Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2204 EXPLOITDB text VERIFIED
GPL PHP Board unstable-2001.11.14-1 - RCE
Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.
by ThE TiGeR
CVE-2007-2272 EXPLOITDB text VERIFIED
Advanced Webhost Billing System <2.4.0 - RCE
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.
by DamaR
CVE-2007-2256 EXPLOITDB text VERIFIED
TJSChat 0.95 - Cross-Site Scripting via User Parameter
Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
by the_Edit0r
CVE-2007-2201 EXPLOITDB text VERIFIED
Post Revolution 6.6 and 7.0 RC2 - Remote File Inclusion via dir Parameter
Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.
by InyeXion
CVE-2007-2258 EXPLOITDB text VERIFIED
PHPMyBibli - Remote File Inclusion via base_path Parameter
PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
by MoHaNdKo
CVE-2007-2250 EXPLOITDB text VERIFIED
Phorum < 5.1.20 - Information Disclosure via admin.php module[] Parameter
admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.
by Janek Vind
CVE-2007-2248 EXPLOITDB text VERIFIED
Phorum < 5.1.21 - Cross-Site Scripting via group_id or smiley_id Parameter
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.
by Janek Vind
CVE-2007-2248 EXPLOITDB text VERIFIED
Phorum < 5.1.21 - Cross-Site Scripting via group_id or smiley_id Parameter
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.
by Janek Vind
CVE-2007-2339 EXPLOITDB text VERIFIED
Phorum < 5.1.20 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.
by Janek Vind
CVE-2007-2339 EXPLOITDB text VERIFIED
Phorum < 5.1.20 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.
by Janek Vind
CVE-2007-2249 EXPLOITDB text VERIFIED
Phorum <5.1.22 - Privilege Escalation
include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.
by Janek Vind
CVE-2007-2338 EXPLOITDB text VERIFIED
Phorum < 5.1.20 - Cross-Site Request Forgery via Banlist Delete Parameter
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.
by Janek Vind
CVE-2007-2200 EXPLOITDB text VERIFIED
Pagode 0.5.8 - Directory Traversal via Absolute Parameter
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.
by GoLd_M
CVE-2007-2205 EXPLOITDB text VERIFIED
LAN Management System 1.5.3 - Remote File Inclusion via _LIB_DIR Parameter
PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.
by InyeXion
CVE-2007-2199 EXPLOITDB text VERIFIED
CJG EXPLORER PRO 3.3 - Remote Code Execution via g_pcltar_lib_dir Parameter
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
by Omid
CVE-2007-2262 EXPLOITDB text VERIFIED
Sinato jmuffin - Remote Code Execution via relPath or folder Parameter
Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as "File117".
by InyeXion
EIP-2026-105885 EXPLOITDB text VERIFIED
Claroline 1.x - RootSys Remote File Inclusion
by MoHaNdKo
EIP-2026-105102 EXPLOITDB text VERIFIED
Allfaclassifieds 6.04 - 'Level2.php' Remote File Inclusion
by Dr.RoVeR
CVE-2007-2202 EXPLOITDB text VERIFIED
Accueil et Conseil en Visites et Sejours Web Services PHP5 1.0 - Remote File Inclusion via CheminInclude Parameter
PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.
by MoHaNdKo
CVE-2007-2175 EXPLOITDB text VERIFIED
Apple QuickTime Java extensions - RCE
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.
by Shane Macaulay
CVE-2007-2183 EXPLOITDB text VERIFIED
PHP-Ring Webring System 0.9 - SQL Injection via Ring Parameter
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.
by Dj7xpl
CVE-2007-2182 EXPLOITDB text VERIFIED
Maran PHP Forum - Unauthenticated Arbitrary File Upload via Trailing Null Byte in Filename
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.
by Dj7xpl
CVE-2007-2184 EXPLOITDB text VERIFIED
jchit counter 1.0.0 - Directory Traversal via imgsrv.php acc Parameter
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter.
by Dj7xpl
CVE-2007-2185 EXPLOITDB text VERIFIED
Supasite 1.23b - Remote Code Execution via supa[db_path] or supa[include_path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.
by GoLd_M
CVE-2007-2503 EXPLOITDB text VERIFIED
PHP Turbulence 0.0.1 alpha - Path Traversal
Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion
by Omni