Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-3897 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Denial of Service via NMSA.ASFSourceMediaDescription ActiveX Object
Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
by hdm
CVE-2006-3915 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Denial of Service via Native Function Iterator
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.
by hdm
CVE-2006-4029 EXPLOITDB text VERIFIED
AGEphone 1.24 and 1.38.1 - Stack-Based Buffer Overflow via Crafted UDP SIP Packet
Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet.
by Tan Chew Keong
EIP-2026-111663 EXPLOITDB text VERIFIED
RadScripts - 'a_editpage.php?Filename' Arbitrary File Overwrite
by INVENT
EIP-2026-111504 EXPLOITDB text VERIFIED
Prince Clan Chess Club 0.8 - 'Include.PCchess.php' Remote File Inclusion
by OLiBekaS
CVE-2006-3886 EXPLOITDB text VERIFIED
Shalwan MusicBox <= 2.3.4 - SQL Injection via Page Parameter
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.
by EllipSiS Security
CVE-2006-5044 EXPLOITDB text VERIFIED
Princeclan Chess <0.8 - Info Disclosure
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.
by OLiBekaS
CVE-2006-3850 EXPLOITDB text VERIFIED
Vanilla CMS < 1.0.1 - Remote File Inclusion via RootDirectory Parameter
PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected
by MFox
CVE-2006-3944 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Denial of Service via ListWidth Property Overflow
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.
by hdm
CVE-2006-3911 EXPLOITDB text VERIFIED
PHP Live! < 3.2.1 - Remote File Inclusion via css_path Parameter
PHP remote file inclusion vulnerability in OSI Codes PHP Live! 3.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the css_path parameter in (1) help.php and (2) setup/header.php.
by magnific
CVE-2006-3846 EXPLOITDB text VERIFIED
Mambo MultiBanners 1.0.1 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Blue|Spy
CVE-2006-3847 EXPLOITDB text VERIFIED
MoSpray 1.8 RC1 - Remote Code Execution via basedir Parameter
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter.
by Kurdish Security
CVE-2006-3951 EXPLOITDB text VERIFIED
mam-moodle_alpha_component - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by jank0
EIP-2026-105251 EXPLOITDB text VERIFIED
ArticlesOne 07232006 - 'page' Remote File Inclusion
by CyberLord
EIP-2026-103853 EXPLOITDB text VERIFIED
Apache Tomcat < 5.5.17 - Remote Directory Listing
by ScanAlert Security
CVE-2006-3917 EXPLOITDB text VERIFIED
R. Corson PHP Forge <3 - Code Injection
PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter.
by Virangar Security
CVE-2006-3746 EXPLOITDB text VERIFIED
GnuPG 1.4.4 - Denial of Service via Integer Overflow in parse_comment
Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.
by Evgeny Legerov
CVE-2006-2372 EXPLOITDB text VERIFIED
Microsoft DHCP Client Service - Remote Code Execution via Crafted DHCP Response
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
by redsand
CVE-2006-3836 EXPLOITDB text VERIFIED
UNIDOmedia Chameleon LE < 1.203 - Directory Traversal via rmid Parameter
Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.
by kicktd
CVE-2003-1179 EXPLOITDB text VERIFIED
Advanced Poll 2.0.2 - Remote File Inclusion via include_path or base_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.
by Solpot
CVE-2006-3835 EXPLOITDB text VERIFIED
Apache Tomcat <5.5.17 - Path Traversal
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
by ScanAlert Security
CVE-2006-3899 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6.0 - Denial of Service via CEnroll ActiveX stringToBinary Function
Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.
by hdm
CVE-2006-3793 EXPLOITDB text VERIFIED
sitedepth_cms < 3.01 - Remote File Inclusion via SD_DIR Parameter
PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SD_DIR parameter.
by Aesthetico
CVE-2006-3955 EXPLOITDB text VERIFIED
MiniBB Forum 1.5a - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) news.php, (2) search.php, or (3) whosOnline.php.
by AG-Spider
CVE-2006-3771 EXPLOITDB text VERIFIED
iManage CMS < 4.0.12 - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) articles.php, (2) contact.php, (3) displaypage.php, (4) faq.php, (5) mainbody.php, (6) news.php, (7) registration.php, (8) whosOnline.php, (9) components/com_calendar.php, (10) components/com_forum.php, (11) components/minibb/index.php, (12) components/minibb/bb_admin.php, (13) components/minibb/bb_plugins.php, (14) modules/mod_calendar.php, (15) modules/mod_browser_prefs.php, (16) modules/mod_counter.php, (17) modules/mod_online.php, (18) modules/mod_stats.php, (19) modules/mod_weather.php, (20) themes/bizz.php, (21) themes/default.php, (22) themes/simple.php, (23) themes/original.php, (24) themes/portal.php, (25) themes/purple.php, and other unspecified files.
by Matdhule