Exploitdb Exploits
31,394 exploits tracked across all sources.
XOOPS XT-Conteudo - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by g00ns
XFsection 1.07 module for XOOPS - Remote File Inclusion via dir_module Parameter
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.
by Sp[L]o1T
Cjay Content Module for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.
by g00ns
TinyContent Module 1.5 for XOOPS - Remote File Inclusion via spaw_root Parameter
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
by Sp[L]o1T
XOOPS Horoscope Module 1.0 - Remote File Inclusion via xoopsConfig[root_path] Parameter
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.
by BeyazKurt
Mbedthis AppWeb 2.0.5-4 - Denial of Service via Format String in HTTP Scheme
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
by Nir Rachmel
Bakbone Netvault < 2.0.0 - Buffer Overflow
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
by Cody Pierce
Windows Privacy Tray 1.2.0 - User-Assisted RCE
Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.
by nnposter
Link Request Contact Form 3.4 - Unauthenticated Arbitrary PHP File Upload
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.
by CorryL
Just For Fun Network Management System 0.8.3 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
by Tim Brown
Just For Fun Network Management System 0.8.3 - SQL Injection via User and Pass Parameters
Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.
by Tim Brown
Just For Fun Network Management System <0.8.3 - Info Disclosure
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.
by Tim Brown
Just For Fun Network Management System <0.8.3 - Info Disclosure
Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.
by Tim Brown
Beehive Forum 0.7.1 - Cross-Site Scripting via links.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.
by Ory Segal
bbPress 0.8.1 - Cross-Site Scripting via re Parameter
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.
by Ory Segal
vBSupport Integrated Ticket System 3.x.x - SQL Injection via Ticket ID Parameter
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.
by rUnViRuS
GeometriX Download Portal - SQL Injection via down_indir.asp id Parameter
SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
by CyberGhost
WordPress Core 2.2 - 'Request_URI' Cross-Site Scripting
by zamolx3
3Com OfficeConnect Secure Router 1.04-168 - Cross-Site Scripting via tk Parameter
Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter.
by Secunia Research
PacketShaper 7.3.0g2 and 7.5.0g1 - Denial of Service via Empty OP.MEAS.DATAQUERY and MEAS.TYPE Parameters
rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.
by nnposter
Ibrahim Ã?AKICI - 'Okul Portal Haber_Oku.asp' SQL Injection
by ertuqrul
Microsoft Windows XP - Denial of Service via ICO File with Zero Height
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
by Kad
CVSS 5.5
WmsCMS <= 2.0 - Cross-Site Scripting via 4print.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.
by Glafkos Charalambous
Atom PhotoBlog < 1.0.9 - Cross-Site Scripting via Comment Fields
Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "Approve Comments."
by Serapis.net
Microsoft Windows XP - Denial of Service via ICO File with Zero Height
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
by Dennis Rand
CVSS 5.5
By Source