Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2934 EXPLOITDB text VERIFIED
Vistered Little <1.6a - Path Traversal
Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter.
by GoLd_M
EIP-2026-107118 EXPLOITDB text VERIFIED
FlashChat F_CMS 4.7.9 - Multiple Remote File Inclusions
by Hasadya Raed
CVE-2007-0693 EXPLOITDB text VERIFIED
DGNews 2.1 - SQL Injection via catid Parameter
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
by laurent gaffie
CVE-2007-0694 EXPLOITDB text VERIFIED
DGNews 2.1 - Cross-Site Scripting via Copyright Parameter
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.
by Jesper Jurcenoks
CVE-2007-0693 EXPLOITDB text VERIFIED
DGNews 2.1 - SQL Injection via catid Parameter
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
by Jesper Jurcenoks
CVE-2007-2683 EXPLOITDB text VERIFIED
Mutt 1.4.2 - Buffer Overflow via GECOS Field Alias Expansion
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.
by raylai
CVE-2007-2936 EXPLOITDB text VERIFIED
Frequency Clock 0.1b - Remote File Inclusion via Securelib Parameter
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.
by ThE TiGeR
CVE-2007-2937 EXPLOITDB text VERIFIED
TROforum 0.1 - Remote File Inclusion via site_url Parameter
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.
by Mehmet Ince
CVE-2007-2939 EXPLOITDB text VERIFIED
Mazen's PHP Chat 3.0.0 - Remote File Inclusion via basepath Parameter
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.
by ThE TiGeR
CVE-2007-2943 EXPLOITDB text VERIFIED
webavis < 0.1.1 - Remote File Inclusion via Root Parameter
PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
by ThE TiGeR
CVE-2007-2941 EXPLOITDB text VERIFIED
vBGSiteMap 2.41 - Remote File Inclusion via Base Parameter
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.
by Cold Zero
CVE-2007-5579 EXPLOITDB text VERIFIED
Pligg CMS 9.5 - Password Reset via Guessable Confirmation Code
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.
by 242th section
CVE-2007-5728 EXPLOITDB text VERIFIED
phppgadmin 3.5-4.1.1 - Cross-Site Scripting via PHP_SELF in redirect.php
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.
by Michal Majchrowicz
CVE-2007-2947 EXPLOITDB text VERIFIED
OpenBASE Alpha 0.6 - Remote File Inclusion via root_prefix Parameter
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.
by DeltahackingTEAM
CVE-2007-2879 EXPLOITDB text VERIFIED
GTP GNUTurk Portal System 3G - Cross-Site Scripting via Month Parameter
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter.
by vagrant
CVE-2007-2940 EXPLOITDB text VERIFIED
FlaP 1.0b - Remote File Inclusion via pachtofile Parameter
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php.
by Mehmet Ince
EIP-2026-106444 EXPLOITDB text VERIFIED
Digirez 3.4 - Multiple Cross-Site Scripting Vulnerabilities
by Linux_Drox
CVE-2007-2932 EXPLOITDB text VERIFIED
BoastMachine - Cross-Site Scripting via Blog Parameter in Content Search
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.
by newbinaryfile
CVE-2007-0752 EXPLOITDB text VERIFIED
Apple Mac OS X 10.4.8 - Privilege Escalation
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
by qaaz
CVE-2007-3227 EXPLOITDB text VERIFIED
Ruby on Rails - Cross-Site Scripting via ActiveRecord::Base#to_json Input Values
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
by BCC
CVE-2007-2891 EXPLOITDB text VERIFIED
FirmWorX 0.1.2 - Remote File Inclusion via bank_data[root] or fm_data[root] Parameter
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.
by DeltahackingTEAM
CVE-2007-2892 EXPLOITDB text VERIFIED
ASP-Nuke 2.0.7 - Cross-Site Scripting via News ID Parameter
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by vagrant
CVE-2007-2887 EXPLOITDB text VERIFIED
Web Icerik Yonetim Sistemi WIYS 1.0 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.
by vagrant
CVE-2007-2900 EXPLOITDB text VERIFIED
Scallywag 2005-04-25 - Remote Code Execution via Path Parameter in Template.php
Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/.
by Mehmet Ince
CVE-2007-2865 EXPLOITDB text VERIFIED
phppgadmin 4.1.1 - Cross-Site Scripting via Server Parameter
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.
by Michal Majchrowicz