Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106362 EXPLOITDB text VERIFIED
Datecomm 1.1 - Multiple Cross-Site Scripting Vulnerabilities
by Luny
CVE-2006-3213 EXPLOITDB text VERIFIED
WeBBoA Hosting 1.1 - SQL Injection via id Parameter
SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter to an unspecified script, possibly host/yeni_host.asp.
by EntriKa
CVE-2006-3109 EXPLOITDB text VERIFIED
Cisco CallManager 3.3-4.3 - Cross-Site Scripting via ccmadmin/phonelist.asp and ccmuser/logon.asp
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.
by Jake Reynolds
CVE-2006-3109 EXPLOITDB text VERIFIED
Cisco CallManager 3.3-4.3 - Cross-Site Scripting via ccmadmin/phonelist.asp and ccmuser/logon.asp
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.
by Jake Reynolds
CVE-2006-3580 EXPLOITDB text VERIFIED
asp_stats_generator < 2.1.1 - SQL Injection via order Parameter
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.
by Hamid Ebadi
EIP-2026-110719 EXPLOITDB text VERIFIED
PHP Live Helper 1.x - 'abs_path' Remote File Inclusion
by SnIpEr_SA
CVE-2006-7017 EXPLOITDB text VERIFIED
Indexu 5.0.1 - Remote File Inclusion via admin_template_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3) app_mod_rewrite.php, (4) app_page_caching.php, (5) app_setup.php, (6) cat_add.php, (7) cat_delete.php, (8) cat_edit.php, (9) cat_path_update.php, (10) cat_search.php, (11) cat_struc.php, (12) cat_view.php, (13) cat_view_hidden.php, (14) cat_view_hierarchy.php, (15) cat_view_registered_only.php, (16) checkurl_web.php, (17) db_alter.php, (18) db_alter_change.php, (19) db_backup.php, (20) db_export.php, (21) db_import.php, (22) editor_add.php, (23) editor_delete.php, (24) editor_validate.php, (25) head.php, (26) index.php, (27) inv_config.php, (28) inv_config_payment.php, (29) inv_create.php, (30) inv_delete.php, (31) inv_edit.php, (32) inv_markpaid.php, (33) inv_markunpaid.php, (34) inv_overdue.php, (35) inv_paid.php, (36) inv_send.php, (37) inv_unpaid.php, (38) lang_modify.php, (39) link_add.php, (40) link_bad.php, (41) link_bad_delete.php, (42) link_checkurl.php, (43) link_delete.php, (44) link_duplicate.php, (45) link_edit.php, (46) link_premium_listing.php, (47) link_premium_sponsored.php, (48) link_search.php, (49) link_sponsored_listing.php, (50) link_validate.php, (51) link_validate_edit.php, (52) link_view.php, (53) log_search.php, (54) mail_modify.php, (55) menu.php, (56) message_create.php, (57) message_delete.php, (58) message_edit.php, (59) message_send.php, (60) message_subscriber.php, (61) message_view.php, (62) review_validate.php, (63) review_validate_edit.php, (64) summary.php, (65) template_active.php, (66) template_add_custom.php, (67) template_delete.php, (68) template_delete_file.php, (69) template_duplicate.php, (70) template_export.php, (71) template_import.php, (72) template_manager.php, (73) template_modify.php, (74) template_modify_file.php, (75) template_rename.php, (76) user_add.php, (77) user_delete.php, (78) user_edit.php, (79) user_search.php, and (80) whos.php.
by CrAsh_oVeR_rIdE
EIP-2026-103817 EXPLOITDB text VERIFIED
Sun iPlanet Messaging Server 5.2 HotFix 1.16 - Root Password Disclosure
by php0t
CVE-2006-3314 EXPLOITDB text VERIFIED
RahnemaCo.com eShop - Remote File Inclusion via page.php pageid Parameter
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter.
by CrAzY.CrAcKeR
CVE-2006-3185 EXPLOITDB text VERIFIED
CMS Faethon 1.3.2 - Remote File Inclusion via mainpath Parameter
PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter.
by M.Hasran Addahroni
EIP-2026-105917 EXPLOITDB text VERIFIED
Cline Communications - Multiple SQL Injections
by Liz0ziM
CVE-2006-3192 EXPLOITDB text VERIFIED
Ad Manager Pro 2.6 - Remote File Inclusion via ipath Parameter
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath parameter in common.php and (2) unspecified vectors in ad.php.
by Basti
CVE-2006-3175 EXPLOITDB text VERIFIED
mcGuestbook 1.3 - Remote Code Execution via Lang Parameter File Inclusion
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.
by SwEET-DeViL
CVE-2006-3175 EXPLOITDB text VERIFIED
mcGuestbook 1.3 - Remote Code Execution via Lang Parameter File Inclusion
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.
by SwEET-DeViL
CVE-2006-3175 EXPLOITDB text VERIFIED
mcGuestbook 1.3 - Remote Code Execution via Lang Parameter File Inclusion
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.
by SwEET-DeViL
EIP-2026-108091 EXPLOITDB text VERIFIED
Ji-takz - Remote File Inclusion
by SpC-x
EIP-2026-107827 EXPLOITDB text VERIFIED
Indexu 5.0.1 - Multiple Remote File Inclusions
by CrAsh_oVeR_rIdE
CVE-2006-3186 EXPLOITDB text VERIFIED
CMS Faethon 1.3.2 - Cross-Site Scripting via mainpath Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by K-159
EIP-2026-105439 EXPLOITDB text VERIFIED
Bee-hive 1.2 - Multiple Remote File Inclusions
by Kw3[R]Ln
CVE-2006-3101 EXPLOITDB text VERIFIED
Cisco Secure ACS for UNIX 2.3 - XSS
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.
by Thomas Liam Romanis
CVE-2006-3142 EXPLOITDB text VERIFIED
vbzoom 1.11 - SQL Injection via MainID Parameter
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.
by CrAsh_oVeR_rIdE
EIP-2026-112985 EXPLOITDB text VERIFIED
vBulletin 2.x/3.x - Multiple Cross-Site Scripting Vulnerabilities
by Luny
CVE-2006-3189 EXPLOITDB text VERIFIED
HotPlug CMS 1.0 - Cross-Site Scripting via msg Parameter
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by Federico Fazzi
CVE-2006-2914 EXPLOITDB text VERIFIED
DeluxeBB 1.06 - Remote File Inclusion via Templatefolder Parameter
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/ directory.
by Andreas Sandblad
CVE-2006-3653 EXPLOITDB text VERIFIED
Microsoft Works Spreadsheet 8.0 - Denial of Service via Crafted Spreadsheet Files
wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
by Benjamin Franz