Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2519 EXPLOITDB text VERIFIED
PEAR 1.0-1.5.3 - Directory Traversal via Package.xml Install Attribute
Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.
by Gregory Beaver
CVE-2007-2027 EXPLOITDB text VERIFIED
Elinks 0.11.1 - Format String Injection via Untrusted Gettext Message Catalog
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.
by Arnaud Giersch
CVE-2007-2524 EXPLOITDB text VERIFIED
OTRS 2.0.x - Cross-Site Scripting via Subaction Parameter
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.
by ciri
CVE-2007-2561 EXPLOITDB text VERIFIED
fipsCMS 2.1 - SQL Injection via pid Parameter
SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115.
by ilker Kandemir
CVE-2007-2571 EXPLOITDB text VERIFIED
wfquotes_module < 1.0.0 - SQL Injection via index.php c Parameter
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.
by Mehmet Ince
CVE-2007-2570 EXPLOITDB text VERIFIED
Wikivi5 - Remote File Inclusion via sous_rep Parameter
PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the sous_rep parameter.
by GoLd_M
CVE-2007-2572 EXPLOITDB text VERIFIED
NoAh < 0.9_pre_1.2 - Remote Code Execution via tpls[1] Parameter
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter.
by kezzap66345
CVE-2007-2569 EXPLOITDB text VERIFIED
Friendly < 1.0d1 - Remote File Inclusion via friendly_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.
by GoLd_M
CVE-2006-0944 EXPLOITDB text VERIFIED
Archangel Weblog 0.90.02 - Auth Bypass
Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.
by Dj7xpl
CVE-2007-2575 EXPLOITDB text VERIFIED
vm_watermark 0.4.1 - Remote Code Execution via GALLERY_BASEDIR Parameter
PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
by ThE TiGeR
CVE-2007-2573 EXPLOITDB text VERIFIED
PHPtree 1.3 - Remote Code Execution
PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter.
by ThE TiGeR
CVE-2007-2574 EXPLOITDB text VERIFIED
Archangel Weblog 0.90.02 - Path Traversal
Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter.
by Dj7xpl
CVE-2007-2581 EXPLOITDB text VERIFIED
Microsoft Windows SharePoint Services 3.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
by Solarius
CVE-2007-2543 EXPLOITDB text VERIFIED
Flashgames 1.0.1 - SQL Injection via lid Parameter
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
by Mehmet Ince
CVE-2007-2542 EXPLOITDB text VERIFIED
PHP <workbench survival guide 0.11 - RCE
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by kezzap66345
CVE-2007-2541 EXPLOITDB text VERIFIED
Versado CMS 1.07 - Remote File Inclusion via urlModulo Parameter
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a URL in the urlModulo parameter.
by kezzap66345
CVE-2007-2540 EXPLOITDB text VERIFIED
PMECMS <1.0 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[pathMod] parameter to index.php in (1) mod/image/, (2) mod/liens/, (3) mod/liste/, (4) mod/special/, or (5) mod/texte/.
by GoLd_M
CVE-2007-2544 EXPLOITDB text VERIFIED
PHP TopTree BBS < 2.0.1a - Remote File Inclusion via right_file Parameter
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the right_file parameter.
by kezzap66345
CVE-2007-2545 EXPLOITDB text VERIFIED
Persism CMS < 0.9.2 - Remote File Inclusion via system[path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.
by GoLd_M
CVE-2007-2521 EXPLOITDB text VERIFIED
e-gads < 2.2.6 - Remote Code Execution via Locale Parameter
PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter.
by kezzap66345
CVE-2007-2674 EXPLOITDB text VERIFIED
Pre Shopping Mall 1.0 - SQL Injection
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
by Mehmet Ince
CVE-2006-2763 EXPLOITDB text VERIFIED
Pre News Manager 1.0 - SQL Injection via id or nid Parameter
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. It is possible that this is primary to CVE-2006-2678.
by Mehmet Ince
CVE-2007-2675 EXPLOITDB text VERIFIED
Pre Classifieds Listings 1.0 - SQL Injection
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
by Mehmet Ince
CVE-2007-2677 EXPLOITDB text VERIFIED
phpChess Community Edition 2.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2) layout_admin_cfg.php, (3) layout_cfg.php, or (4) layout_t_top.php in skins/phpchess/. NOTE: vector 1 has been disputed by CVE, since the code is defined within a function that is not called from within includes/language.php.
by GoLd_M
CVE-2007-2672 EXPLOITDB text VERIFIED
PHP Coupon Script 3.0 - SQL Injection
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a viewbus page.
by Mehmet Ince