Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-0757 EXPLOITDB text VERIFIED
HiveMail <= 1.3 - Remote Code Execution via Eval Injection in Multiple Parameters
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.
by GulfTech Security
CVE-2006-0717 EXPLOITDB text VERIFIED
IBM Tivoli Directory Server 6.0 - Denial of Service via Crafted LDAP Request
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
by Evgeny Legerov
CVE-2006-0564 EXPLOITDB text VERIFIED
Microsoft HTML Help Workshop 4.74.8702.0 - Stack-based Buffer Overflow via Long Contents File Field
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
by darkeagle
CVE-2006-0660 EXPLOITDB text VERIFIED
FarsiNews 2.5 - Directory Traversal and Arbitrary File Read via Archive Parameter
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.
by Hamid Ebadi
CVE-2006-0663 EXPLOITDB text VERIFIED
IBM Lotus Domino iNotes Client 6.5.4 and 7.0 - Cross-Site Scripting via Email Subject, URI, or Attachment Filename
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java&#13;script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
by Jakob Balle
CVE-2006-0663 EXPLOITDB text VERIFIED
IBM Lotus Domino iNotes Client 6.5.4 and 7.0 - Cross-Site Scripting via Email Subject, URI, or Attachment Filename
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java&#13;script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
by Jakob Balle
EIP-2026-110469 EXPLOITDB text VERIFIED
Papoo 2.1.x - Multiple Cross-Site Scripting Vulnerabilities
by Dj Eyes
CVE-2006-0651 EXPLOITDB text VERIFIED
vwdev - SQL Injection via UID Parameter
SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.
by Omid Aghababaei
CVE-2006-0625 EXPLOITDB text VERIFIED
SPIP 1.8.2g - Directory Traversal and Remote Code Execution via GLOBALS[type_urls] Parameter
Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.
by rgod
CVE-2006-0650 EXPLOITDB text VERIFIED
CPAINT < 2.0.3 - Cross-Site Scripting via cpaint_response_type Parameter
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.
by GulfTech Security
CVE-2006-0647 EXPLOITDB text VERIFIED
Sun Java System Directory Server 5.2 - Denial of Service via Crafted Subtree Search Request
LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.
by Evgeny Legerov
CVE-2006-0624 EXPLOITDB text VERIFIED
Whomp Real Estate Manager XP 2005 - SQL Injection via Username and Password Parameters
SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
by night_warrior771
CVE-2005-1528 EXPLOITDB text VERIFIED
QNX Neutrino RTOS 6.2.1 - Local Privilege Escalation
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.
by anonymous
EIP-2026-109684 EXPLOITDB text VERIFIED
MyBB 1.0.3 - 'moderation.php' SQL Injection
by imei
EIP-2026-106988 EXPLOITDB text VERIFIED
eyeOS 0.8.x - Session Remote Command Execution
by GulfTech Security
CVE-2006-0669 EXPLOITDB text VERIFIED
GA's Forum Light - SQL Injection via Forum and Pages Parameters
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments
by Dj_Eyes
CVE-2006-0513 EXPLOITDB text VERIFIED
IBM Tivoli Access Manager for e-business 5.1 - Directory Traversal via pkmslogout Filename Parameter
Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
by Timothy D. Morgan
EIP-2026-106206 EXPLOITDB text VERIFIED
cPanel 10.8.1 - Multiple Cross-Site Scripting Vulnerabilities
by Simo Ben Youssef
CVE-2006-0532 EXPLOITDB text VERIFIED
SoftMaker Shop - Cross-Site Scripting via resultat.asp strSok Parameter
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.
by preben@watchcom.no
CVE-2006-0534 EXPLOITDB text VERIFIED
CyberShop Ultimate E-commerce - Cross-Site Scripting via ortak or kat Parameter
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.
by B3g0k
EIP-2026-112990 EXPLOITDB text VERIFIED
vBulletin 3.5.2 - Event Title HTML Injection
by trueend5
CVE-2006-0491 EXPLOITDB text VERIFIED
szusermgnt 1.4 - SQL Injection via Username Parameter
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.
by Aliaksandr Hartsuyeu
EIP-2026-112387 EXPLOITDB text VERIFIED
SPIP 1.8/1.9 - Multiple SQL Injections
by Siegfried
CVE-2006-0518 EXPLOITDB text VERIFIED
SPIP < 1.8.2e - Cross-Site Scripting via Lang Parameter
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
by Siegfried
CVE-2006-0539 EXPLOITDB text VERIFIED
fcron 3.0.0 - Local Privilege Escalation via Long Command-Line Argument
The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can "overwrite some data."
by Adam Zabrocki