Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112404 EXPLOITDB text VERIFIED
SQuery 4.5 - 'gore.php' Remote File Inclusion
by SHiKaA
CVE-2006-3560 EXPLOITDB text VERIFIED
Blue Dojo Graffiti Forums 1.0 - SQL Injection
SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter.
by Paisterist
CVE-2006-3602 EXPLOITDB text VERIFIED
FarsiNews 3.0 BETA 1 - Directory Traversal via Language Parameter
Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the language parameter in the advanced theme.
by armin390
CVE-2006-3512 EXPLOITDB text VERIFIED
Internet Explorer 6 on Windows XP - DoS
Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.
by hdm
CVE-2006-3520 EXPLOITDB text VERIFIED
sabdrimer_cms < 2.2.4 - Remote Code Execution via Pluginpath Parameter
PHP remote file inclusion vulnerability in skins/advanced/advanced1.php in Sabdrimer Pro 2.2.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pluginpath[0] parameter.
by A.nosrati
EIP-2026-109276 EXPLOITDB text VERIFIED
Mambo Componen phpBB 1.2.4 - Multiple Remote File Inclusions
by h4ntu
CVE-2006-3510 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - DoS
The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
by hdm
CVE-2006-3513 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - DoS
danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.
by hdm
CVE-2006-3517 EXPLOITDB text VERIFIED
PHP <stats.php> - Remote Code Execution
PHP remote file inclusion vulnerability in stats.php in RW::Download, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
by StorMBoY
CVE-2006-3528 EXPLOITDB text VERIFIED
Simpleboard < 1.1.0 - Remote Code Execution via PHP File Inclusion in sbp Parameter
Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) image_upload.php and (2) file_upload.php.
by h4ntu
CVE-2006-7208 EXPLOITDB text VERIFIED
Adam van Dongen Forum (com_forum) 1.2.4RC3 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by h4ntu
CVE-2006-3662 EXPLOITDB text VERIFIED
ATutor 1.5.3 - SQL Injection via fid Parameter
SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1
by securityconnection
CVE-2006-3518 EXPLOITDB text VERIFIED
Webvizyon Portal 2006 - SQL Injection
SQL injection vulnerability in SayfalaAltList.asp in Webvizyon Portal 2006 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by StorMBoY
CVE-2006-3556 EXPLOITDB text VERIFIED
ExtCalendar 2.0 - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Matdhule
CVE-2006-3431 EXPLOITDB text VERIFIED
Microsoft Excel - Buffer Overflow via Crafted STYLE Record
Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
by Nanika
CVE-2006-3484 EXPLOITDB text VERIFIED
ATutor < 1.5.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.
by Security News
CVE-2006-3484 EXPLOITDB text VERIFIED
ATutor < 1.5.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.
by Security News
CVE-2006-3484 EXPLOITDB text VERIFIED
ATutor < 1.5.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.
by Security News
CVE-2006-3484 EXPLOITDB text VERIFIED
ATutor < 1.5.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.
by Security News
CVE-2006-3484 EXPLOITDB text VERIFIED
ATutor < 1.5.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.
by Security News
CVE-2006-3147 EXPLOITDB text VERIFIED
Hosting Controller <6.1 - Privilege Escalation
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise details, it is not clear whether this is related to a previously disclosed issue such as CVE-2005-1788.
by Soroush Dalili
CVE-2006-3478 EXPLOITDB text VERIFIED
myphp_cms 0.3 - Remote File Inclusion via global_header.php domain Parameter
PHP remote file inclusion vulnerability in styles/default/global_header.php in MyPHP CMS 0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the domain parameter.
by Kw3[R]Ln
CVE-2006-3543 EXPLOITDB text VERIFIED
Invision Power Board <2.x - SQL Injection
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB
by CrAzY CrAcKeR
EIP-2026-105524 EXPLOITDB text VERIFIED
Blog:CMS 4.1 - 'Thumb.php' Remote File Inclusion
by EllipSiS Security
CVE-2006-3422 EXPLOITDB text VERIFIED
WonderEdit Pro CMS - Remote File Inclusion via config[template_path] Parameter
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb (template/rwb/user_bottom.php), (2) gwb (template/rwb/user_bottom.php, (3) blues, (4) bluwhi, and (5) grns.
by OLiBekaS