Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4279 EXPLOITDB text VERIFIED
XennoBB <= 2.2.1 - SQL Injection via topic_post.php icon_topic Parameter
SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter.
by Chris Boulton
CVE-2006-4277 EXPLOITDB text VERIFIED
tutti_nova < 1.6 - Remote File Inclusion via TNLIB_DIR Parameter
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by SHiKaA
CVE-2006-4363 EXPLOITDB text VERIFIED
CropImage component 1.0 for Mambo - Remote File Inclusion via cropimagedir Parameter
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.
by Mehmet Ince
CVE-2006-4372 EXPLOITDB text VERIFIED
Mambo com_lurm_constructor <0.6b - RCE
PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constructor) 0.6b and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.
by mdx
CVE-2006-4296 EXPLOITDB text VERIFIED
Mambo bigAPE-Backup Component - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosConfig_absolute_path parameter.
by mdx
CVE-2006-4448 EXPLOITDB text VERIFIED
interact 2.2 - Remote File Inclusion via CONFIG[BASE_PATH] or CONFIG[LANGUAGE_CPATH] Parameter
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c) admin/autoprompter.php.
by Kacper
CVE-2006-4285 EXPLOITDB text VERIFIED
Fantastic News <= 2.1.5 - Remote Code Execution via CONFIG[script_path] Parameter
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected.
by SHiKaA
CVE-2006-4311 EXPLOITDB text VERIFIED
Sonium Enterprise Adressbook 0.2 - RCE
PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php.
by Philipp Niedziela
EIP-2026-111013 EXPLOITDB text VERIFIED
phpCodeGenie 3.0.2 - 'BEAUT_PATH' Remote File Inclusion
by Kacper
CVE-2006-4291 EXPLOITDB text VERIFIED
phlymail_lite < 3.4.4 - Remote Code Execution via _PM_[path][handler] Parameter
PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers to execute arbitrary PHP code via a URL in the _PM_[path][handler] parameter.
by Kacper
EIP-2026-109301 EXPLOITDB text VERIFIED
Mambo Component Rssxt 1.0 - 'MosConfig_absolute_path' Multiple Remote File Inclusions
by Crackers_Child
CVE-2006-4282 EXPLOITDB text VERIFIED
MamboWiki 0.9.6 - Remote File Inclusion via IP Parameter
PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.
by camino
EIP-2026-109290 EXPLOITDB text VERIFIED
Mambo Component LMTG Myhomepage 1.2 - Multiple Remote File Inclusions
by O.U.T.L.A.W
EIP-2026-108774 EXPLOITDB text VERIFIED
Joomla! Component Link Directory 1.0.3 - Remote File Inclusion
by camino
CVE-2006-4348 EXPLOITDB text VERIFIED
Kochsuite Component 0.9.4 - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by camino
CVE-2006-3949 EXPLOITDB text VERIFIED
Mambo Artlinks Component - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by camino
EIP-2026-102982 EXPLOITDB text VERIFIED
Roxio Toast 7 - DejaVu Component PATH Variable Privilege Escalation
by Netragard
CVE-2006-4238 EXPLOITDB text VERIFIED
WebTorrent < 0.2.4 - SQL Injection via Category Parameter
SQL injection vulnerability in torrents.php in WebTorrent (WTcom) 0.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter in category mode.
by sh1r081
CVE-2006-4236 EXPLOITDB text VERIFIED
POWERGAP - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parameter to (a) s01.php, (b) s02.php, (c) s03.php, and (d) s04.php; and possibly a URL located after "shopid=" or "sid=" in the PATH_INFO.
by Saudi Hackrz
CVE-2006-4270 EXPLOITDB text VERIFIED
mambelfish_component < 1.1 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by mdx
EIP-2026-109278 EXPLOITDB text VERIFIED
Mambo Component 'com_phpshop' 1.2 RC2b - Remote File Inclusion
by Cmaster4
CVE-2006-4288 EXPLOITDB text VERIFIED
a6mambocredits component for Mambo - Remote Code Execution via mosConfig_live_site Parameter
PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party information.
by Cmaster4
CVE-2006-3990 EXPLOITDB text VERIFIED
Savant2 - Remote File Inclusion via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.
by Crackers_Child
CVE-2006-4242 EXPLOITDB text VERIFIED
Joomla/Mambo JIM 1.0.1 - Code Injection
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Mehmet Ince
CVE-2006-4237 EXPLOITDB text VERIFIED
Invisionix Roaming System <0.2 - RCE
PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter.
by Kacper