Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3182 EXPLOITDB text VERIFIED
Calendarix 0.7.20070307 - Cross-Site Scripting via year, month, and leftfooter Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.
by Jesper Jurcenoks
CVE-2007-3448 EXPLOITDB text VERIFIED
BugMall Shopping Cart 2.5 - Cross-Site Scripting via msgs Parameter
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
by t0pP8uZz
CVE-2007-3401 EXPLOITDB text VERIFIED
b1g b1gBB 2.24 - Remote File Inclusion via tfooter Parameter
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.
by Rf7awy
CVE-2007-3451 EXPLOITDB text VERIFIED
6ALBlog - Authenticated Remote File Inclusion via admin/index.php pg Parameter
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.
by Crackers_Child
CVE-2007-3407 EXPLOITDB text VERIFIED
Sergey Lyubka Simple HTTPD <1.38 - Info Disclosure
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
by Shay Priel
CVE-2007-3396 EXPLOITDB text VERIFIED
KeyFocus KF Web Server 3.1.0 - Cross-Site Scripting via opsubmenu Parameter
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
by Shay Priel
CVE-2007-3433 EXPLOITDB text VERIFIED
Pharmacy System < 2 - SQL Injection via ID Parameter
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
by t0pP8uZz
CVE-2007-3426 EXPLOITDB text VERIFIED
phpTrafficA < 1.4.2 - Cross-Site Scripting via Lang Parameter
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
by laurent gaffié
CVE-2007-3425 EXPLOITDB text VERIFIED
phpTrafficA < 1.4.2 - Directory Traversal via Lang Parameter
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.
by laurent gaffié
CVE-2007-3427 EXPLOITDB text VERIFIED
phpTrafficA < 1.4.2 - SQL Injection via PageID Parameter
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.
by laurent gaffié
CVE-2007-3434 EXPLOITDB text VERIFIED
Pharmacy System <2 - Info Disclosure
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
by t0pP8uZz
CVE-2007-3429 EXPLOITDB text VERIFIED
e107 <= 0.7.8 - Unauthenticated Arbitrary File Upload via Double Extension Bypass
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
by g00ns
CVE-2007-3431 EXPLOITDB text VERIFIED
Valerio Capello Dagger - The Cutting Edge r23jan2007 - RCE
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.
by Katatafish
CVE-2007-3370 EXPLOITDB text VERIFIED
Sun Board 1.00.00 Alpha - Remote File Inclusion via sunPath or dir Parameter
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.
by GoLd_M
CVE-2005-3978 EXPLOITDB text VERIFIED
NetClassifieds - SQL Injection via CatID or ItemNum Parameter
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.
by laurent gaffié
EIP-2026-108166 EXPLOITDB text VERIFIED
Joomla! / Mambo Component Mod_Forum - 'PHPBB_Root.php' Remote File Inclusion
by spymeta
CVE-2007-3394 EXPLOITDB text VERIFIED
eNdonesia 8.4 - SQL Injection via artid or bid Parameter
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
by laurent gaffie
CVE-2007-3394 EXPLOITDB text VERIFIED
eNdonesia 8.4 - SQL Injection via artid or bid Parameter
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
by laurent gaffie
CVE-2007-2401 EXPLOITDB text VERIFIED
Apple Mac OS X <10.4.9 - CRLF Injection
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
by Richard Moore
EIP-2026-110913 EXPLOITDB text VERIFIED
PHPAccounts 0.5 - 'index.php' Multiple SQL Injections
by r0t
CVE-2007-3346 EXPLOITDB text VERIFIED
PHPAccounts 0.5 - Directory Traversal via Page Parameter
Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.
by r0t
CVE-2007-3354 EXPLOITDB text VERIFIED
NetClassifieds Premium Edition - SQL Injection via s_user_id Parameter
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.
by laurent gaffie
CVE-2007-3365 EXPLOITDB HIGH text VERIFIED
myserver < 0.8.9 - Sensitive Information Exposure via Case Sensitivity Bypass
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
by Shay Priel
CVSS 7.5
CVE-2007-3289 EXPLOITDB text VERIFIED
WiwiMod 0.4 for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by GoLd_M
EIP-2026-114385 EXPLOITDB text VERIFIED
Wrapper.php for osCommerce - Local File Inclusion
by Joe Bloomquist