Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1837 EXPLOITDB text VERIFIED
MangoBery CMS 0.5.5 - Remote File Inclusion via Site_Path Parameter
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.
by kezzap66345
CVE-2005-2246 EXPLOITDB text VERIFIED
iPhotoAlbum 1.1 - Remote File Inclusion via doc_path or set_menu Parameter
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.
by GoLd_M
CVE-2007-1839 EXPLOITDB text VERIFIED
CodeBB < 1.1_beta_3 - Remote File Inclusion via phpbb_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.
by Alkomandoz Hacker
CVE-2007-1778 EXPLOITDB text VERIFIED
eve-nuke_forum - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by ThE TiGeR
CVE-2007-1873 EXPLOITDB text VERIFIED
Mephisto 0.7.3 - Cross-Site Scripting via Search q Parameter
Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search script.
by The[Boss]
EIP-2026-107798 EXPLOITDB text VERIFIED
Image_Upload Script 2.0 - Multiple Remote File Inclusions
by Crackers_Child
CVE-2007-1678 EXPLOITDB text VERIFIED
Fizzle 0.5 - Cross-Site Scripting via RSS Feed Processing
Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler.
by CrYpTiC MauleR
CVE-2007-1714 EXPLOITDB text VERIFIED
CcCounter 2.0 - Cross-Site Scripting via dir Parameter
Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter.
by Crackers_Child
CVE-2007-1721 EXPLOITDB text VERIFIED
C-Arbre < 0.6_pr7 - Remote File Inclusion via root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
by K-159
CVE-2006-5763 EXPLOITDB text VERIFIED
Free File Hosting < 1.1 - Remote File Inclusion via AD_BODY_TEMP Parameter
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. Vector 1 also affects Free Image Hosting 2.0, which contains the same code.
by Crackers_Child
CVE-2006-5762 EXPLOITDB text VERIFIED
Free File Hosting < 1.1 - Remote Code Execution via AD_BODY_TEMP Parameter
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. This also affects Free Image Hosting 2.0, which contains the same code.
by Crackers_Child
CVE-2007-1715 EXPLOITDB text VERIFIED
Free Image Hosting 2.0 - Remote File Inclusion via AD_BODY_TEMP Parameter
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.
by Crackers_Child
CVE-2007-1708 EXPLOITDB text VERIFIED
ttCMS 4 and earlier - Remote File Inclusion via lib_path Parameter
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
by Kacper
CVE-2007-1707 EXPLOITDB text VERIFIED
Net Side Content Management System - RCE
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter.
by Sharingan
CVE-2006-5763 EXPLOITDB text VERIFIED
Free File Hosting < 1.1 - Remote File Inclusion via AD_BODY_TEMP Parameter
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. Vector 1 also affects Free Image Hosting 2.0, which contains the same code.
by IbnuSina
CVE-2006-5763 EXPLOITDB text VERIFIED
Free File Hosting < 1.1 - Remote File Inclusion via AD_BODY_TEMP Parameter
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. Vector 1 also affects Free Image Hosting 2.0, which contains the same code.
by IbnuSina
CVE-2006-5764 EXPLOITDB text VERIFIED
Free File Hosting < 1.1 - Remote Code Execution via AD_BODY_TEMP Parameter
PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting.
by IbnuSina
CVE-2007-1697 EXPLOITDB text VERIFIED
Philex < 0.2.3 - Remote File Inclusion via CssFile Parameter
PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.
by GoLd_M
CVE-2007-1658 EXPLOITDB text VERIFIED
Windows Vista - Remote Code Execution via Windows Mail Link Handling
Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).
by kingcope
CVE-2007-1698 EXPLOITDB text VERIFIED
Philex < 0.2.3 - Unauthenticated Arbitrary File Read via download.php file Parameter
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.
by GoLd_M
CVE-2006-5043 EXPLOITDB text VERIFIED
Joomlaboard Forum Component <1.1.2 - RCE
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of CVE-2006-3528.
by Cold Zero
CVE-2007-1699 EXPLOITDB text VERIFIED
SWmenu Component for Joomla and Mambo - Remote File Inclusion via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.
by Cold Zero
CVE-2007-3824 EXPLOITDB text VERIFIED
MzK Blog - SQL Injection via katID Parameter
SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter.
by GeFORC3
CVE-2005-2062 EXPLOITDB text VERIFIED
ActiveBuyAndSell 6.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
by CyberGhost
CVE-2007-1705 EXPLOITDB text VERIFIED
Active Trade 2 - SQL Injection via catid Parameter
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by CyberGhost