Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3594 EXPLOITDB text VERIFIED
AdventNet ManageEngine OpManager 6-7 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.
by Lostmon
CVE-2007-3582 EXPLOITDB text VERIFIED
SuperCali PHP Event Calendar 0.4.0 - SQL Injection via o Parameter
SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter.
by t0pP8uZz
CVE-2006-3562 EXPLOITDB text VERIFIED
plume_cms 1.0.4 - Remote Code Execution via _PX_config[manager_path] Parameter
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and versions than CVE-2006-2645 and CVE-2006-0725.
by CrAsh_oVeR_rIdE
CVE-2006-3562 EXPLOITDB text VERIFIED
plume_cms 1.0.4 - Remote Code Execution via _PX_config[manager_path] Parameter
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and versions than CVE-2006-2645 and CVE-2006-0725.
by CrAsh_oVeR_rIdE
CVE-2007-3583 EXPLOITDB text VERIFIED
girlserv_ads < 1.5 - SQL Injection via idnew Parameter
SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter.
by Cold Zero
CVE-2007-3011 EXPLOITDB text VERIFIED
Fujitsu-Siemens Computers ServerView <4.50.09 - Command Injection
The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.
by RedTeam Pentesting GmbH
CVE-2010-0416 EXPLOITDB text VERIFIED
Helix Player and RealPlayer - Buffer Overflow via Malformed URL Percent Encoding
Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.
by gwright
CVE-2007-3569 EXPLOITDB text VERIFIED
Oliver Library Management System - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) "Basic Search page"; and (8) username parameter when (c) logging on.
by A. R.
CVE-2007-3530 EXPLOITDB text VERIFIED
PHPDirector <0.21 - Info Disclosure
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.
by Kw3[R]Ln
CVE-2007-3529 EXPLOITDB text VERIFIED
PHPDirector <0.21 - Info Disclosure
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.
by Kw3[R]Ln
CVE-2007-3518 EXPLOITDB text VERIFIED
hispah youtube_clone_script - SQL Injection via msg.php id Parameter
SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.
by t0pP8uZz
CVE-2006-3142 EXPLOITDB text VERIFIED
vbzoom 1.11 - SQL Injection via MainID Parameter
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.
by Cold Zero
CVE-2007-3562 EXPLOITDB text VERIFIED
PHP Director < 0.21 - SQL Injection via Videos.php ID Parameter
SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Kw3[R]Ln
CVE-2007-3555 EXPLOITDB text VERIFIED
Moodle 1.7.1 - Cross-Site Scripting via Search Parameter Style Expression
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.
by MustLive
CVE-2007-3556 EXPLOITDB text VERIFIED
Liesbeth base CMS - Info Disclosure
Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.
by durito
CVE-2007-3517 EXPLOITDB text VERIFIED
Claroline 1.8.3 - Cross-Site Scripting via PATH_INFO
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.
by munozferna
CVE-2007-3563 EXPLOITDB text VERIFIED
AV Arcade 2.1b - SQL Injection via id Parameter
SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.
by Kw3[R]Ln
CVE-2007-3572 EXPLOITDB text VERIFIED
Yoggie Pico and Pico Pro - Remote Command Execution via runDiagnostics.cgi param Parameter
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).
by Cody Brocious
CVE-2007-3520 EXPLOITDB text VERIFIED
Easybe 1-2-3 Music Store - SQL Injection via CategoryID Parameter
SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
by t0pP8uZz
CVE-2007-3521 EXPLOITDB text VERIFIED
ArcadeBuilder Game Portal Manager 1.7 - SQL Injection via usercookie Cookie
SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie.
by t0pP8uZz
CVE-2007-3523 EXPLOITDB text VERIFIED
XCMS 1.1 - Directory Traversal and Arbitrary File Execution via Ent or Lang Parameter
Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.
by BlackNDoor
CVE-2007-3515 EXPLOITDB text VERIFIED
TotalCalendar < 2.402 - SQL Injection via view_event.php id Parameter
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by t0pP8uZz
CVE-2007-3522 EXPLOITDB text VERIFIED
sPHPell 1.01 - Remote File Inclusion via SpellIncPath Parameter
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.
by Mehmet Ince
CVE-2007-3524 EXPLOITDB text VERIFIED
ripe_website_manager < 0.8.9 - Remote File Inclusion via Level Parameter
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php.
by BlackNDoor
CVE-2007-3526 EXPLOITDB text VERIFIED
Buddy Zone < 1.5 - SQL Injection via News ID, Category ID, or Member ID Parameter
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.
by t0pP8uZz