Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105215 EXPLOITDB text VERIFIED
AR-Blog 5.2 - Multiple Cross-Site Scripting Vulnerabilities
by black-code
EIP-2026-100497 EXPLOITDB text VERIFIED
PrideForum 1.0 - 'forum.asp' SQL Injection
by ajann
EIP-2026-119401 EXPLOITDB text VERIFIED
MDaemon WebAdmin 2.0.x - SQL Injection
by KOUSULIN
EIP-2026-115704 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6 - Malformed HTML Parsing Denial of Service (2)
by Thomas Waldegger
CVE-2006-2645 EXPLOITDB text VERIFIED
Plume CMS 1.0.3 - Remote Code Execution via _PX_config[manager_path] Parameter
PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-0725.
by beford
EIP-2026-106488 EXPLOITDB text VERIFIED
DoceboLms 2.0.x - 'Lang' Multiple Remote File Inclusions
by beford
CVE-2006-2656 EXPLOITDB text VERIFIED
libtiff < 3.8.2 - Stack-based Buffer Overflow via Long Filename
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
by nitr0us
CVE-2006-2638 EXPLOITDB text VERIFIED
qjforum - SQL Injection via uName Parameter
SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter.
by ajann
CVE-2006-2665 EXPLOITDB text VERIFIED
v-webmail < 1.6.4 - Remote File Inclusion via CONFIG[pear_dir] Parameter
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.
by beford
CVE-2006-2666 EXPLOITDB text VERIFIED
v-webmail 1.5-1.6.4 - Remote Code Execution via CONFIG[pear_dir] Parameter
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.
by beford
CVE-2006-2681 EXPLOITDB text VERIFIED
SocketMail Lite and Pro < 2.2.6 - Remote Code Execution via site_path Parameter
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) inc-common.php.
by Aesthetico
CVE-2006-2683 EXPLOITDB text VERIFIED
open-medium_cms 0.25 - Remote File Inclusion via REDSYS[MYPATH][TEMPLATES] Parameter
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.
by Kacper
CVE-2006-2061 EXPLOITDB text VERIFIED
Invision Power Board 2.0.x-2.1.x - SQL Injection via ck Parameter
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.
by IceShaman
CVE-2006-2668 EXPLOITDB text VERIFIED
Docebo LMS <2.05 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.php.
by beford
CVE-2006-2685 EXPLOITDB text VERIFIED
Basic Analysis and Security Engine <= 1.2.4 - Remote Code Execution via BASE_path Parameter
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (2) base_stat_common.php, and (3) includes/base_include.inc.php.
by str0ke
CVE-2006-2682 EXPLOITDB text VERIFIED
Back-End CMS 0.7.2.1 - Remote File Inclusion via _PSL[classdir] Parameter
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter.
by Kacper
CVE-2006-2686 EXPLOITDB text VERIFIED
ActionApps 2.8.1 - Remote Code Execution via GLOBALS[AA_INC_PATH] Parameter
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.
by Kacper
CVE-2006-2797 EXPLOITDB text VERIFIED
phpCommunityCalendar 4.0.3 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4) EventLocationID parameter in (f) delAddress.php; and (5) LocationID parameter in (g) delCategory.php.
by X0r_1
CVE-2006-2576 EXPLOITDB text VERIFIED
Docebo < 3.0.3 - Remote File Inclusion via GLOBALS Overwrite
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) lib.simplesel.php, (b) lib.filelist.php, (c) tree.documents.php, (d) lib.repo.php, and (e) lib.php, and (2) GLOBALS[where_scs] to (f) lib.teleskill.php. NOTE: this issue might be resultant from a global overwrite vulnerability.
by Kacper
CVE-2006-2798 EXPLOITDB text VERIFIED
phpCommunityCalendar 4.0.3 - Cross-Site Scripting via LoName and AddressLink Parameters
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php.
by X0r_1
EIP-2026-106489 EXPLOITDB text VERIFIED
DoceboLms 2.0.x/3.0.x / DoceboKms 3.0.3 / Docebo CMS 3.0.x - Multiple Remote File Inclusions
by Kacper
CVE-2006-2577 EXPLOITDB text VERIFIED
Docebo < 3.0.3 - Remote File Inclusion via Multiple PHP Parameters
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) where_cms, (2) where_lms, (3) where_upgrade, (4) BBC_LIB_PATH, and (5) BBC_LANGUAGE_PATH parameters in various unspecified scripts. NOTE: the provenance of some of this information is unknown; the details are obtained solely from third party information.
by Kacper
CVE-2006-2680 EXPLOITDB text VERIFIED
AZ Photo Album Script Pro - Cross-Site Scripting via gazpart Parameter
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.
by Luny
CVE-2006-2587 EXPLOITDB text VERIFIED
PunkBuster < 1.229 - Buffer Overflow via WebTool HTTP Server Webkey Parameter
Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5) Battlefield Vietnam 1.150 and earlier, (6) Call of Duty 1.173 and earlier, (7) Call of Duty 2 1.108 and earlier, (8) DOOM 3 1.159 and earlier, (9) Enemy Territory 1.167 and earlier, (10) Far Cry 1.150 and earlier, (11) F.E.A.R. 1.093 and earlier, (12) Joint Operations 1.187 and earlier, (13) Quake III Arena 1.150 and earlier, (14) Quake 4 1.181 and earlier, (15) Rainbow Six 3: Raven Shield 1.169 and earlier, (16) Rainbow Six 4: Lockdown 1.093 and earlier, (17) Return to Castle Wolfenstein 1.175 and earlier, and (18) Soldier of Fortune II 1.183 and earlier allows remote attackers to cause a denial of service (application crash) via a long webkey parameter.
by Luigi Auriemma
CVE-2006-2575 EXPLOITDB text VERIFIED
NetPanzer 0.8 and earlier - Denial of Service via setFrame Function
The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (crash) via a client flag (frameNum) that is greater than 41, which triggers an assert error.
by Luigi Auriemma