Exploitdb Exploits
31,394 exploits tracked across all sources.
pSlash 0.70 - Remote File Inclusion via lvc_include_dir Parameter
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.
by Mehmet Ince
RedBLoG 0.5 - Remote Code Execution
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Root3r_H3ll
Phome Empire CMS 3.7 - Remote File Inclusion via CheckLevel.php check_path Parameter
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the check_path parameter.
by Bob Linuson
ToendaCMS 1.0.3 - Remote File Inclusion via tcms_administer_site Parameter
PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_administer_site parameter to an unspecified script, probably index.php. NOTE: this issue has been disputed by a third party, who states that $tcms_administer_site is initialized to a constant value within index.php
by You_You
PHProjekt <0.6.1 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the path_pre parameter in (1) cm_lib.inc.php, (2) doc/br.edithelp.php, (3) doc/de.edithelp.php, (4) doc/ct.edithelp.php, (5) userrating.php, and (6) listing.php, a different set of vectors than CVE-2006-4204. NOTE: a third-party researcher has disputed the impact of the cm_lib.inc.php vector, stating that it is limited to local file inclusion. CVE analysis as of 20060905 concurs, although use of ftp URLs is also possible. The remaining five vectors have also been disputed by the same third party, stating that the path_pre variable is initialized before it is used
by the master
PHProjekt 6.1 - 'path_pre' Multiple Remote File Inclusions
by the master
PHlyMail Lite 3.4.4 - 'folderprops.php' Remote File Inclusion (2)
by Kw3[R]Ln
EstateAgent Component for Mambo - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by O.U.T.L.A.W
Mambo Component Display MOSBot Manager - 'MosConfig_absolute_path' Remote File Inclusion
by O.U.T.L.A.W
Headline Portal Engine 0.x/1.0 - 'HPEInc' Multiple Remote File Inclusions
by the master
Diesel Smart Traffic - Remote File Inclusion via clients/index.php src Parameter
PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter.
by night_warrior771
DieselScripts Job Site - 'Forgot.php' Multiple Cross-Site Scripting Vulnerabilities
by night_warrior771
Diesel Pay - Cross-Site Scripting via Read Parameter
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter.
by night_warrior771
Diesel Paid Mail - Cross-Site Scripting via getad.php ps Parameter
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter.
by night_warrior771
cPanel 10 - Cross-Site Scripting via dir Parameter in dohtaccess.html or file Parameter in editit.html/showfile.html
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.
by preth00nker
cPanel 10 - Cross-Site Scripting via dir Parameter in dohtaccess.html or file Parameter in editit.html/showfile.html
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.
by preth00nker
cPanel 10 - Cross-Site Scripting via dir Parameter in dohtaccess.html or file Parameter in editit.html/showfile.html
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.
by preth00nker
SportsPHool 1.0 - Remote File Inclusion via mainnav Parameter
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the mainnav parameter.
by Kacper
Shadows Rising RPG < 0.0.5b_pre-alpha - Remote File Inclusion via CONFIG[gameroot] Parameter
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2) core/includes/smarty.inc.php, (3) qcms/includes/smarty.inc.php or (4) qlib/smarty.inc.php.
by Kacper
NES Game and NES System - Remote File Inclusion via PHPHTMllib Parameter
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php.
by Kacper
SimpleBlog < 2.0 - SQL Injection via comments.asp id Parameter
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Chironex Fleckeri
LBlog <= 1.05 - SQL Injection via comments.asp id Parameter
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Chironex Fleckeri
tutti_nova < 1.6 - Remote File Inclusion via TNLIB_DIR Parameter
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.
by SHiKaA
ZZ:FlashChat 3.1 - 'adminlog' Remote File Inclusion
by SHiKaA
By Source