Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2353 EXPLOITDB text VERIFIED
Apache Axis 1.0 - Information Disclosure via Non-Existent WSDL Request
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
by jericho+bblog@attrition.org
CVE-2007-1215 EXPLOITDB text VERIFIED
Microsoft Windows - Buffer Overflow
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.
by Lionel d'Hauenens
CVE-2007-2340 EXPLOITDB text VERIFIED
phporacleview - Remote Code Execution via page_dir or inc_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.
by Alkomandoz Hacker
CVE-2007-2341 EXPLOITDB text VERIFIED
phpBandManager 0.8 - Remote File Inclusion via pg Parameter
PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.
by koray
CVE-2007-2423 EXPLOITDB text VERIFIED
MoinMoin 1.5.7 - Cross-Site Scripting via AttachFile do Parameter
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by En Douli
CVE-2007-2456 EXPLOITDB text VERIFIED
FireFly 1.1.01 - Remote File Inclusion via doc_root Parameter
Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.
by Alkomandoz Hacker
CVE-2007-2259 EXPLOITDB text VERIFIED
EsForum 3.0 - SQL Injection via idsalon Parameter
SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.
by ilker Kandemir
CVE-2007-2288 EXPLOITDB text VERIFIED
doruk100net - Remote File Inclusion via info.php file Parameter
PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
by Ali7
CVE-2007-2420 EXPLOITDB text VERIFIED
Burak Yilmaz Blog 1.0 - SQL Injection
SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by RMx
CVE-2007-2474 EXPLOITDB text VERIFIED
Turnkey Web Tools SunShop Shopping Cart 4.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.
by s3rv3r_hack3r
CVE-2007-2268 EXPLOITDB text VERIFIED
SWsoft Plesk 7.6.1, 8.1.0, 8.1.1 - Directory Traversal via Locale ID Parameter
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
by anonymous
EIP-2026-111173 EXPLOITDB text VERIFIED
PHPMyTGP 1.4 - 'AddVIP.php' Remote File Inclusion
by alijsb
CVE-2007-2325 EXPLOITDB text VERIFIED
MyNewsGroups include.php - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
by Ali & Saeid
CVE-2007-2324 EXPLOITDB text VERIFIED
JulmaCMS 1.4 - Directory Traversal via File Parameter
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by GoLd_M
CVE-2007-2326 EXPLOITDB text VERIFIED
HYIP Manager Pro - Remote File Inclusion via Plugin File Parameter
Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.
by alijsb
CVE-2007-2327 EXPLOITDB text VERIFIED
HTMLeditbox 2.2 - Remote File Inclusion via settings[app_dir] Parameter
PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.
by alijsb
CVE-2007-2285 EXPLOITDB text VERIFIED
Ext JS 1.0 alpha1 - Directory Traversal via Feed Parameter
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.
by Alkomandoz Hacker
CVE-2007-2330 EXPLOITDB text VERIFIED
DynaTracker 151 - Remote File Inclusion via base_path Parameter
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
by alijsb
CVE-2007-2330 EXPLOITDB text VERIFIED
DynaTracker 151 - Remote File Inclusion via base_path Parameter
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
by alijsb
CVE-2007-2287 EXPLOITDB text VERIFIED
comus < 2.0_final - Remote File Inclusion via DOCUMENT_ROOT Parameter
PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
by alijsb
CVE-2007-2428 EXPLOITDB text VERIFIED
ahhp-portal - Remote Code Execution via page.php fp or sc Parameter
Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.
by CodeXpLoder'tq
EIP-2026-104921 EXPLOITDB text VERIFIED
Active PHP BookMarks 1.0 - 'APB.php' Remote File Inclusion
by Ali & Saeid
EIP-2026-119054 EXPLOITDB text VERIFIED
Progress 3.1 - Webspeed _CPYFile.P Unauthorized Access
by suresync
CVE-2007-2271 EXPLOITDB text VERIFIED
USP FOSS Distribution 1.01 - Directory Traversal via dnld Parameter
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.
by GoLd_M
EIP-2026-111137 EXPLOITDB text VERIFIED
phpMyAdmin 2.9.1 - Multiple Cross-Site Scripting Vulnerabilities
by sp3x@securityreason.com