Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-7026 EXPLOITDB text VERIFIED
Aardvark Topsites PHP < 4.2.2 - Remote File Inclusion via CONFIG[path] Parameter
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector than CVE-2006-2149.
by [Oo]
CVE-2006-2228 EXPLOITDB text VERIFIED
w-Agora 4.2.0 - Cross-Site Scripting via BBCode Tag Event Bypass
Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) character, which bypasses a restrictive regular expression that attempts to remove onmouseover and other events.
by r0xes
CVE-2006-2143 EXPLOITDB text VERIFIED
TextFileBB 1.0.16 - Cross-Site Scripting via BBCode Tag Event Handlers
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.
by r0xes
CVE-2006-2116 EXPLOITDB text VERIFIED
planetGallery - Privilege Escalation
planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.
by tugr@
CVE-2006-2137 EXPLOITDB text VERIFIED
OpenPHPNuke < 2.3.3 - Remote File Inclusion via root_path Parameter
PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
by [Oo]
CVE-2006-2142 EXPLOITDB text VERIFIED
Limbo CMS <= 1.04 - Remote File Inclusion via classes_dir Parameter
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
by [Oo]
CVE-2006-2134 EXPLOITDB text VERIFIED
PHPbb 2.0.2 - Remote Code Execution
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by [Oo]
CVE-2006-2127 EXPLOITDB text VERIFIED
Blog Mod 0.2.x - SQL Injection via r Parameter
SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter.
by Qex
EIP-2026-104981 EXPLOITDB text VERIFIED
Advanced Guestbook 2.x - 'Addentry.php' Remote File Inclusion
by [Oo]
CVE-2006-2214 EXPLOITDB text VERIFIED
4images < 1.7.2 - SQL Injection via Session ID Parameter
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
by CrAzY.CrAcKeR
CVE-2006-2214 EXPLOITDB text VERIFIED
4images < 1.7.2 - SQL Injection via Session ID Parameter
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
by CrAzY.CrAcKeR
CVE-2006-2101 EXPLOITDB text VERIFIED
WinISO 5.3 - Directory Traversal and Arbitrary File Write via ISO Image Filename
Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
by Sowhat
CVE-2006-2102 EXPLOITDB text VERIFIED
PowerISO 2.9 - Directory Traversal and Arbitrary File Write via ISO Image Filename
Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
by Sowhat
CVE-2006-2100 EXPLOITDB text VERIFIED
Magic ISO Maker < 5.0_build_0166 - Directory Traversal and Arbitrary File Write via ISO Image Filename
Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
by Sowhat
CVE-2006-2099 EXPLOITDB text VERIFIED
UltraISO 8.0.0.1392 - Directory Traversal and Arbitrary File Write via ISO Image Filename
Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
by Sowhat
CVE-2006-2119 EXPLOITDB text VERIFIED
Artmedic Event - Remote File Inclusion via Page Parameter
PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.
by botan
CVE-2006-2152 EXPLOITDB text VERIFIED
phpBB Advanced Guestbook <2.4.0 - RCE
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
by [Oo]
CVE-2006-1864 EXPLOITDB text VERIFIED
Linux Kernel <= 2.6.16 - Directory Traversal via SMB Chroot Escape
Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.
by Marcel Holtmann
CVE-2006-1863 EXPLOITDB text VERIFIED
Linux Kernel < 2.6.17 - Directory Traversal via CIFS Chroot Escape
Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.
by Marcel Holtmann
CVE-2006-2025 EXPLOITDB text VERIFIED
libtiff < 3.8.1 - Denial of Service and Possible Remote Code Execution via TIFFFetchData Integer Overflow
Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.
by Tavis Ormandy
CVE-2006-2024 EXPLOITDB text VERIFIED
libtiff < 3.8.1 - Denial of Service via TIFF Image Parsing Errors
Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.
by Tavis Ormandy
CVE-2006-2138 EXPLOITDB text VERIFIED
NeoMail 1.29 - Cross-Site Scripting via Session ID Parameter
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
by O.U.T.L.A.W
CVE-2006-2132 EXPLOITDB text VERIFIED
DUclassified - SQL Injection via iPro Parameter
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by sadegh.sarshogh
CVE-2006-2111 EXPLOITDB text VERIFIED
Microsoft Outlook Express 6 - Exposure of Sensitive Information via MHTML URI Handler
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."
by codedreamer
CVE-2006-2151 EXPLOITDB text VERIFIED
phpBB TopList < 1.3.8 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
by [Oo]