Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-1783 EXPLOITDB text VERIFIED
PatroNet CMS - Cross-Site Scripting via URI
Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.
by Soothackers
EIP-2026-109686 EXPLOITDB text VERIFIED
MyBB 1.10 - 'member.php' Cross-Site Scripting
by o.y.6
CVE-2006-1683 EXPLOITDB text VERIFIED
Chipmunk Guestbook - SQL Injection via User Name Parameter
SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name.
by Dr.Jr7
CVE-2006-1711 EXPLOITDB text VERIFIED
Plone 2.0.5, 2.1.2, 2.5-beta1 - Unauthenticated Arbitrary Portrait Modification via Unrestricted Method Access
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
by MJ0011
CVE-2006-1709 EXPLOITDB text VERIFIED
interaktiv.shop < 5 - Cross-Site Scripting via pn or sbeg Parameters
Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters.
by r0t
CVE-2006-1771 EXPLOITDB text VERIFIED
SAXoTECH SAXoPRESS - Path Traversal
Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read arbitrary files and possibly execute arbitrary programs via a .. (dot dot) in the url parameter.
by SecuriTeam
CVE-2006-1768 EXPLOITDB text VERIFIED
Tritanium Bulletin Board 1.2.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.
by d4igoro
CVE-2006-1759 EXPLOITDB text VERIFIED
SWSoft Confixx 3.1.2 - Cross-Site Scripting via Jahr Parameter
Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.
by Snake_23
CVE-2006-1754 EXPLOITDB text VERIFIED
SWSoft Confixx <3.1.2 - SQL Injection
SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.
by LoK-Crew
CVE-2006-1773 EXPLOITDB text VERIFIED
phpkit < 1.6.1 - SQL Injection via contentid Parameter
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.
by Hamid Ebadi
CVE-2006-1760 EXPLOITDB text VERIFIED
JetPhoto - Cross-Site Scripting via Page or Name Parameter
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.
by 0o_zeus_o0
CVE-2006-1760 EXPLOITDB text VERIFIED
JetPhoto - Cross-Site Scripting via Page or Name Parameter
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.
by 0o_zeus_o0
CVE-2006-1760 EXPLOITDB text VERIFIED
JetPhoto - Cross-Site Scripting via Page or Name Parameter
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.
by 0o_zeus_o0
CVE-2006-1760 EXPLOITDB text VERIFIED
JetPhoto - Cross-Site Scripting via Page or Name Parameter
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.
by 0o_zeus_o0
CVE-2006-1767 EXPLOITDB text VERIFIED
nicecoder INDEXU 5.0.0-5.0.1 - Remote File Inclusion via theme_path and base_path Parameters
Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6) detail.php, (7) fav.php, (8) get_rated.php, (9) login.php, (10) mailing_list.php, (11) new.php, (12) modify.php, (13) pick.php, (14) power_search.php, (15) rating.php, (16) register.php, (17) review.php, (18) rss.php, (19) search.php, (20) send_pwd.php, (21) sendmail.php, (22) tell_friend.php, (23) top_rated.php, (24) user_detail.php, and (25) user_search.php; and the (26) base_path parameter in invoice.php.
by SnIpEr_SA
EIP-2026-106506 EXPLOITDB text VERIFIED
Dokeos 1.x - 'viewtopic.php' SQL Injection
by Alvaro Olavarria
CVE-2006-1718 EXPLOITDB text VERIFIED
Magus Perde Clever Copy <3.0 - Info Disclosure
Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc.
by M.Hasran Addahroni
CVE-2006-1770 EXPLOITDB text VERIFIED
Azerbaijan Design & Development Group AzDGVote - RCE
Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php.
by SnIpEr_SA
CVE-2006-0015 EXPLOITDB text VERIFIED
Microsoft FrontPage Server Extensions and SharePoint Team Services - Cross-Site Scripting via fpadmdll.dll Parameters
Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
by Esteban Martinez Fayo
CVE-2006-1758 EXPLOITDB text VERIFIED
Vegadns 0.99 - SQL Injection via cid Parameter
SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
by Ph03n1X
CVE-2006-1702 EXPLOITDB text VERIFIED
SPIP 1.8.3 - Remote File Inclusion via spip_login.php3 url Parameter
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
by cR45H3R
CVE-2006-1704 EXPLOITDB text VERIFIED
Sire 2.0 - Unauthenticated Arbitrary File Upload via upload.php
Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.
by simo64
CVE-2006-1706 EXPLOITDB text VERIFIED
Shopweezle 2.0 - SQL Injection via itemID, itemgr, brandID, or album Parameters
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
by r0t
CVE-2006-1706 EXPLOITDB text VERIFIED
Shopweezle 2.0 - SQL Injection via itemID, itemgr, brandID, or album Parameters
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
by r0t
CVE-2006-1706 EXPLOITDB text VERIFIED
Shopweezle 2.0 - SQL Injection via itemID, itemgr, brandID, or album Parameters
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
by r0t