Exploitdb Exploits
31,394 exploits tracked across all sources.
Marco Antonio Islas Cruz WebSlider 0.6 - RCE
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.
by GoLd_M
Gallery 1.2.5 - 'GALLERY_BASEDIR' Multiple Remote File Inclusions
by GoLd_M
CNStats 2.12 - Remote File Inclusion via bn Parameter
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by irvian
arash audiocms 0.1.4 - Remote File Inclusion via arashlib_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.
by GoLd_M
Pixaria Gallery < 1.4.3 - Remote File Inclusion via cfg[sys][base_path] Parameter
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
by irvian
Pixaria Gallery - Remote File Inclusion via cfg[sys][base_path] Parameter
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
by irvian
Limesoft Guestbook 1.0 - Code Injection
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.
by Gammarays
AutoStand < 1.1 - Remote Code Execution via mosConfig_absolute_path Parameter
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.
by Cold Zero
Jx Development Article Component < 1.1 - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.
by Cold Zero
FloweRS 2.0 - Cross-Site Scripting via rok Parameter
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.
by the_Edit0r
bloofoxcms 0.2.2 - Cross-Site Scripting via img_url Parameter
Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.
by the_Edit0r
qdblog < 0.4 - Directory Traversal via Theme Parameter
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.
by Omni
qdblog < 0.4 - SQL Injection via Username and Password Parameters
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
by Omni
AfterLogic MailBee WebMail Pro 3.4 - Cross-Site Scripting via Username Parameter
Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
by David Vieira-Kurz
Garennes < 0.6.1 - Remote File Inclusion via repertoire_config Parameter
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.
by GoLd_M
Doop Content Management System 1.3.x - Multiple Input Validation Vulnerabilities
by KaBuS
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' exec-shield Local Overflow
by Xpl017Elz
eIQnetworks Enterprise Security Analyzer 2.5 - Remote Code Execution via Long Parameter to ESA Protocol Command
Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.
by Leon Juranic
WebKalk2 1.9.0 - Remote File Inclusion via Absolute Path Parameter
PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.
by GoLd_M
TuMusika Evolution 1.6 - Cross-Site Scripting via msg Parameter
Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by the_Edit0r
RicarGBooK 1.2.1 - Directory Traversal and Arbitrary File Execution via Lang Cookie or Language Parameter
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.
by Dj7xpl
Request It 1.0b - Remote File Inclusion via index.php id Parameter
PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
by hackberry
Expow 0.8 - Remote File Inclusion via autoindex.php cfg_file Parameter
PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.
by mdx
webMethods Glue <= 6.5.1 - Directory Traversal via Resource Parameter
Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.
by Patrick Webster
MiniBB < 1.5a - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.
by Cold Zero
By Source