Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-1582 EXPLOITDB text VERIFIED
Blank'N'Berg 0.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter. NOTE: this might be resultant from the directory traversal issue.
by Amine ABOUD
CVE-2006-1593 EXPLOITDB text VERIFIED
Zdaemon < 1.08.01 and X-Doom - Denial of Service via Invalid Player Slot or Item Number
The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.
by Luigi Auriemma
CVE-2006-1567 EXPLOITDB text VERIFIED
SiteSearch Indexer < 3.5 - Cross-Site Scripting via searchField Parameter
Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.
by r0t
CVE-2006-1557 EXPLOITDB text VERIFIED
X-Changer 0.2 - SQL Injection via From/Into/ID Parameters
Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.
by Morocco Security Team
CVE-2006-1543 EXPLOITDB text VERIFIED
VNews 1.2 - SQL Injection via loginvar Parameter
Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.
by Aliaksandr Hartsuyeu
CVE-2006-1572 EXPLOITDB text VERIFIED
Oxygen 1.1.3 - SQL Injection via fid Parameter in newthread Action
SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.
by Morocco Security Team
CVE-2006-1573 EXPLOITDB text VERIFIED
MediaSlash Gallery - Remote File Inclusion via rub Parameter
PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).
by Morocco Security Team
CVE-2006-1535 EXPLOITDB text VERIFIED
Phoetux.net PhxContacts <0.93.1 - XSS
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.
by DaBDouB-MoSiKaR
CVE-2006-1536 EXPLOITDB text VERIFIED
Phoetux.net PhxContacts <0.93.1 - SQL Injection
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.
by Morocco Security Team
CVE-2006-1536 EXPLOITDB text VERIFIED
Phoetux.net PhxContacts <0.93.1 - SQL Injection
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.
by Morocco Security Team
CVE-2006-1490 EXPLOITDB text VERIFIED
PHP - Information Disclosure via html_entity_decode Binary Data Handling
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.
by Samuel
CVE-2006-1425 EXPLOITDB text VERIFIED
phpmyfamily 1.4.1 - Cross-Site Scripting via Track.php Name Parameter
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
by matrix_killer
CVE-2006-1428 EXPLOITDB text VERIFIED
phpCOIN <= 1.2.2 - Cross-Site Scripting via fs Parameter
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
by r0t
CVE-2006-1428 EXPLOITDB text VERIFIED
phpCOIN <= 1.2.2 - Cross-Site Scripting via fs Parameter
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
by r0t
CVE-2006-1501 EXPLOITDB text VERIFIED
OneOrZero 1.6.3.0 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.
by Preddy
CVE-2006-1430 EXPLOITDB text VERIFIED
controlzx/hms < 3.3.4 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.
by r0t
CVE-2006-1430 EXPLOITDB text VERIFIED
controlzx/hms < 3.3.4 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.
by r0t
CVE-2006-1430 EXPLOITDB text VERIFIED
controlzx/hms < 3.3.4 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.
by r0t
CVE-2006-1508 EXPLOITDB text VERIFIED
MH Software Connect Daily Web Calendar Software <3.2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.
by r0t
CVE-2006-1508 EXPLOITDB text VERIFIED
MH Software Connect Daily Web Calendar Software <3.2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.
by r0t
CVE-2006-1508 EXPLOITDB text VERIFIED
MH Software Connect Daily Web Calendar Software <3.2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.
by r0t
CVE-2006-1508 EXPLOITDB text VERIFIED
MH Software Connect Daily Web Calendar Software <3.2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.
by r0t
CVE-2006-1508 EXPLOITDB text VERIFIED
MH Software Connect Daily Web Calendar Software <3.2.9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.
by r0t
CVE-2006-1504 EXPLOITDB text VERIFIED
Arab Portal 2.0 - Cross-Site Scripting via Title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.
by o.y.6
CVE-2006-1504 EXPLOITDB text VERIFIED
Arab Portal 2.0 - Cross-Site Scripting via Title Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.
by o.y.6