Exploitdb Exploits
31,394 exploits tracked across all sources.
Apache Axis 1.0 - Information Disclosure via Non-Existent WSDL Request
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
by jericho+bblog@attrition.org
Microsoft Windows - Buffer Overflow
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.
by Lionel d'Hauenens
phporacleview - Remote Code Execution via page_dir or inc_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.
by Alkomandoz Hacker
phpBandManager 0.8 - Remote File Inclusion via pg Parameter
PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.
by koray
MoinMoin 1.5.7 - Cross-Site Scripting via AttachFile do Parameter
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by En Douli
FireFly 1.1.01 - Remote File Inclusion via doc_root Parameter
Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.
by Alkomandoz Hacker
EsForum 3.0 - SQL Injection via idsalon Parameter
SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.
by ilker Kandemir
doruk100net - Remote File Inclusion via info.php file Parameter
PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
by Ali7
Burak Yilmaz Blog 1.0 - SQL Injection
SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by RMx
Turnkey Web Tools SunShop Shopping Cart 4.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.
by s3rv3r_hack3r
SWsoft Plesk 7.6.1, 8.1.0, 8.1.1 - Directory Traversal via Locale ID Parameter
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.
by anonymous
MyNewsGroups include.php - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
by Ali & Saeid
JulmaCMS 1.4 - Directory Traversal via File Parameter
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by GoLd_M
HYIP Manager Pro - Remote File Inclusion via Plugin File Parameter
Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.
by alijsb
HTMLeditbox 2.2 - Remote File Inclusion via settings[app_dir] Parameter
PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.
by alijsb
Ext JS 1.0 alpha1 - Directory Traversal via Feed Parameter
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.
by Alkomandoz Hacker
DynaTracker 151 - Remote File Inclusion via base_path Parameter
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
by alijsb
DynaTracker 151 - Remote File Inclusion via base_path Parameter
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
by alijsb
comus < 2.0_final - Remote File Inclusion via DOCUMENT_ROOT Parameter
PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.
by alijsb
ahhp-portal - Remote Code Execution via page.php fp or sc Parameter
Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.
by CodeXpLoder'tq
Active PHP BookMarks 1.0 - 'APB.php' Remote File Inclusion
by Ali & Saeid
Progress 3.1 - Webspeed _CPYFile.P Unauthorized Access
by suresync
USP FOSS Distribution 1.01 - Directory Traversal via dnld Parameter
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.
by GoLd_M
phpMyAdmin 2.9.1 - Multiple Cross-Site Scripting Vulnerabilities
by sp3x@securityreason.com
By Source