Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
CVE-2006-2811 EXPLOITDB text VERIFIED
Cantico Ovidentia 5.8.0 - Remote File Inclusion via babInstallPath Parameter
Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.
by black-cod3
EIP-2026-109746 EXPLOITDB text VERIFIED
MyBloggie 2.1.x - 'MyBloggie_Root_Path' Remote File Inclusion
by sh3ll
CVE-2006-2818 EXPLOITDB text VERIFIED
Cameron McKay Informium 0.12.0 - RCE
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONF[local_path] parameter.
by Kacper
CVE-2006-2819 EXPLOITDB text VERIFIED
barnraiser igloo < 0.1.9 - Remote File Inclusion via Wiki.php c_node[class_path] Parameter
PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c_node[class_path] parameter.
by Kacper
CVE-2006-2821 EXPLOITDB text VERIFIED
DeltaScripts Pro Publish - Cross-Site Scripting via artid or catname Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
by Soot
CVE-2003-1292 EXPLOITDB text VERIFIED
ashNews 0.83 - Remote File Inclusion via pathtoashnews Parameter
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.
by Kacper
CVE-2006-2858 EXPLOITDB text VERIFIED
LocazoList Classifieds 1.05e - SQL Injection
SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter.
by ajann
CVE-2006-2873 EXPLOITDB text VERIFIED
Enigma Haber 4.2 - Cross-Site Scripting via il Parameter
Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber 4.2 allows remote attackers to inject arbitrary web script or HTML via the il parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by The_BeKiR
CVE-2006-2817 EXPLOITDB text VERIFIED
tekno.portal - SQL Injection via bolum.php id Parameter
SQL injection vulnerability in bolum.php in tekno.Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by SpC-x
CVE-2006-3395 EXPLOITDB text VERIFIED
SiteBuilder-FX 3.5 - Remote Code Execution via admindir Parameter
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.
by MazaGi
CVE-2006-2849 EXPLOITDB text VERIFIED
Bytehoard 2.1 Epsilon/Delta - Remote File Inclusion via bhconfig[bhfilepath] Parameter
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.
by beford
CVE-2006-2841 EXPLOITDB text VERIFIED
AssoCIateD CMS 1.1.3 - Remote File Inclusion via root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) menu.php, (2) profile.php, (3) users.php, (4) cache_mngt.php, and (5) gallery_functions.php.
by Kacper
CVE-2006-2853 EXPLOITDB text VERIFIED
abarcar Realty Portal 5.1.5 - SQL Injection
SQL injection vulnerability in content.php in abarcar Realty Portal 5.1.5 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by SpC-x
CVE-2006-2766 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6.0-6.0 SP2 - Denial of Service via Long mhtml URI in URL File
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
by Mr.Niega
CVE-2006-2805 EXPLOITDB text VERIFIED
vBulletin 3.0.10 - SQL Injection via FeatureID Parameter
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
by SpC-x
EIP-2026-112729 EXPLOITDB text VERIFIED
ToendaCMS 0.7 - 'index.php' Cross-Site Scripting
by Jokubas
CVE-2006-2747 EXPLOITDB text VERIFIED
PhpMyDesktop|arcade < 1.0_final - Directory Traversal and Arbitrary File Read via Subsite Parameter
Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.
by darkgod
CVE-2006-2767 EXPLOITDB text VERIFIED
Ottoman 1.1.2 - Remote Code Execution via Default Path Parameter
PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the default_path parameter in (1) error.php, (2) index.php, and (3) classes/main_class.php.
by Kacper
EIP-2026-110407 EXPLOITDB text VERIFIED
osTicket 1.x - 'Open_form.php' Remote File Inclusion
by Sweet
CVE-2006-2768 EXPLOITDB text VERIFIED
METAjour 2.1 - Remote File Inclusion via system_path Parameter
PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) system_path parameter in a large number of files in the (a) app/edocument/, (b) app/eproject/, (c) app/erek/, and (d) extension/ directories, and the (2) GLOBALS[system_path] parameter in (e) extension/sitemap/sitemap.datatype.php.
by Kacper