Exploitdb Exploits
31,394 exploits tracked across all sources.
Calendarix 0.7.20070307 - Cross-Site Scripting via year, month, and leftfooter Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.
by Jesper Jurcenoks
BugMall Shopping Cart 2.5 - Cross-Site Scripting via msgs Parameter
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
by t0pP8uZz
b1g b1gBB 2.24 - Remote File Inclusion via tfooter Parameter
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.
by Rf7awy
6ALBlog - Authenticated Remote File Inclusion via admin/index.php pg Parameter
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.
by Crackers_Child
Sergey Lyubka Simple HTTPD <1.38 - Info Disclosure
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
by Shay Priel
KeyFocus KF Web Server 3.1.0 - Cross-Site Scripting via opsubmenu Parameter
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
by Shay Priel
Pharmacy System < 2 - SQL Injection via ID Parameter
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
by t0pP8uZz
phpTrafficA < 1.4.2 - Cross-Site Scripting via Lang Parameter
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
by laurent gaffié
phpTrafficA < 1.4.2 - Directory Traversal via Lang Parameter
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.
by laurent gaffié
phpTrafficA < 1.4.2 - SQL Injection via PageID Parameter
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.
by laurent gaffié
Pharmacy System <2 - Info Disclosure
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
by t0pP8uZz
e107 <= 0.7.8 - Unauthenticated Arbitrary File Upload via Double Extension Bypass
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
by g00ns
Valerio Capello Dagger - The Cutting Edge r23jan2007 - RCE
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.
by Katatafish
Sun Board 1.00.00 Alpha - Remote File Inclusion via sunPath or dir Parameter
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.
by GoLd_M
NetClassifieds - SQL Injection via CatID or ItemNum Parameter
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.
by laurent gaffié
Joomla! / Mambo Component Mod_Forum - 'PHPBB_Root.php' Remote File Inclusion
by spymeta
eNdonesia 8.4 - SQL Injection via artid or bid Parameter
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
by laurent gaffie
eNdonesia 8.4 - SQL Injection via artid or bid Parameter
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.
by laurent gaffie
Apple Mac OS X <10.4.9 - CRLF Injection
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
by Richard Moore
PHPAccounts 0.5 - 'index.php' Multiple SQL Injections
by r0t
PHPAccounts 0.5 - Directory Traversal via Page Parameter
Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.
by r0t
NetClassifieds Premium Edition - SQL Injection via s_user_id Parameter
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.
by laurent gaffie
myserver < 0.8.9 - Sensitive Information Exposure via Case Sensitivity Bypass
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
by Shay Priel
CVSS 7.5
WiwiMod 0.4 for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by GoLd_M
Wrapper.php for osCommerce - Local File Inclusion
by Joe Bloomquist
By Source