Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1712 EXPLOITDB text VERIFIED
ActiveWebSoftwares Active Auction Pro 7.1 - SQL Injection via catid Parameter
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by CyberGhost
CVE-2007-1643 EXPLOITDB text VERIFIED
LAN Management System < 1.8.9 - Remote Code Execution via PHP File Inclusion
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
by Kacper
CVE-2007-1640 EXPLOITDB text VERIFIED
ClassWeb < 2.03 - Remote File Inclusion via BASE Parameter
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php.
by GoLd_M
CVE-2004-1552 EXPLOITDB text VERIFIED
aspWebCalendar - SQL Injection via Username Field or EventID Parameter
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
by parad0x
CVE-2007-1628 EXPLOITDB text VERIFIED
Study planner (Studiewijzer) <= 0.15 - Remote File Inclusion via SPL_CFG[dirroot] Parameter
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files.
by K-159
CVE-2006-4606 EXPLOITDB text VERIFIED
Longino Jacome php-Revista 1.1.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter in autor.php, the (4) email parameter in lista.php, and the (5) id_articulo parameter in articulo.php.
by Cold Zero
CVE-2007-1596 EXPLOITDB text VERIFIED
NFN Address Book - Remote File Inclusion via mosConfig_absolute_path Parameter
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.
by Cold Zero
CVE-2007-1600 EXPLOITDB text VERIFIED
Digital Eye Gallery <1.1 Beta - RCE
PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.
by Cold Zero
CVE-2007-2293 EXPLOITDB text VERIFIED
Asterisk - Stack-Based Buffer Overflow in SIP Channel T.38 SDP Parser
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.
by Barrie Dempster
CVE-2007-2293 EXPLOITDB text VERIFIED
Asterisk - Stack-Based Buffer Overflow in SIP Channel T.38 SDP Parser
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.
by Barrie Dempster
CVE-2007-1563 EXPLOITDB text VERIFIED
Opera 9.10 - FTP PASV Response Manipulation Leading to Information Exposure
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
by mark
CVE-2007-1562 EXPLOITDB text VERIFIED
Firefox < 1.5.0.11 and 2.x < 2.0.0.3 - FTP PASV Response Manipulation
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
by mark
CVE-2007-1564 EXPLOITDB text VERIFIED
Konqueror 3.5.5 - Exposure of Sensitive Information via FTP PASV Response
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
by mark
CVE-2007-1629 EXPLOITDB text VERIFIED
Active Photo Gallery - SQL Injection via catid Parameter
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by CyberGhost
CVE-2007-1630 EXPLOITDB text VERIFIED
ActiveWebSoftwares Active Link Engine - SQL Injection via catid Parameter
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by CyberGhost
CVE-2007-1548 EXPLOITDB text VERIFIED
Web Wiz Forums < 8.05 - SQL Injection via Name Parameter
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
by Ivan Fratric
CVE-2007-1606 EXPLOITDB text VERIFIED
w-Agora - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.
by laurent gaffie
CVE-2007-1606 EXPLOITDB text VERIFIED
w-Agora - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.
by laurent gaffie
CVE-2007-1606 EXPLOITDB text VERIFIED
w-Agora - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.
by laurent gaffie
CVE-2006-0308 EXPLOITDB text VERIFIED
htmltonuke 2.0 alpha - Remote Code Execution via filnavn Parameter
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.
by Cold Zero
CVE-2007-1586 EXPLOITDB text VERIFIED
ZynOS 3.40 - Denial of Service via SMB Mail Slot Protocol
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.
by Joxean Koret
CVE-2007-1550 EXPLOITDB text VERIFIED
phpx < 3.5.15 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.
by laurent gaffie
CVE-2007-1550 EXPLOITDB text VERIFIED
phpx < 3.5.15 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.
by laurent gaffie
CVE-2007-1550 EXPLOITDB text VERIFIED
phpx < 3.5.15 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.
by laurent gaffie
CVE-2007-1550 EXPLOITDB text VERIFIED
phpx < 3.5.15 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.
by laurent gaffie