Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-0143 EXPLOITDB text VERIFIED
Microsoft Windows 2000 and 2003 Server - Denial of Service via WMF File with Inconsistent Length Arguments
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
by cocoruder
CVE-2006-0030 EXPLOITDB text VERIFIED
Microsoft Excel <2003 - Code Injection
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
by ad@heapoverflow.com
CVE-2006-0198 EXPLOITDB text VERIFIED
XOOPS Pool Module - Stored Cross-Site Scripting via IMG SRC Attribute in Comment
Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.
by night_warrior771
CVE-2006-0160 EXPLOITDB text VERIFIED
Venom Board 1.22 - SQL Injection via parent root or topic_id Parameters
SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.
by Aliaksandr Hartsuyeu
CVE-2006-0185 EXPLOITDB text VERIFIED
Php-Nuke Pool and News Modules - Cross-Site Scripting via IMG Tag SRC Attribute
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
by night_warrior771
CVE-2006-0163 EXPLOITDB text VERIFIED
PHPNuke EV 7.7-R1 - SQL Injection via Search Module Query Parameter
SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792.
by Lostmon
CVE-2006-0125 EXPLOITDB text VERIFIED
AppServ 2.4.5 - Arbitrary File Inclusion via appserv_root Parameter
Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.
by Xez
CVE-2006-0153 EXPLOITDB text VERIFIED
427BB 2.2 and 2.2.1 - Authentication Bypass via Cookie Manipulation
427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.
by Aliaksandr Hartsuyeu
CVE-2006-0154 EXPLOITDB text VERIFIED
427BB 2.2-2.2.1 - SQL Injection via ForumID Parameter
SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.
by Aliaksandr Hartsuyeu
CVE-2006-0304 EXPLOITDB text VERIFIED
Dual DHCP DNS Server 1.0 - Buffer Overflow via DHCP Options Field
Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.
by Luigi Auriemma
CVE-2006-0103 EXPLOITDB text VERIFIED
TinyPHPForum <= 3.6 - Unauthenticated Exposure of Sensitive User Information via Web-Accessible Hash and Email Files
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
by Aliaksandr Hartsuyeu
CVE-2006-0135 EXPLOITDB text VERIFIED
TheWebForum < 1.2.1 - SQL Injection via Login Username Parameter
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
by Aliaksandr Hartsuyeu
CVE-2006-0110 EXPLOITDB text VERIFIED
Foro Domus 2.10 - Cross-Site Scripting via Email Parameter
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.
by Aliaksandr Hartsuyeu
CVE-2006-0115 EXPLOITDB text VERIFIED
OnePlug CMS - SQL Injection via Press_Release_ID, Service_ID, or Product_ID Parameter
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.
by Preddy
CVE-2006-0115 EXPLOITDB text VERIFIED
OnePlug CMS - SQL Injection via Press_Release_ID, Service_ID, or Product_ID Parameter
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.
by Preddy
CVE-2006-0115 EXPLOITDB text VERIFIED
OnePlug CMS - SQL Injection via Press_Release_ID, Service_ID, or Product_ID Parameter
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.
by Preddy
CVE-2005-3539 EXPLOITDB text VERIFIED
HylaFAX <= 4.2.3 - Remote Code Execution via Notify Script and CallID Parameter
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
by Patrice Fournier
CVE-2005-4622 EXPLOITDB text VERIFIED
efilego 3.01 - Directory Traversal and Arbitrary File Upload via Triple Dot in URL
Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.
by dr_insane
EIP-2026-111503 EXPLOITDB text VERIFIED
Primo Place Primo Cart 1.0 - Multiple SQL Injections
by r0t
EIP-2026-107824 EXPLOITDB text VERIFIED
INCOGEN Bugport 1.x - Multiple SQL Injections
by r0t
EIP-2026-107823 EXPLOITDB text VERIFIED
INCOGEN Bugport 1.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
by r0t
EIP-2026-103519 EXPLOITDB text VERIFIED
Intel Graphics Accelerator Driver - Remote Denial of Service
by Sumit Siddharth
CVE-2006-0079 EXPLOITDB text VERIFIED
ScozNet ScozBook BETA 1.1 - SQL Injection via Username Field
SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).
by Aliaksandr Hartsuyeu
CVE-2006-0073 EXPLOITDB text VERIFIED
DiscusWare Discus Freeware/Professional <3.10.5-3.10.4 - XSS
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by $um$id
CVE-2006-0066 EXPLOITDB text VERIFIED
phpjournaler 1.0 - SQL Injection via readold Parameter
SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.
by Aliaksandr Hartsuyeu