Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106272 EXPLOITDB text VERIFIED
CubeCart 3.0.x - Multiple Input Validation Vulnerabilities
by rgod
EIP-2026-105523 EXPLOITDB text VERIFIED
Blog:CMS 4.1 - 'Dir_Plugins' Multiple Remote File Inclusions
by Drago84
CVE-2006-4227 EXPLOITDB text VERIFIED
MySQL - Privilege Escalation via SUID Routine Argument Evaluation
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
by Michal Prokopiuk
CVE-2006-4239 EXPLOITDB text VERIFIED
Outreach Project Tool OPT Max < 1.2.6 - Remote File Inclusion via CRM_inc Parameter
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_inc parameter.
by Kacper
CVE-2006-4241 EXPLOITDB text VERIFIED
Mambo Reporter Component - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Crackers_Child
CVE-2006-4321 EXPLOITDB text VERIFIED
Coppermine Photo Gallery <1.0 - RCE
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by k1tk4t
CVE-2006-4234 EXPLOITDB text VERIFIED
dotProject 2.0.4 - Remote File Inclusion via baseDir Parameter
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
by Kacper
EIP-2026-116506 EXPLOITDB text VERIFIED
VMware 5.5.1 - Partition Table Deletion Denial of Service
by nop
CVE-2006-4215 EXPLOITDB text VERIFIED
Zen Cart < 1.3.0.2 - Remote Code Execution via autoLoadConfig Parameter
PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter.
by GulfTech Security
CVE-2006-4217 EXPLOITDB text VERIFIED
WEBInsta CMS < 0.3.1 - Remote File Inclusion via module_dir Parameter
PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Yns
CVE-2006-4204 EXPLOITDB text VERIFIED
phprojekt < 5.1 - Remote Code Execution via path_pre or lib_path Parameter
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre parameter in lib/specialdays.php and the (2) lib_path parameter in lib/dbman_filter.inc.php.
by Kacper
CVE-2006-4190 EXPLOITDB text VERIFIED
PHP-Nuke AutoHTML Module - Directory Traversal via Name Parameter
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation.
by MosT3mR
CVE-2006-4230 EXPLOITDB text VERIFIED
Lizge V.20 Web Portal - Remote File Inclusion via lizge or bade Parameter
Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) lizge or (2) bade parameters.
by Crackers_Child
CVE-2006-4207 EXPLOITDB text VERIFIED
Bob Jewell Discloser < 0.0.4 - Remote File Inclusion via fileloc Parameter
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php.
by Arash RJ
CVE-2006-4208 EXPLOITDB text VERIFIED
Skippy WP-DB-Backup plugin for WordPress <= 1.7 - Authenticated Directory Traversal via Backup Parameter
Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.
by marc & shb
CVE-2006-4205 EXPLOITDB text VERIFIED
WebDynamite ProjectButler 0.8.4 - RCE
Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3) Performance.class.php, (4) Project.class.php, (5) Representative.class.php, (6) User.class.php, or (7) common.php.
by the master
CVE-2006-4195 EXPLOITDB text VERIFIED
Peoplebook Component for Mambo < 1.1.2 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Matdhule
CVE-2006-4203 EXPLOITDB text VERIFIED
Mambo com_mmp <1.2 - Remote Code Execution
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by mdx
CVE-2006-4197 EXPLOITDB text VERIFIED
libmusicbrainz < 2.1.2 and libmusicbrainz_svn < 8406 - Buffer Overflow via HTTP Location Header or RDF URL
Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.
by Luigi Auriemma
CVE-2006-4144 EXPLOITDB text VERIFIED
ImageMagick - Denial of Service and Possible Remote Code Execution via Integer Overflow in ReadSGIImage
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.
by Damian Put
CVE-2006-4202 EXPLOITDB text VERIFIED
spidey_blog_script < 1.5 - SQL Injection via pid Parameter
SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.
by ASIANEAGLE
EIP-2026-100167 EXPLOITDB text VERIFIED
BlaBla 4U - Multiple Cross-Site Scripting Vulnerabilities
by Vampire
CVE-2006-4129 EXPLOITDB text VERIFIED
Joomla Webring Component 1.0 - Remote File Inclusion via component_dir Parameter
PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter.
by Mehmet Ince
CVE-2006-3121 EXPLOITDB text VERIFIED
High-Availability Linux <2.0.7 - DoS
The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.
by Yan Rong Ge
CVE-2006-4138 EXPLOITDB text VERIFIED
Microsoft Windows Help File viewer - RCE
Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files.
by Benjamin Tobias Franz