Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1910 EXPLOITDB text VERIFIED
Microsoft Word 2007 - Buffer Overflow via Crafted Document
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
by muts
CVE-2007-1911 EXPLOITDB text VERIFIED
Microsoft Word 2007 - Denial of Service via Crafted Document
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
by muts
CVE-2007-1912 EXPLOITDB text VERIFIED
Microsoft Windows - Heap-Based Buffer Overflow via Crafted HLP File
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.
by muts
CVE-2007-1956 EXPLOITDB text VERIFIED
ubb.threads < 6.1.1 - SQL Injection via C Parameter
SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.
by John Martinelli
CVE-2007-1905 EXPLOITDB text VERIFIED
QuizShock < 1.6.1 - Cross-Site Scripting via auth.php forward_to Parameter
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "&lt;&quot;&lt;".
by John Martinelli
CVE-2007-1908 EXPLOITDB text VERIFIED
PHP121 Instant Messenger 2.2 - Remote PHP Code Execution via php121dir Parameter
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.
by Dj7xpl
CVE-2007-1907 EXPLOITDB text VERIFIED
Pathos Content Management System 0.92-2 - Remote File Inclusion via warn.php file Parameter
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
by kezzap66345
CVE-2007-1909 EXPLOITDB text VERIFIED
Ryan Haudenschilt Battle.net Clan Script 1.5.1 - SQL Injection via User or Pass Parameter
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.
by h a c k e r _ X
CVE-2007-1357 EXPLOITDB text VERIFIED
Linux Kernel < 2.6.20.4 - Denial of Service via AppleTalk Frame Length Mismatch
The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.
by Jean Delvare
CVE-2007-1928 EXPLOITDB text VERIFIED
witshare 0.9 - Directory Traversal via Menu Parameter
Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.
by the_Edit0r
CVE-2007-1932 EXPLOITDB text VERIFIED
ScarNews 1.2.1 - Unauthenticated Directory Traversal via sn_admin_dir Parameter
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.
by BeyazKurt
CVE-2007-1933 EXPLOITDB text VERIFIED
dreamcodes pcp-guestbook 3.0 - Directory Traversal via Lang Parameter
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
by Dj7xpl
CVE-2007-1968 EXPLOITDB text VERIFIED
MyBlog <1.6 - Remote Code Execution
PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.
by the_Edit0r
CVE-2007-2300 EXPLOITDB text VERIFIED
phpwebnews <= 0.2 - Cross-Site Scripting via m_txt Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.
by the_Edit0r
CVE-2007-2300 EXPLOITDB text VERIFIED
phpwebnews <= 0.2 - Cross-Site Scripting via m_txt Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.
by the_Edit0r
CVE-2007-2300 EXPLOITDB text VERIFIED
phpwebnews <= 0.2 - Cross-Site Scripting via m_txt Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.
by the_Edit0r
CVE-2007-1919 EXPLOITDB text VERIFIED
Arizona Dream Livre d'or (livor) 2.5 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by Arham Muhammad
CVE-2007-1930 EXPLOITDB text VERIFIED
cattadoc - Directory Traversal via download2.php fn1 Parameter
Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.
by GoLd_M
CVE-2007-1929 EXPLOITDB text VERIFIED
Beryo - Directory Traversal via Downloadpic.php Chemin Parameter
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter.
by GoLd_M
CVE-2007-2368 EXPLOITDB text VERIFIED
WebSPELL <4.01.02 - Info Disclosure
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
by Trex
CVE-2007-2369 EXPLOITDB text VERIFIED
WebSPELL < 4.01.02 - Directory Traversal via Picture.php ID Parameter
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
by Trex
CVE-2007-2347 EXPLOITDB text VERIFIED
OneClick CMS < 05.10 - Remote File Inclusion via site_path Parameter
PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.
by kezzap66345
CVE-2007-2346 EXPLOITDB text VERIFIED
PHP-Generics 1.0 beta - Remote File Inclusion via _APP_RELATIVE_PATH Parameter
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php.
by bd0rk
CVE-2007-2345 EXPLOITDB text VERIFIED
CodeWand phpBrowse - Remote File Inclusion via include_path Parameter
PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
by kezzap66345
CVE-2007-1738 EXPLOITDB text VERIFIED
TrueCrypt 4.3 - Privilege Escalation or Denial of Service via Crafted Volume Mount
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.
by Marco Ivaldi