Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4115 EXPLOITDB text VERIFIED
PgMarket 2.2.3 - Remote File Inclusion via CFG[libdir] Parameter
PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter.
by Mehmet Ince
EIP-2026-105956 EXPLOITDB text VERIFIED
CLUB Nuke 2.0 - Multiple SQL Injections
by ASIANEAGLE
CVE-2006-4123 EXPLOITDB text VERIFIED
Boite de News 4.0.1 - Remote File Inclusion via url_index Parameter
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter.
by the master
CVE-2006-4131 EXPLOITDB text VERIFIED
ArcSoft MMS Composer < 1.5.5.6 - Buffer Overflow via Crafted MMS Messages
Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers.
by Collin R. Mulliner
CVE-2006-4110 EXPLOITDB text VERIFIED
Apache HTTP Server 2.2.2 - Source Code Disclosure via Case-Insensitive ScriptAlias Bypass
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
by Susam Pal
CVE-2006-4089 EXPLOITDB text VERIFIED
AlsaPlayer <= 0.99.76 - Multiple Buffer Overflow via HTTP Location Field, URL, and CDDB Response
Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an overflow in the reconnect function in reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file for the playlist, which triggers overflows in new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers an overflow in cddb_lookup in input/ccda/cdda_engine.c.
by Luigi Auriemma
CVE-2006-4103 EXPLOITDB text VERIFIED
PHP <1.3 - Remote Code Execution
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
by Drago84
CVE-2006-4113 EXPLOITDB text VERIFIED
PHP <4.2 - Remote Code Execution
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.
by Drago84
CVE-2006-4075 EXPLOITDB text VERIFIED
Wim Fleischhauer docpile: wim's edition <0.2.2 - RCE
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3) lib/document.class.php or (4) lib/auth.inc.php.
by Mehmet Ince
CVE-2006-4077 EXPLOITDB text VERIFIED
Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1 - RCE
PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.
by Philipp Niedziela
CVE-2006-4081 EXPLOITDB text VERIFIED
Barracuda Spam Firewall (BSF) <3.3.03.053 - Command Injection
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.
by PATz
CVE-2006-4072 EXPLOITDB text VERIFIED
Club-Nuke [XP] 2.0 LCID 2048 - SQL Injection via haber_id Parameter
Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via the (2) menu_id parameter to menu.asp.
by ASIANEAGLE
CVE-2006-4062 EXPLOITDB text VERIFIED
Dmitry Sheiko SAPID Shop <1.2 - RCE
PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.
by Kacper
CVE-2006-4026 EXPLOITDB text VERIFIED
SAPID CMS 123 rc3 - Remote Code Execution via root_path Parameter
PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter in usr/extensions/get_infochannel.inc.php and the (2) GLOBALS["root_path"] parameter in usr/extensions/get_tree.inc.php.
by Kacper
CVE-2006-4036 EXPLOITDB text VERIFIED
ZoneMetrics ZoneX Publishers Gold Edition <1.0.3 - RCE
PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2006-4025 EXPLOITDB text VERIFIED
XennoBB < 2.1.0 - Authenticated SQL Injection via Profile Parameters
SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.
by Chris Boulton
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-1747 EXPLOITDB text VERIFIED
Virtual War 1.5.0 - Remote File Inclusion via vwar_root Parameter
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
by AG-Spider
CVE-2006-4060 EXPLOITDB text VERIFIED
Visual Events Calendar 1.1 - Remote File Inclusion via cfg_dir Parameter
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.
by Mehmet Ince
EIP-2026-112812 EXPLOITDB text VERIFIED
TurnkeyWebTools PHP Simple Shop 2.0 - Multiple Remote File Inclusions
by Matdhule