Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2067 EXPLOITDB text VERIFIED
Marco Antonio Islas Cruz WebSlider 0.6 - RCE
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.
by GoLd_M
EIP-2026-107332 EXPLOITDB text VERIFIED
Gallery 1.2.5 - 'GALLERY_BASEDIR' Multiple Remote File Inclusions
by GoLd_M
CVE-2007-2087 EXPLOITDB text VERIFIED
CNStats 2.12 - Remote File Inclusion via bn Parameter
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by irvian
CVE-2007-2301 EXPLOITDB text VERIFIED
arash audiocms 0.1.4 - Remote File Inclusion via arashlib_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.
by GoLd_M
CVE-2007-2457 EXPLOITDB text VERIFIED
Pixaria Gallery < 1.4.3 - Remote File Inclusion via cfg[sys][base_path] Parameter
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
by irvian
CVE-2007-2458 EXPLOITDB text VERIFIED
Pixaria Gallery - Remote File Inclusion via cfg[sys][base_path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
by irvian
CVE-2007-2093 EXPLOITDB text VERIFIED
Limesoft Guestbook 1.0 - Code Injection
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.
by Gammarays
CVE-2007-2319 EXPLOITDB text VERIFIED
AutoStand < 1.1 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.
by Cold Zero
CVE-2007-2089 EXPLOITDB text VERIFIED
Jx Development Article Component < 1.1 - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.
by Cold Zero
CVE-2007-2308 EXPLOITDB text VERIFIED
FloweRS 2.0 - Cross-Site Scripting via rok Parameter
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.
by the_Edit0r
CVE-2007-2310 EXPLOITDB text VERIFIED
bloofoxcms 0.2.2 - Cross-Site Scripting via img_url Parameter
Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.
by the_Edit0r
CVE-2007-2304 EXPLOITDB text VERIFIED
qdblog < 0.4 - Directory Traversal via Theme Parameter
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.
by Omni
CVE-2007-2305 EXPLOITDB text VERIFIED
qdblog < 0.4 - SQL Injection via Username and Password Parameters
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
by Omni
CVE-2007-2061 EXPLOITDB text VERIFIED
AfterLogic MailBee WebMail Pro 3.4 - Cross-Site Scripting via Username Parameter
Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
by David Vieira-Kurz
CVE-2007-2298 EXPLOITDB text VERIFIED
Garennes < 0.6.1 - Remote File Inclusion via repertoire_config Parameter
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.
by GoLd_M
EIP-2026-106543 EXPLOITDB text VERIFIED
Doop Content Management System 1.3.x - Multiple Input Validation Vulnerabilities
by KaBuS
EIP-2026-102957 EXPLOITDB text VERIFIED
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' exec-shield Local Overflow
by Xpl017Elz
CVE-2007-2059 EXPLOITDB text VERIFIED
eIQnetworks Enterprise Security Analyzer 2.5 - Remote Code Execution via Long Parameter to ESA Protocol Command
Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.
by Leon Juranic
CVE-2007-2307 EXPLOITDB text VERIFIED
WebKalk2 1.9.0 - Remote File Inclusion via Absolute Path Parameter
PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.
by GoLd_M
CVE-2007-2090 EXPLOITDB text VERIFIED
TuMusika Evolution 1.6 - Cross-Site Scripting via msg Parameter
Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by the_Edit0r
CVE-2007-2050 EXPLOITDB text VERIFIED
RicarGBooK 1.2.1 - Directory Traversal and Arbitrary File Execution via Lang Cookie or Language Parameter
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.
by Dj7xpl
CVE-2007-2015 EXPLOITDB text VERIFIED
Request It 1.0b - Remote File Inclusion via index.php id Parameter
PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
by hackberry
CVE-2007-2302 EXPLOITDB text VERIFIED
Expow 0.8 - Remote File Inclusion via autoindex.php cfg_file Parameter
PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.
by mdx
CVE-2007-2048 EXPLOITDB text VERIFIED
webMethods Glue <= 6.5.1 - Directory Traversal via Resource Parameter
Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.
by Patrick Webster
CVE-2007-2317 EXPLOITDB text VERIFIED
MiniBB < 1.5a - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.
by Cold Zero