Exploitdb Exploits
31,394 exploits tracked across all sources.
Softbiz Banner Exchange Script 1.0 - Cross-Site Scripting via City Parameter and PHPSESSID Cookie
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
by securityconnection
Softbiz Banner Exchange Script 1.0 - Cross-Site Scripting via City Parameter and PHPSESSID Cookie
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
by securityconnection
Softbiz Banner Exchange Script 1.0 - Cross-Site Scripting via City Parameter and PHPSESSID Cookie
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
by securityconnection
PHP ICalender 2.22 - 'index.php' Cross-Site Scripting
by Kurdish Security
NewsPHP 2006 PRO - Cross-Site Scripting via Index.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
by securityconnection
NewsPHP 2006 PRO - Cross-Site Scripting via Index.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
by securityconnection
NewsPHP 2006 PRO - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.
by securityconnection
GeekLog 1.4 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc, (2) polls/functions.inc, (3) spamx/BlackList.Examine.class.php, (4) spamx/DeleteComment.Action.class.php, (5) spamx/EditIPofURL.Admin.class.php, (6) spamx/MTBlackList.Examine.class.php, (7) spamx/MassDelete.Admin.class.php, (8) spamx/MailAdmin.Action.class.php, (9) spamx/MassDelTrackback.Admin.class.php, (10) spamx/EditHeader.Admin.class.php, (11) spamx/EditIP.Admin.class.php, (12) spamx/IPofUrl.Examine.class.php, (13) spamx/Import.Admin.class.php, (14) spamx/LogView.Admin.class.php, and (15) staticpages/functions.inc, in the plugins/ directory.
by Kw3[R]Ln
MyAds module 2.04jp for Xoops - SQL Injection via lid Parameter
SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbitrary SQL commands via the lid parameter.
by KeyCoder
RS Gallery2 1.11.2 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047.
by marriottvn
PHP/MySQL Classifieds - SQL Injection
SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter.
by Luny
MF Piadas 1.0 - Remote File Inclusion via Admin Page Parameter
PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.
by botan
MF Piadas 1.0 - Remote File Inclusion via Admin Page Parameter
PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.
by botan
Pearl For Mambo 1.6 - Remote File Inclusion via phpbb_root_path and GlobalSettings[templatesDirectory] Parameters
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php and the (2) GlobalSettings[templatesDirectory] parameter in multiple files in the "includes" directory including (b) adminSensored.php, (c) adminBoards.php, (d) adminAttachments.php, (e) adminAvatars.php, (f) adminBackupdatabase.php, (g) adminBanned.php, (h) adminForums.php, (i) adminPolls.php, (j) adminSmileys.php, (k) poll.php, and (l) move.php.
by Kw3[R]Ln
CrisoftRicette 1.0pre15b - Remote File Inclusion via crisoftricette Parameter
PHP remote file inclusion vulnerability in recipe/cookbook.php in CrisoftRicette 1.0pre15b allows remote attackers to execute arbitrary PHP code via a URL in the crisoftricette parameter.
by CrAzY.CrAcKeR
cPanel 10.8.1/10.8.2 - OnMouseover Cross-Site Scripting
by MexHackTeam.org
H-Sphere 2.5.1 - Multiple Cross-Site Scripting Vulnerabilities
by r0t
Open Guestbook 0.5 - SQL Injection via Offset Parameter
SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
by simo64
Open Guestbook 0.5 - Cross-Site Scripting via Title Parameter
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
by simo64
mvnforum 1.0 GA - Cross-Site Scripting via Member and Activatecode Parameters
Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters.
by r0t
CBSMS Mambo Module 1.0 - Remote File Inclusion via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
by Kw3[R]Ln
eNpaper1 - 'Root_Header.php' Remote File Inclusion
by almaster
cPanel < 10.8.2_current_118 - Cross-Site Scripting via File Parameter
Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
by preth00nker
ADODB 4.6/4.7 - 'Tmssql.php' Cross-Site Scripting
by Rodrigo Silva
By Source