Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-2255 EXPLOITDB text VERIFIED
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
CVE-2006-2255 EXPLOITDB text VERIFIED
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
CVE-2006-2255 EXPLOITDB text VERIFIED
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
CVE-2006-1959 EXPLOITDB text VERIFIED
ActualScripts ActualAnalyzer Lite <2.72, Gold <7.63, Server <8.23 -...
PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.
by Aesthetico
CVE-2006-2264 EXPLOITDB text VERIFIED
Calendar Manager Pro 1.00 - SQL Injection via Date, SearchFor, or ID Parameter
Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by dj_eyes2005
CVE-2006-2264 EXPLOITDB text VERIFIED
Calendar Manager Pro 1.00 - SQL Injection via Date, SearchFor, or ID Parameter
Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by dj_eyes2005
CVE-2006-2265 EXPLOITDB text VERIFIED
Ocean12 Calendar Manager Pro 1.00 - Cross-Site Scripting via Date Parameter
Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by dj_eyes2005
CVE-2006-2264 EXPLOITDB text VERIFIED
Calendar Manager Pro 1.00 - SQL Injection via Date, SearchFor, or ID Parameter
Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by dj_eyes2005
CVE-2006-2256 EXPLOITDB text VERIFIED
EQdkp 1.3.0 - Remote File Inclusion via eqdkp_root_path Parameter
PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path parameter.
by OLiBekaS
CVE-2006-2261 EXPLOITDB text VERIFIED
ACal 2.2.6 - Remote File Inclusion via day.php path Parameter
PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by PiNGuX
CVE-2006-2269 EXPLOITDB text VERIFIED
myWebland MyBloggie <= 2.1.3 - Cross-Site Scripting via BBCode img Tag
Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.
by zerogue
CVE-2006-2263 EXPLOITDB text VERIFIED
VP-ASP 6.00 - SQL Injection via shopcurrency.asp cid Parameter
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
by tracewar
CVE-2006-1172 EXPLOITDB text VERIFIED
Cryptomathic Cenroll ActiveX Control 1.1.0.0 - Buffer Overflow
Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature.
by Dennis Rand
CVE-2006-7055 EXPLOITDB text VERIFIED
TotalCalendar < 2.30 - Remote File Inclusion via inc_dir Parameter
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
by Aesthetico
CVE-2006-2249 EXPLOITDB text VERIFIED
CuteNews < 1.4.1 - Cross-Site Scripting via Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
by NST
CVE-2006-2217 EXPLOITDB text VERIFIED
Invision Power Board - SQL Injection via Reputation Action PID Parameter
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by almaster
CVE-2006-2233 EXPLOITDB text VERIFIED
BankTown Client Control - Buffer Overflow via SetBannerUrl
Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBannerUrl. NOTE: portions of these details are obtained from third party information.
by Gyu Tae
CVE-2006-2176 EXPLOITDB text VERIFIED
PHP Linkliste 1.0b - Cross-Site Scripting via new_input, new_url, or new_name Parameter
Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter.
by d4igoro
CVE-2006-2209 EXPLOITDB text VERIFIED
PHP Arena paCheckBook 1.1 - SQL Injection via transtype or entry Parameter
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by almaster
CVE-2006-2208 EXPLOITDB text VERIFIED
MyNews 1.6.2 - Cross-Site Scripting via Hash and Page Parameters
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.
by DreamLord
CVE-2006-2241 EXPLOITDB text VERIFIED
Fast Click SQL Lite <= 1.1.3 - Remote File Inclusion via show.php path Parameter
PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a different vulnerability than CVE-2006-2175.
by R@1D3N
CVE-2006-2210 EXPLOITDB text VERIFIED
321soft php-gallery 0.9 - Cross-Site Scripting via Path Parameter
Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.
by d4igoro
CVE-2006-2211 EXPLOITDB text VERIFIED
321soft php-gallery 0.9 - Absolute Path Traversal via Index.php Path Parameter
Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.
by d4igoro
CVE-2006-2224 EXPLOITDB text VERIFIED
Quagga Routing Software Suite < 0.99.3 - Unauthenticated Routing State Modification via RIPv1 RESPONSE Packets
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
by Konstantin V. Gavrilenko
CVE-2006-2223 EXPLOITDB text VERIFIED
Quagga 0.98-0.99 - Unauthenticated Routing State Exposure via RIPv1 REQUEST Packets
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.
by Konstantin V. Gavrilenko