Exploitdb Exploits
31,394 exploits tracked across all sources.
vBulletin 3.5.4 and 3.6.0 - Cross-Site Scripting via PDF Attachment
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6.
by imei
Yahoo! Messenger 8.0.0.863 - File Extension Spoofing
by ivancool2003
Virtual War <= 1.5.0 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by mfoxhacker
Virtual War <= 1.5.0 - SQL Injection via Page Parameter
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by CVE-2006-3139.
by mfoxhacker
WoW Roster 1.70 - '/lib/phpBB.php' Remote File Inclusion
by |peti
TSEP <0.942 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php, (2) contentimages.class.php, (3) ipfunctions.php, (4) configfunctions.php, (5) printpagedetails.php, or (6) log.class.php. NOTE: the copyright.php vector is already covered by CVE-2006-3993.
by beford
circeOS SaveWeb Portal 3.4 - RCE
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the SITE_Path parameter to (1) poll/poll.php or (2) poll/view_polls.php. NOTE: the menu_dx.php vector is already covered by CVE-2005-2687.
by Mehmet Ince
Kayako eSupport - Remote File Inclusion via autoclose.php subd Parameter
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.
by beford
TSEP < 0.942 - Remote File Inclusion via tsep_config[absPath] Parameter
PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter.
by Philipp Niedziela
WoWRoster 1.5.1 - Remote File Inclusion via conf.php subdir Parameter
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.
by skulmatic
WoWRoster 1.5.x and earlier - Remote File Inclusion via hsList.php subdir Parameter
PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.
by skulmatic
Vlad Vostrykh Voodoo chat <1.0RC1b - RCE
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter.
by SHiKaA
Olaf Noehring The Search Engine Project (TSEP) <0.942 - RCE
PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to pagenavigation.php, a different vector than CVE-2006-4055. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Philipp Niedziela
TinyPHPForum 3.6 - 'UpdatePF.php' Authentication Bypass
by SirDarckCat
TinyPHPForum 3.6 - 'error.php' Information Disclosure
by SirDarckCat
phpauction 2.1 - Remote File Inclusion via phpAds_path Parameter
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.
by Philipp Niedziela
Knusperleicht newsReporter <1.1 - RCE
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.
by Kurdish Security
Knusperleicht Newsletter <3.5 - RCE
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.
by SHiKaA
Knusperleicht Shoutbox < 4.4 - Remote File Inclusion via sb_include_path Parameter
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.
by Kurdish Security
Knusperleicht FileManager <1.2 - RCE
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.
by SHiKaA
Knusperleicht Quickie - Remote File Inclusion via QUICK_PATH Parameter
PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter.
by Kurdish Security
Knusperleicht Guestbook 3.5 - Remote File Inclusion via GB_PATH Parameter
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
by Kurdish Security
Knusperleicht Faq 1.0 - Remote File Inclusion via faq_path Parameter
PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.
by Kurdish Security
TinyPHPForum 3.6 - Multiple Cross-Site Scripting Vulnerabilities (2)
by SirDarckCat
By Source