Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3221 EXPLOITDB text VERIFIED
XOOPS XT-Conteudo - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by g00ns
CVE-2007-3222 EXPLOITDB text VERIFIED
XFsection 1.07 module for XOOPS - Remote File Inclusion via dir_module Parameter
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.
by Sp[L]o1T
CVE-2007-3220 EXPLOITDB text VERIFIED
Cjay Content Module for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.
by g00ns
CVE-2007-3237 EXPLOITDB text VERIFIED
TinyContent Module 1.5 for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by Sp[L]o1T
CVE-2007-3236 EXPLOITDB text VERIFIED
XOOPS Horoscope Module 1.0 - Remote File Inclusion via xoopsConfig[root_path] Parameter
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.
by BeyazKurt
CVE-2007-3009 EXPLOITDB text VERIFIED
Mbedthis AppWeb 2.0.5-4 - Denial of Service via Format String in HTTP Scheme
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
by Nir Rachmel
CVE-2007-3181 EXPLOITDB text VERIFIED
Bakbone Netvault < 2.0.0 - Buffer Overflow
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
by Cody Pierce
CVE-2007-3201 EXPLOITDB text VERIFIED
Windows Privacy Tray 1.2.0 - User-Assisted RCE
Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.
by nnposter
CVE-2007-3199 EXPLOITDB text VERIFIED
Link Request Contact Form 3.4 - Unauthenticated Arbitrary PHP File Upload
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.
by CorryL
CVE-2007-3189 EXPLOITDB text VERIFIED
Just For Fun Network Management System 0.8.3 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
by Tim Brown
CVE-2007-3190 EXPLOITDB text VERIFIED
Just For Fun Network Management System 0.8.3 - SQL Injection via User and Pass Parameters
Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.
by Tim Brown
CVE-2007-3192 EXPLOITDB text VERIFIED
Just For Fun Network Management System <0.8.3 - Info Disclosure
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.
by Tim Brown
CVE-2007-3191 EXPLOITDB text VERIFIED
Just For Fun Network Management System <0.8.3 - Info Disclosure
Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.
by Tim Brown
CVE-2007-3212 EXPLOITDB text VERIFIED
Beehive Forum 0.7.1 - Cross-Site Scripting via links.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.
by Ory Segal
CVE-2007-3243 EXPLOITDB text VERIFIED
bbPress 0.8.1 - Cross-Site Scripting via re Parameter
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.
by Ory Segal
CVE-2007-3196 EXPLOITDB text VERIFIED
vBSupport Integrated Ticket System 3.x.x - SQL Injection via Ticket ID Parameter
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.
by rUnViRuS
CVE-2007-3188 EXPLOITDB text VERIFIED
GeometriX Download Portal - SQL Injection via down_indir.asp id Parameter
SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
by CyberGhost
EIP-2026-113497 EXPLOITDB text VERIFIED
WordPress Core 2.2 - 'Request_URI' Cross-Site Scripting
by zamolx3
CVE-2006-3974 EXPLOITDB text VERIFIED
3Com OfficeConnect Secure Router 1.04-168 - Cross-Site Scripting via tk Parameter
Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter.
by Secunia Research
CVE-2007-3151 EXPLOITDB text VERIFIED
PacketShaper 7.3.0g2 and 7.5.0g1 - Denial of Service via Empty OP.MEAS.DATAQUERY and MEAS.TYPE Parameters
rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.
by nnposter
EIP-2026-100364 EXPLOITDB text VERIFIED
Ibrahim Ã?AKICI - 'Okul Portal Haber_Oku.asp' SQL Injection
by ertuqrul
CVE-2007-2237 EXPLOITDB MEDIUM text VERIFIED
Microsoft Windows XP - Denial of Service via ICO File with Zero Height
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
by Kad
CVSS 5.5
CVE-2007-3137 EXPLOITDB text VERIFIED
WmsCMS <= 2.0 - Cross-Site Scripting via 4print.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.
by Glafkos Charalambous
CVE-2007-3134 EXPLOITDB text VERIFIED
Atom PhotoBlog < 1.0.9 - Cross-Site Scripting via Comment Fields
Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "Approve Comments."
by Serapis.net
CVE-2007-2237 EXPLOITDB MEDIUM text VERIFIED
Microsoft Windows XP - Denial of Service via ICO File with Zero Height
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
by Dennis Rand
CVSS 5.5