Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2676 EXPLOITDB text VERIFIED
Open Translation Engine 0.7.8 - RCE
PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter.
by GoLd_M
CVE-2007-2673 EXPLOITDB text VERIFIED
Censura < 1.16.04 - SQL Injection via vendorid Parameter
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.
by Mehmet Ince
EIP-2026-101246 EXPLOITDB text VERIFIED
D-Link DSL-G624T - Var:RelaodHref Cross-Site Scripting
by Tim Brown
CVE-2007-2492 EXPLOITDB text VERIFIED
PostNuke v4bJournal - SQL Injection
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.
by Ali Abbasi
CVE-2007-2532 EXPLOITDB text VERIFIED
Minh Nguyen Duong Obie Website Mini Web Shop 2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734.
by CorryL
CVE-2007-2532 EXPLOITDB text VERIFIED
Minh Nguyen Duong Obie Website Mini Web Shop 2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734.
by CorryL
CVE-2007-2473 EXPLOITDB text VERIFIED
CMS Made Simple <1.0.5 - SQL Injection
SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.
by Daniel Lucq
CVE-2007-2507 EXPLOITDB text VERIFIED
Treble Designs 1024 CMS 0.7 - Path Traversal
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter.
by Dj7xpl
CVE-2007-2486 EXPLOITDB text VERIFIED
Motobit 1.3 and 1.5 - Directory Traversal via File Parameter
Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter.
by Dj7xpl
CVE-2007-2483 EXPLOITDB text VERIFIED
wp-Table < 1.43 - Directory Traversal via wpPATH Parameter
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.
by K-159
CVE-2007-2481 EXPLOITDB text VERIFIED
wordtube < 1.43 - Remote File Inclusion via wpPATH Parameter
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
by K-159
CVE-2007-2484 EXPLOITDB text VERIFIED
wp-Table < 1.43 - Remote File Inclusion via wpPATH Parameter
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
by K-159
CVE-2007-2482 EXPLOITDB text VERIFIED
wordtube < 1.43 - Directory Traversal via wpPATH Parameter
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.
by K-159
CVE-2007-2485 EXPLOITDB text VERIFIED
myflash < 1.00 - Remote File Inclusion via wpPATH Parameter
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.
by Crackers_Child
CVE-2007-2471 EXPLOITDB text VERIFIED
Sendcard < 3.4.1 - Directory Traversal via Form Parameter
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter.
by ettee
CVE-2007-2437 EXPLOITDB text VERIFIED
X.org X Window System 7.0-7.2 with Xserver < 1.3.0 - Authenticated Denial of Service via XRender Extension
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.
by Derek Abdine
CVE-2007-2434 EXPLOITDB text VERIFIED
Aventail Connect 4.1.2.13 - Buffer Overflow
Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query.
by Thomas Pollet
CVE-2007-2416 EXPLOITDB text VERIFIED
E-Annu - SQL Injection via home.php a Parameter
SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter.
by ilkerkandemir
EIP-2026-103210 EXPLOITDB text VERIFIED
RedHat Directory Server 7.1 - Multiple Cross-Site Scripting Vulnerabilities
by Kaushal Desai
CVE-2007-2810 EXPLOITDB text VERIFIED
Gazi Download Portal - SQL Injection
SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by ertuqrul
CVE-2007-2426 EXPLOITDB text VERIFIED
myGallery < 1.4b4 - Remote File Inclusion via myPath Parameter
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.
by GoLd_M
CVE-2007-2425 EXPLOITDB text VERIFIED
Imageview 5.3 - Directory Traversal via Album Parameter
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter.
by DNX
CVE-2007-2427 EXPLOITDB text VERIFIED
pnFlashGames 1.5 - SQL Injection via cid Parameter
SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
by Mehmet Ince
CVE-2007-2364 EXPLOITDB text VERIFIED
burnCMS 0.2 - Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/.
by GoLd_M
CVE-2007-2429 EXPLOITDB text VERIFIED
ManageEngine PasswordManager Pro - Command Injection
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by anonymous