB text VERIFIED
Sky GUNNING MySpeach <= 3.0.2 - Remote File Inclusion via my_ms[root] Parameter
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter.
by SHiKaA
CVE-2006-4610 EXPLOITDB text VERIFIED
GrapAgenda < 0.11 - Remote File Inclusion via index.php page Parameter
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.
by Kurdish Security
CVE-2006-4629 EXPLOITDB text VERIFIED
C-News < 1.0.1 - Remote File Inclusion via path Parameter
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by SHiKaA
CVE-2006-4622 EXPLOITDB text VERIFIED
AnnonceV 1.1 - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by Kurdish Security
CVE-2006-4638 EXPLOITDB text VERIFIED
acgv_news < 0.9.1 - Remote File Inclusion via PathNews Parameter
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter.
by SHiKaA
CVE-2006-4611 EXPLOITDB text VERIFIED
dsocks <1.4 - Remote Code Execution
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long node name.
by Michael Adams
CVE-2006-4612 EXPLOITDB text VERIFIED
ZIXForum 1.12 - SQL Injection via ReplyNew.asp RepId Parameter
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter.
by Chironex Fleckeri
CVE-2006-4654 EXPLOITDB text VERIFIED
Easy Address Book Web Server 1.2 - DoS
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.
by Revnic Vasile
CVE-2006-4563 EXPLOITDB text VERIFIED
MyHeadlines < 4.3.1 - Cross-Site Scripting via myh_op Parameter
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.
by Thomas Pollet
EIP-2026-107821 EXPLOITDB text VERIFIED
In-portal In-Link 2.3.4 - 'ADODB_DIR.php' Remote File Inclusion
by Saudi Hackrz
EIP-2026-107817 EXPLOITDB text VERIFIED
In-link 2.3.4 - 'ADODB_DIR' Remote File Inclusion
by Saudi Hackrz
CVE-2006-4583 EXPLOITDB text VERIFIED
FlashChat < 4.6.1_beta - Remote Code Execution via dir[inc] Parameter
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cmses/aedatingCMS.php, (2) inc/cmses/aedatingCMS2.php, or (3) inc/cmses/aedating4CMS.php.
by NeXtMaN
CVE-2006-4592 EXPLOITDB text VERIFIED
8pixel.net Simple Blog <= 2.3 - SQL Injection via id Parameter
Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism.
by Vipsta/MurderSkillz
CVE-2005-1312 EXPLOITDB text VERIFIED
yappa-ng - Remote File Inclusion
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
by SHiKaA
CVE-2006-4641 EXPLOITDB text VERIFIED
Muratsoft Haber Portal 3.6 - SQL Injection
SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
by ASIANEAGLE
CVE-2006-4589 EXPLOITDB text VERIFIED
dyncms < 6 - Remote File Inclusion via x_admindir Parameter
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the x_admindir parameter.
by SHiKaA
CVE-2006-4599 EXPLOITDB text VERIFIED
Autentificator 2.01 - SQL Injection via User Parameter
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary SQL commands via the user parameter.
by SirDarckCat
CVE-2006-4541 EXPLOITDB text VERIFIED
BlackICE PC Protection < 3.6 - Denial of Service via NtOpenSection API
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.
by David Matousek
EIP-2026-114502 EXPLOITDB text VERIFIED
YACS 6.6.1 - Multiple Remote File Inclusions
by MATASANOS
CVE-2006-4634 EXPLOITDB text VERIFIED
vbzoom - Cross-Site Scripting via UserID Parameter
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.
by Crack_MaN
EIP-2026-112730 EXPLOITDB text VERIFIED
ToendaCMS 0.x/1.0.x - Remote File Inclusion
by h4ck3riran
EIP-2026-110471 EXPLOITDB text VERIFIED
Papoo CMS 3.2 - IBrowser Remote File Inclusion
by Ironfist