Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113463 EXPLOITDB text VERIFIED
Woltlab Burning Board 2.x - Multiple SQL Injections
by CrAzY CrAcKeR
CVE-2006-3177 EXPLOITDB text VERIFIED
The Bible Portal Project <2.12 - RCE
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the destination parameter.
by Kacper
CVE-2006-3315 EXPLOITDB text VERIFIED
RahnemaCo.com - Remote Code Execution
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter.
by Breeeeh
EIP-2026-110939 EXPLOITDB text VERIFIED
phpBB - 'BBRSS.php' Remote File Inclusion
by SpC-x
CVE-2006-3076 EXPLOITDB text VERIFIED
PhpBlueDragon CMS 2.9.1 - Remote File Inclusion via vsDragonRootPath Parameter
PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.
by Federico Fazzi
CVE-2006-3042 EXPLOITDB text VERIFIED
ISPConfig 2.2.3 - Remote File Inclusion via go_info Parameter
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.
by Federico Fazzi
EIP-2026-106145 EXPLOITDB text VERIFIED
Content-Builder (CMS) 0.7.2 - Multiple Include Vulnerabilities
by Kacper
EIP-2026-106132 EXPLOITDB text VERIFIED
Confixx 3.0/3.1 - 'FTP_index.php' Cross-Site Scripting
by kr4ch
CVE-2006-3081 EXPLOITDB text VERIFIED
MySQL <4.1.18, <5.0.19, <5.1.6 - DoS
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
by Kanatoko
CVE-2006-2383 EXPLOITDB text VERIFIED
Microsoft Internet Explorer <6 - RCE
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.
by Will Dormann
EIP-2026-113032 EXPLOITDB text VERIFIED
VBZoom 1.0/1.1 - Multiple SQL Injections
by CrAzY CrAcKeR
EIP-2026-112167 EXPLOITDB text VERIFIED
Simpnews 2.x - 'Wap_short_news.php' Remote File Inclusion
by SpC-x
CVE-2006-3028 EXPLOITDB text VERIFIED
Minerva 2.0.8a Build 237 and earlier - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Kacper
CVE-2006-3069 EXPLOITDB text VERIFIED
DoubleSpeak 0.1 - Remote File Inclusion via config[private] Parameter
PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and (3) hardware.php. NOTE: this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used
by R@1D3N
CVE-2006-3052 EXPLOITDB text VERIFIED
Event Registration - Cross-Site Scripting via Event ID or Select Events Parameter
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Luny
EIP-2026-105335 EXPLOITDB text VERIFIED
aWebNews 1.5 - 'visview.php' Remote File Inclusion
by SpC-x
CVE-2006-3036 EXPLOITDB text VERIFIED
35mmslidegallery 6.0 - Cross-Site Scripting via imgdir w h and t Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
by black-cod3
CVE-2006-3036 EXPLOITDB text VERIFIED
35mmslidegallery 6.0 - Cross-Site Scripting via imgdir w h and t Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
by black-cod3
CVE-2006-4837 EXPLOITDB text VERIFIED
DCP-Portal SE 6.0 - Remote File Inclusion via Root Parameter
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
by Federico Fazzi
CVE-2006-3015 EXPLOITDB text VERIFIED
WinSCP 3.8.1 - Argument Injection via Encoded Spaces in SCP/SFTP URI
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
by Jelmer Kuperus
CVE-2006-3051 EXPLOITDB text VERIFIED
SixCMS < 6.0.6patch2 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.
by Aesthetico
CVE-2006-3050 EXPLOITDB text VERIFIED
SixCMS <6.0.6patch2 - Path Traversal
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
by Aesthetico
EIP-2026-109968 EXPLOITDB text VERIFIED
NPDS 5.10 - Multiple Input Validation Vulnerabilities
by DarkFig
EIP-2026-107764 EXPLOITDB text VERIFIED
iFusion iFlance 1.1 - Multiple Input Validation Vulnerabilities
by Luny
CVE-2006-3006 EXPLOITDB text VERIFIED
ifoto 0.20 - Cross-Site Scripting via Base64-Encoded File Parameter
Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.
by Luny