Exploitdb Exploits
31,394 exploits tracked across all sources.
Seir Anphin V666 Community Management System - Multiple SQL Injections
by CR
php(Reactor) 1.27pl1 - Remote File Inclusion via editprofile.php pathtohomedir Parameter
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter.
by CeNGiZ-HaN
MyNewsGroups :) < 0.6b - Remote Code Execution via myng_root Parameter
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
by Philipp Niedziela
mywebland myevent < 1.3 - Remote File Inclusion via myevent_path Parameter
PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter.
by CeNGiZ-HaN
moskool 1.5 - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in component/option,com_moskool/Itemid,34/admin.moskool.php in MamboXChange Moskool 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by saudi.unix
Help Center Live 2.1.2 - 'module.php' Directory Traversal
by Dr.GooGle
Banex PHP MySQL Banner Exchange 2.21 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
by SirDarckCat
Banex PHP MySQL Banner Exchange <2.21 - RCE
PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.
by SirDarckCat
Banex PHP MySQL Banner Exchange 2.21 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
by SirDarckCat
Scott Weedon Ajax Chat - Directory Traversal via chatid Parameter
Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arbitrary files via a .. (dot dot) in the chatid parameter.
by SirDarckCat
VMware ESX 2.0.x < 2.0.2 and 2.x < 2.5.2 patch 4 - Privilege Escalation via Base64-Encoded Cookie Credentials
VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows attackers to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).
by Stephen de Vries
User Home Pages 0.5 - Remote Code Execution via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Kurdish Security
Joomla LMO Component < 1.0b2 - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by vitux
Joomla! Component Liga Manager Online 2.0 - Remote File Inclusion
by vitux.manis
Mambo com_bayesiannaivefilter 1.1 - RCE
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesiannaivefilter) 1.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Pablin77
Microsoft Internet Explorer 6 and 7.0.6000.16473 - Denial of Service via Orphaned Object Property Access
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
by hdm
X-Scripts X-Protection 1.10 - SQL Injection via Username or Password Parameter
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.
by SirDarckCat
X-Scripts X-Poll - SQL Injection via Poll Parameter
SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by SirDarckCat
Mambatstaff < 3.1b - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Dr.Jr7
Colophon < 1.2 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Drago84
Yahoo! Messenger 7.0/7.5 - Remote Search String Arbitrary Browser Navigation
by Ivan Ivan
PHP-Nuke INP - Cross-Site Scripting via Query Parameter
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.
by l2odon
Joomla! com_securityimages <3.0.5 - RCE
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php, (2) lang.php, (3) client.php, and (4) server.php.
by Drago84
Mambo Gallery Manager < 0.95r2 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by A-S-T TEAM
JD-WordPress for Joomla! 2.0-1.0 RC2 - RCE
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.
by Drago84
By Source