Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-114491 EXPLOITDB text VERIFIED
Xtreme/Ditto News 1.0 - 'post.php' Remote File Inclusion
by Kacper
EIP-2026-111434 EXPLOITDB text VERIFIED
PostNuke 0.76 RC2 - Multiple Input Validation Vulnerabilities
by SpC-x
CVE-2006-2929 EXPLOITDB text VERIFIED
OpenEMR < 2.8.1 - Remote Code Execution via GLOBALS[fileroot] Parameter
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.
by Kacper
CVE-2006-3009 EXPLOITDB text VERIFIED
Open Business Management 1.0.3 pl1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
by r0t
CVE-2006-3009 EXPLOITDB text VERIFIED
Open Business Management 1.0.3 pl1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
by r0t
CVE-2006-3009 EXPLOITDB text VERIFIED
Open Business Management 1.0.3 pl1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
by r0t
CVE-2006-3009 EXPLOITDB text VERIFIED
Open Business Management 1.0.3 pl1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
by r0t
CVE-2006-3009 EXPLOITDB text VERIFIED
Open Business Management 1.0.3 pl1 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
by r0t
CVE-2006-2922 EXPLOITDB text VERIFIED
MiraksGalerie 2.62 - Remote File Inclusion via g_pcltar_lib_dir and listconfigfile Parameters
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2) listconfigfile[] parameter in (b) galsecurity.lib.php and (c) galimage.lib.php.
by Federico Fazzi
CVE-2006-2973 EXPLOITDB text VERIFIED
PHP Lite Calendar Express 2.2 - SQL Injection
Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.
by CrAzY CrAcKeR
CVE-2006-2888 EXPLOITDB text VERIFIED
Wikiwig - Remote File Inclusion via WK[wkPath] Parameter
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter.
by Kacper
CVE-2006-2892 EXPLOITDB text VERIFIED
GANTTy 1.0.3 - Cross-Site Scripting via Message Parameter
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action.
by Luny
CVE-2006-3637 EXPLOITDB text VERIFIED
Microsoft Internet Explorer <6 - RCE
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
by Kil13r
CVE-2006-2861 EXPLOITDB text VERIFIED
Particle Wiki <1.0.2 - SQL Injection
SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
by FarhadKey
CVE-2006-2883 EXPLOITDB text VERIFIED
Kmita FAQ 1.0 - Cross-Site Scripting via search.php q Parameter
Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
by Luny
CVE-2006-2884 EXPLOITDB text VERIFIED
Kmita FAQ 1.0 - SQL Injection via catid Parameter
SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by Luny
CVE-2006-2899 EXPLOITDB text VERIFIED
ESTsoft InternetDISK <2006/04/20 - RCE
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory.
by Kil13r
CVE-2006-2881 EXPLOITDB text VERIFIED
DreamAccount < 3.1 - Remote File Inclusion via da_path Parameter
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.inc.php, or (3) auth.sessions.inc.php scripts.
by Aesthetico
CVE-2006-2852 EXPLOITDB text VERIFIED
dotwidget_cms 1.0.6 - Remote Code Execution via file_path Parameter
PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php.
by Aesthetico
CVE-2006-2871 EXPLOITDB text VERIFIED
CyBoards PHP Lite 1.25 - Remote File Inclusion via script_path Parameter
PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. NOTE: CVE disputes this issue, since $script_path is set to a constant value
by SpC-x
CVE-2006-2867 EXPLOITDB text VERIFIED
CoolForum < 0.8.3_beta - SQL Injection via editpost.php Post Parameter
SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.
by DarkFig
CVE-2006-2877 EXPLOITDB text VERIFIED
Bookmark4U < 2.0 - Remote File Inclusion via include_prefix Parameter
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
by SnIpEr_SA
CVE-2006-2877 EXPLOITDB text VERIFIED
Bookmark4U < 2.0 - Remote File Inclusion via include_prefix Parameter
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
by SnIpEr_SA
CVE-2006-2877 EXPLOITDB text VERIFIED
Bookmark4U < 2.0 - Remote File Inclusion via include_prefix Parameter
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
by SnIpEr_SA
CVE-2006-2877 EXPLOITDB text VERIFIED
Bookmark4U < 2.0 - Remote File Inclusion via include_prefix Parameter
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
by SnIpEr_SA