Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4992 EXPLOITDB text VERIFIED
JD-WordPress for Joomla! 2.0-1.0 RC2 - RCE
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.
by Drago84
CVE-2006-4992 EXPLOITDB text VERIFIED
JD-WordPress for Joomla! 2.0-1.0 RC2 - RCE
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.
by Drago84
CVE-2006-3943 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Stack-Based Buffer Overflow via NDFXArtEffects Color Properties
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.
by hdm
CVE-2006-3928 EXPLOITDB text VERIFIED
WMNews < 0.2a - Remote File Inclusion via base_datapath Parameter
PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_datapath parameter.
by uNfz
CVE-2006-3922 EXPLOITDB text VERIFIED
PortailPHP < 1.7 - Remote File Inclusion via chemin Parameter
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
by Mehmet Ince
EIP-2026-109754 EXPLOITDB text VERIFIED
MyBulletinBoard (MyBB) 1.x - 'usercp.php' Directory Traversal
by Roozbeh Afrasiabi
CVE-2006-3930 EXPLOITDB text VERIFIED
a6mambohelpdesk < 1.2 - Remote File Inclusion via mosConfig_live_site Parameter
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
by Dr.Jr7
CVE-2006-7072 EXPLOITDB text VERIFIED
GeoClassifieds Enterprise <= 2.0.5.2 - Cross-Site Scripting via b[username] or c Parameter
Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b) admin/index.php, and (3) c[phone] parameter to register.php.
by EllipSiS Security
CVE-2006-3957 EXPLOITDB text VERIFIED
BosDev BosDates - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.
by admin@jaascois.com
EIP-2026-103613 EXPLOITDB text VERIFIED
Oracle 10g - Alter Session Integer Overflow
by putosoft softputo
CVE-2006-3929 EXPLOITDB text
Zyxel Prestige 660H-61 - Cross-Site Scripting via Hex-Encoded a Parameter
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.
by jose.palanco
CVE-2006-3909 EXPLOITDB text VERIFIED
WWWthreads - Cross-Site Scripting via Calendar Week Parameter
Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter.
by l2odon
CVE-2006-3940 EXPLOITDB text VERIFIED
phpbb-auction - SQL Injection via ar Parameter in auction_room.php and u Parameter in auction_store.php
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
by l2odon
CVE-2006-3940 EXPLOITDB text VERIFIED
phpbb-auction - SQL Injection via ar Parameter in auction_room.php and u Parameter in auction_store.php
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
by l2odon
EIP-2026-102515 EXPLOITDB text VERIFIED
OpenCMS 6.0/6.2 - Multiple Unauthorized Access Vulnerabilities
by Meder Kydyraliev
CVE-2006-3990 EXPLOITDB text VERIFIED
Savant2 - Remote File Inclusion via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.
by botan
CVE-2006-3926 EXPLOITDB text VERIFIED
PhpProBid 5.24 - SQL Injection via View/Start/OrderType Parameters
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php.
by EllipSiS Security
CVE-2006-3926 EXPLOITDB text VERIFIED
PhpProBid 5.24 - SQL Injection via View/Start/OrderType Parameters
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php.
by EllipSiS Security
CVE-2006-3927 EXPLOITDB text VERIFIED
PhpProBid 5.24 - Cross-Site Scripting via auctionsearch.php advsrc Parameter
Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter.
by EllipSiS Security
CVE-2006-3883 EXPLOITDB text VERIFIED
Gonafish LinksCaffe 3.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php.
by simo64
CVE-2006-3883 EXPLOITDB text VERIFIED
Gonafish LinksCaffe 3.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php.
by simo64
CVE-2006-3884 EXPLOITDB text VERIFIED
Gonafish LinksCaffe 3.0 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in a deadlink action. NOTE: this issue can also be used for path disclosure by a forced SQL error, or to modify PHP files using OUTFILE.
by simo64
CVE-2006-3883 EXPLOITDB text VERIFIED
Gonafish LinksCaffe 3.0 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php.
by simo64
EIP-2026-109159 EXPLOITDB text VERIFIED
LinksCaffe 2.0/3.0 - Authentication Bypass
by HoangYenXinhDep
EIP-2026-103612 EXPLOITDB text VERIFIED
Opera Web Browser 9 - CSS Background URI Memory Corruption
by hdm