Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-3687 EXPLOITDB text VERIFIED
D-Link DI-524, DI-604, DI-624, DI-784, WBR-1310, WBR-2310, EBR-2310 - Remote Code Execution via UPnP M-SEARCH Request
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.
by Barnaby Jack
CVE-2006-3754 EXPLOITDB text VERIFIED
flushcms < 1.0_pre2 - Remote File Inclusion via class_path Parameter
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.
by igi
CVE-2006-3755 EXPLOITDB text VERIFIED
FlushCMS < 1.0_pre2 - Remote File Inclusion via class_path Parameter
PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by igi
EIP-2026-115826 EXPLOITDB text VERIFIED
Microsoft Windows XP/2000 - Registry Access Local Denial of Service
by David Matousek
CVE-2006-3787 EXPLOITDB text VERIFIED
Kerio Personal Firewall < 4.3.268 - Denial of Service via CreateRemoteThread API Hook Bypass
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread.
by David Matousek
CVE-2006-3689 EXPLOITDB text VERIFIED
Codeworks Gnomedia SubberZ[LITE] - RCE
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed.
by Chironex Fleckeri
CVE-2006-3672 EXPLOITDB text VERIFIED
KDE Konqueror < 3.5.1 - Denial of Service via replaceChild DOM Method
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.
by hdm
CVE-2005-0859 EXPLOITDB text VERIFIED
CzarNews 1.13b - Remote File Inclusion via tpath Parameter
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.
by SHiKaA
EIP-2026-110692 EXPLOITDB text VERIFIED
PHP Event Calendar 1.4 - 'calendar.php' Remote File Inclusion
by Solpot
CVE-2006-3680 EXPLOITDB text VERIFIED
photocycle 1.0 - Cross-Site Scripting via phpage Parameter
Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web script or HTML via the phpage parameter.
by Luny
EIP-2026-107197 EXPLOITDB text VERIFIED
Forum 5 - 'pm.php' Local File Inclusion
by rgod
CVE-2006-3608 EXPLOITDB text VERIFIED
Simone Vellei Flatnuke <2.5.7 - Code Injection
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.
by rgod
CVE-2006-3621 EXPLOITDB text VERIFIED
Koobi Pro CMS 5.6 - SQL Injection via showtopic toid Parameter
SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.
by Evampire chiristof
CVE-2006-3685 EXPLOITDB text VERIFIED
CzarNews 1.12-1.14 - Remote File Inclusion via tpath Parameter
PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.
by SHiKaA
CVE-2006-3605 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Denial of Service via RevealTrans Transition Property
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.
by hdm
CVE-2006-3616 EXPLOITDB text VERIFIED
Carbonize Lazarus Guestbook <= 1.6 - Cross-Site Scripting via show and img Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.
by simo64
CVE-2006-3616 EXPLOITDB text VERIFIED
Carbonize Lazarus Guestbook <= 1.6 - Cross-Site Scripting via show and img Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.
by simo64
CVE-2006-3624 EXPLOITDB text VERIFIED
FLV Players 8 - Cross-Site Scripting via URL Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.
by xzerox
CVE-2006-3624 EXPLOITDB text VERIFIED
FLV Players 8 - Cross-Site Scripting via URL Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.
by xzerox
CVE-2006-3604 EXPLOITDB text VERIFIED
FlexWATCH Network Camera <= 3.0 - Directory Traversal via Dot-Dot-Encoded Slash Sequence
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.
by Jaime Blasco
CVE-2006-3591 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Denial of Service via Uninitialized TriEditDocument Object
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.
by hdm
CVE-2006-2835 EXPLOITDB text VERIFIED
saphplesson 2.0 - SQL Injection via forumid or lessid Parameter
SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.php.
by C.B.B.L
CVE-2006-3568 EXPLOITDB text VERIFIED
Fantastic Guestbook 2.0.1 - Cross-Site Scripting via First Name, Last Name, or Nickname Parameters
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters.
by omnipresent
EIP-2026-100349 EXPLOITDB text VERIFIED
Hosting Controller 1.x - 'error.asp' Cross-Site Scripting
by Dea7h
CVE-2006-3511 EXPLOITDB text VERIFIED
Internet Explorer 6 on Windows XP SP2 - DoS
Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.
by hdm