Exploitdb Exploits
31,394 exploits tracked across all sources.
Vistered Little <1.6a - Path Traversal
Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter.
by GoLd_M
FlashChat F_CMS 4.7.9 - Multiple Remote File Inclusions
by Hasadya Raed
DGNews 2.1 - SQL Injection via catid Parameter
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
by laurent gaffie
DGNews 2.1 - Cross-Site Scripting via Copyright Parameter
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.
by Jesper Jurcenoks
DGNews 2.1 - SQL Injection via catid Parameter
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
by Jesper Jurcenoks
Mutt 1.4.2 - Buffer Overflow via GECOS Field Alias Expansion
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.
by raylai
Frequency Clock 0.1b - Remote File Inclusion via Securelib Parameter
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.
by ThE TiGeR
TROforum 0.1 - Remote File Inclusion via site_url Parameter
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.
by Mehmet Ince
Mazen's PHP Chat 3.0.0 - Remote File Inclusion via basepath Parameter
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.
by ThE TiGeR
webavis < 0.1.1 - Remote File Inclusion via Root Parameter
PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
by ThE TiGeR
vBGSiteMap 2.41 - Remote File Inclusion via Base Parameter
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.
by Cold Zero
Pligg CMS 9.5 - Password Reset via Guessable Confirmation Code
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.
by 242th section
phppgadmin 3.5-4.1.1 - Cross-Site Scripting via PHP_SELF in redirect.php
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.
by Michal Majchrowicz
OpenBASE Alpha 0.6 - Remote File Inclusion via root_prefix Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.
by DeltahackingTEAM
GTP GNUTurk Portal System 3G - Cross-Site Scripting via Month Parameter
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter.
by vagrant
FlaP 1.0b - Remote File Inclusion via pachtofile Parameter
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php.
by Mehmet Ince
Digirez 3.4 - Multiple Cross-Site Scripting Vulnerabilities
by Linux_Drox
BoastMachine - Cross-Site Scripting via Blog Parameter in Content Search
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.
by newbinaryfile
Apple Mac OS X 10.4.8 - Privilege Escalation
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
by qaaz
Ruby on Rails - Cross-Site Scripting via ActiveRecord::Base#to_json Input Values
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
by BCC
FirmWorX 0.1.2 - Remote File Inclusion via bank_data[root] or fm_data[root] Parameter
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.
by DeltahackingTEAM
ASP-Nuke 2.0.7 - Cross-Site Scripting via News ID Parameter
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by vagrant
Web Icerik Yonetim Sistemi WIYS 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.
by vagrant
Scallywag 2005-04-25 - Remote Code Execution via Path Parameter in Template.php
Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/.
by Mehmet Ince
phppgadmin 4.1.1 - Cross-Site Scripting via Server Parameter
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.
by Michal Majchrowicz
By Source