Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-3374 EXPLOITDB text VERIFIED
randshop < 1.2 - Remote File Inclusion via index.php incl Parameter
PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.
by black-code
EIP-2026-111425 EXPLOITDB text VERIFIED
PostNuke 0.6x/0.7x - Multiple Cross-Site Scripting Vulnerabilities
by rgod
CVE-2006-3476 EXPLOITDB text VERIFIED
phpwebgallery - Cross-Site Scripting via comments.php Keyword Parameter
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
by iss4m
CVE-2006-3396 EXPLOITDB text VERIFIED
Galleria Mambo Module <= 1.0 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by sikunYuk
CVE-2006-3402 EXPLOITDB text VERIFIED
VirtuaStore 2.0 - SQL Injection via Login Password Parameter
SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in.
by supermalhacao
CVE-2006-3385 EXPLOITDB text VERIFIED
Vincent Leclercq News 5.2 - Cross-Site Scripting via divers.php id and disabled Parameters
Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.
by DarkFig
CVE-2006-3405 EXPLOITDB text VERIFIED
QTOFileManager 1.0 - Cross-Site Scripting via delete, pathext, or edit Parameters
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
by EllipSiS Security
CVE-2006-3562 EXPLOITDB text VERIFIED
plume_cms 1.0.4 - Remote Code Execution via _PX_config[manager_path] Parameter
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and versions than CVE-2006-2645 and CVE-2006-0725.
by CrAsh_oVeR_rIdE
CVE-2006-3363 EXPLOITDB text VERIFIED
Xoops Glossaire Module 1.7 - Remote File Inclusion via Index.php pa Parameter
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.
by CrAzY CrAcKeR
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3475 EXPLOITDB text VERIFIED
free_qboard 1.1 - Remote File Inclusion via qb_path Parameter
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.
by CrAsh_oVeR_rIdE
CVE-2006-3355 EXPLOITDB text VERIFIED
mpg123 - Heap-based Buffer Overflow via Long URL in httpdget.c
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.
by Horst Schirmeier
EIP-2026-115706 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - OutlookExpress.AddressBook Denial of Service
by hdm
CVE-2006-3361 EXPLOITDB text VERIFIED
stud.ip < 1.3.0-2 - Remote File Inclusion via _PHPLIB[libdir] or ABSOLUTE_PATH_STUDIP Parameter
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP parameter in studip-htdocs/archiv_assi.php.
by Hamid Ebadi
CVE-2006-3421 EXPLOITDB text VERIFIED
SmartSiteCMS < 1.0 - Remote File Inclusion via Root Parameter
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.
by CrAsh_oVeR_rIdE
CVE-2006-3375 EXPLOITDB text VERIFIED
Randshop 1.1.1 - Remote File Inclusion via dateiPfad Parameter
PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.
by OLiBekaS
CVE-2006-7021 EXPLOITDB text VERIFIED
Plume CMS 1.1.3 - Remote Code Execution via _PX_config[manager_path] Parameter
PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.
by Hamid Ebadi
CVE-2006-3763 EXPLOITDB text VERIFIED
Diesel Joke Site - SQL Injection via category.php id Parameter
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.
by black-code
CVE-2006-3353 EXPLOITDB text VERIFIED
Opera < 9.01 - Denial of Service via Crafted Web Page with Iframe and JavaScript
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to an iframe and JavaScript that accesses certain style sheets properties.
by y3dips
CVE-2006-3607 EXPLOITDB text VERIFIED
Softbiz Banner Exchange Script 1.0 - Cross-Site Scripting via City Parameter and PHPSESSID Cookie
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
by securityconnection