Exploitdb Exploits
31,394 exploits tracked across all sources.
Woltlab Burning Board 2.x - Multiple SQL Injections
by CrAzY CrAcKeR
The Bible Portal Project <2.12 - RCE
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the destination parameter.
by Kacper
RahnemaCo.com - Remote Code Execution
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter.
by Breeeeh
PhpBlueDragon CMS 2.9.1 - Remote File Inclusion via vsDragonRootPath Parameter
PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.
by Federico Fazzi
ISPConfig 2.2.3 - Remote File Inclusion via go_info Parameter
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.
by Federico Fazzi
Content-Builder (CMS) 0.7.2 - Multiple Include Vulnerabilities
by Kacper
Confixx 3.0/3.1 - 'FTP_index.php' Cross-Site Scripting
by kr4ch
MySQL <4.1.18, <5.0.19, <5.1.6 - DoS
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
by Kanatoko
Microsoft Internet Explorer <6 - RCE
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.
by Will Dormann
Simpnews 2.x - 'Wap_short_news.php' Remote File Inclusion
by SpC-x
Minerva 2.0.8a Build 237 and earlier - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Kacper
DoubleSpeak 0.1 - Remote File Inclusion via config[private] Parameter
PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and (3) hardware.php. NOTE: this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used
by R@1D3N
Event Registration - Cross-Site Scripting via Event ID or Select Events Parameter
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Luny
35mmslidegallery 6.0 - Cross-Site Scripting via imgdir w h and t Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
by black-cod3
35mmslidegallery 6.0 - Cross-Site Scripting via imgdir w h and t Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
by black-cod3
DCP-Portal SE 6.0 - Remote File Inclusion via Root Parameter
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
by Federico Fazzi
WinSCP 3.8.1 - Argument Injection via Encoded Spaces in SCP/SFTP URI
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
by Jelmer Kuperus
SixCMS < 6.0.6patch2 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.
by Aesthetico
SixCMS <6.0.6patch2 - Path Traversal
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
by Aesthetico
NPDS 5.10 - Multiple Input Validation Vulnerabilities
by DarkFig
iFusion iFlance 1.1 - Multiple Input Validation Vulnerabilities
by Luny
ifoto 0.20 - Cross-Site Scripting via Base64-Encoded File Parameter
Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.
by Luny
By Source