Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2155 EXPLOITDB text VERIFIED
phpfaber topsites 3 - Directory Traversal via Modify Parameter in Admin Template Action
Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.
by Dr.RoVeR
CVE-2007-2044 EXPLOITDB text VERIFIED
Antonis Ventouris Weather <mod_weather.php - RCE
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.
by Cold Zero
CVE-2007-2049 EXPLOITDB text VERIFIED
Mambo Calendar Module 1.5.5 - Remote File Inclusion via absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.
by Cold Zero
CVE-2007-1992 EXPLOITDB text VERIFIED
com_zoom < 2.5_beta_2 - Remote File Inclusion via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.
by iskorpitx
CVE-2007-2043 EXPLOITDB text VERIFIED
Mambo/Joomla! com_mosmedia <1.08 - RCE
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php.
by GoLd_M
CVE-2007-1989 EXPLOITDB text VERIFIED
dotclear < 1.2.6 - Cross-Site Scripting via post_id or tool_url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.
by nassim
CVE-2007-1989 EXPLOITDB text VERIFIED
dotclear < 1.2.6 - Cross-Site Scripting via post_id or tool_url Parameter
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.
by nassim
CVE-2007-2233 EXPLOITDB text VERIFIED
Cosign <= 2.0.2 - Authenticated Privilege Escalation via Service Parameter CR Injection
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
by Jon Oberheide
CVE-2007-2232 EXPLOITDB text VERIFIED
Cosign <= 2.0.1 - Authentication Bypass via CR Sequence in Cookie Parameter
The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.
by Jon Oberheide
CVE-2007-2007 EXPLOITDB text VERIFIED
pl-php beta 0.9 - Unauthenticated Authentication Bypass via is_admin Parameter
admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.
by Omni
CVE-2007-2006 EXPLOITDB text VERIFIED
pl-php < 0.9_beta - SQL Injection via Login or Pass Parameter
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.
by Omni
CVE-2007-2000 EXPLOITDB text VERIFIED
Crea-Book < 1.0 - SQL Injection via Pseudo or Passe Parameter
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.
by Xst3nZ
CVE-2007-1999 EXPLOITDB text VERIFIED
Weatimages < 1.7.1 - Remote File Inclusion via ini[langpack] Parameter
PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.
by Co-Sarper-Der
CVE-2007-2009 EXPLOITDB text VERIFIED
SimpCMS Light <04.10.2007 - Code Injection
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.
by Dr.RoVeR
CVE-2007-2008 EXPLOITDB text VERIFIED
pl-php beta 0.9 - Directory Traversal via Lang Parameter
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
by Omni
CVE-2007-2019 EXPLOITDB text VERIFIED
phpgalleryscript 1.0 - Remote File Inclusion via init.gallery.php include_class Parameter
PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.
by anonymous
CVE-2007-2014 EXPLOITDB text VERIFIED
MyNews 4.2.2 - Remote File Inclusion via myNewsConf[path][sys][index] Parameter
PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.
by hackberry
CVE-2007-2005 EXPLOITDB text VERIFIED
Taskhopper Component for Joomla! and Mambo - Remote Code Execution via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.
by Cold Zero
CVE-2007-1998 EXPLOITDB text VERIFIED
HIOX Guest Book <4.0 - Code Injection
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.
by Dj7xpl
CVE-2007-2013 EXPLOITDB text VERIFIED
JEx-Treme Einfacher Passworschutz - Cross-Site Scripting via msg Parameter
Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by hackberry
CVE-2007-1363 EXPLOITDB text VERIFIED
dropafew < 0.2 - SQL Injection via id or calories Parameter
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
by Alexander Klink
CVE-2007-1364 EXPLOITDB text VERIFIED
dropafew < 0.2 - Arbitrary User Creation and Information Disclosure
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
by Alexander Klink
CVE-2007-1363 EXPLOITDB text VERIFIED
dropafew < 0.2 - SQL Injection via id or calories Parameter
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
by Alexander Klink
CVE-2007-2001 EXPLOITDB text VERIFIED
crea-book < 1.0 - Authenticated PHP Code Injection via Admin Configuration Fields
Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.
by Xst3nZ
EIP-2026-103151 EXPLOITDB text VERIFIED
Kerberos 1.5.1 - Kadmind Buffer Overflow
by c0ntex