Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4045 EXPLOITDB text VERIFIED
torbstoff_news 4 - Remote File Inclusion via pfad Parameter
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.
by SHiKaA
CVE-2006-4102 EXPLOITDB text VERIFIED
sqlitewebadmin < 0.1 - Remote File Inclusion via conf[classpath] Parameter
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.
by SirDarckCat
EIP-2026-112076 EXPLOITDB text VERIFIED
Simple CMS - Administrator Authentication Bypass
by daaan
CVE-2006-4063 EXPLOITDB text VERIFIED
Csaba Godor SAPID Blog Beta 2 - RCE
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/extensions/get_blog_meta_info.inc.php, or (c) usr/extensions/get_infochannel.inc.php; or the (2) GLOBALS[root_path] parameter to (d) usr/extensions/get_tree.inc.php.
by Kacper
CVE-2006-4065 EXPLOITDB text VERIFIED
Dmitry Sheiko SAPID Gallery 1.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.
by Kacper
CVE-2006-4063 EXPLOITDB text VERIFIED
Csaba Godor SAPID Blog Beta 2 - RCE
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/extensions/get_blog_meta_info.inc.php, or (c) usr/extensions/get_infochannel.inc.php; or the (2) GLOBALS[root_path] parameter to (d) usr/extensions/get_tree.inc.php.
by Kacper
CVE-2006-4063 EXPLOITDB text VERIFIED
Csaba Godor SAPID Blog Beta 2 - RCE
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/extensions/get_blog_meta_info.inc.php, or (c) usr/extensions/get_infochannel.inc.php; or the (2) GLOBALS[root_path] parameter to (d) usr/extensions/get_tree.inc.php.
by Kacper
EIP-2026-111631 EXPLOITDB text VERIFIED
QuestCMS - 'main.php' Remote File Inclusion
by Crackers_Child
CVE-2006-4061 EXPLOITDB text VERIFIED
phpPrintAnalyzer 1.1 - Remote File Inclusion via rep_par_rapport_racine Parameter
PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the rep_par_rapport_racine variable is initialized before use
by sh3ll
CVE-2006-4044 EXPLOITDB text VERIFIED
phpCodeCabinet <= 0.5 - Remote File Inclusion via BEAUT_PATH Parameter
PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.
by Minion
CVE-2006-4073 EXPLOITDB text VERIFIED
phpCC Beta 4.2 - Remote File Inclusion via base_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.
by Solpot
CVE-2006-4050 EXPLOITDB text VERIFIED
PHP AMA <3.2.4 - Remote Code Execution
PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.
by Philipp Niedziela
CVE-2006-4052 EXPLOITDB text VERIFIED
Turnkey Web Tools PHP Simple Shop <2.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4) admin/login.php, (5) admin/menu.php or (6) admin/header.php.
by Matdhule
CVE-2006-4051 EXPLOITDB text VERIFIED
Turnkey Web Tools PHP Live Helper <2.0 - RCE
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.
by Matdhule
CVE-2006-4059 EXPLOITDB text VERIFIED
USOLVED NEWSolved Lite <1.9.2 - RCE
Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2) newsticker/newsscript_get.php, (3) inc/output/news_theme1.php, (4) inc/output/news_theme2.php, or (5) inc/output/news_theme3.php.
by Philipp Niedziela
CVE-2006-4034 EXPLOITDB text VERIFIED
ModernGigabyte ModernBill <1.6 - RCE
PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.
by Solpot
CVE-2006-4053 EXPLOITDB text VERIFIED
ME Download System 1.3 - Remote File Inclusion via Vb8878b936c2bd8ae0cab Parameter
PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.
by Philipp Niedziela
CVE-2006-4074 EXPLOITDB text VERIFIED
Joomla JD-Wiki < 1.0.2 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by jank0
CVE-2006-3468 EXPLOITDB text VERIFIED
Linux kernel 2.6.x - Denial of Service via NFS EXT3 File Handle Error
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.
by James McKenzie
CVE-2006-4018 EXPLOITDB text VERIFIED
ClamAV 0.81-0.88.3 - Remote Code Execution via UPX Packed File with Large rsize Values
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
by Damian Put
CVE-2006-4081 EXPLOITDB text VERIFIED
Barracuda Spam Firewall (BSF) <3.3.03.053 - Command Injection
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.
by Greg Sinclair
CVE-2006-4064 EXPLOITDB text VERIFIED
YenerTurk Haber Script <= 2.0 - SQL Injection via id Parameter
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported reported that 2.0 is also affected.
by ASIANEAGLE
CVE-2006-7065 EXPLOITDB text VERIFIED
Microsoft IE - Denial of Service
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
by Thomas Pollet
CVE-2006-4125 EXPLOITDB text VERIFIED
dconnect_daemon <= 0.7.0 - Remote Code Execution via Large Nickname in listen_thread_udp
Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function.
by Luigi Auriemma
CVE-2006-4126 EXPLOITDB text VERIFIED
DConnect Daemon <= 0.7.0 - Denial of Service via Null Pointer Dereference in dc_chat Function
The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference.
by Luigi Auriemma