Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1555 EXPLOITDB text VERIFIED
Minerva mod for phpBB - SQL Injection via forum.php c Parameter
SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.
by Mehmet Ince
CVE-2007-1540 EXPLOITDB text VERIFIED
LedgerSMB < 1.2.0 and SQL-Ledger < 2.6.27 - Directory Traversal and Authentication Bypass via Login Parameter
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter. NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated.
by Chris Travers
CVE-2007-1566 EXPLOITDB text VERIFIED
NetVIOS Portal - SQL Injection via NewsID Parameter
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.
by parad0x
CVE-2007-1626 EXPLOITDB text VERIFIED
PHP-NUKE iFrame Module - Remote File Inclusion via iframe.php file Parameter
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
by Cold Zero
CVE-2007-1647 EXPLOITDB text VERIFIED
Moodle < 1.5.2 - Unauthenticated Sensitive Information Exposure via Session File Access
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
by xSh
CVE-2007-1613 EXPLOITDB text VERIFIED
MPM Chat 2.5 - Directory Traversal via Logi Parameter
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.
by GoLd_M
CVE-2007-1620 EXPLOITDB text VERIFIED
php_db_designer < 1.02 - Remote File Inclusion via _SESSION Parameter
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.
by GoLd_M
EIP-2026-110488 EXPLOITDB text VERIFIED
Particle Blogger 1.2.1 - 'Archives.php' SQL Injection
by Serapis.net
CVE-2007-1509 EXPLOITDB text VERIFIED
Holtstraeter Rot 13 - Directory Traversal via enkrypt.php datei Parameter
Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.
by h4ck3r
CVE-2007-1508 EXPLOITDB text VERIFIED
DirectAdmin - Cross-Site Scripting via CMD_USER_STATS RESULT Parameter
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.
by Mandr4ke
CVE-2007-1556 EXPLOITDB text VERIFIED
Creative Files 1.2 - SQL Injection via dlid Parameter
SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.
by Mehmet Ince
CVE-2007-1506 EXPLOITDB text VERIFIED
Oracle Application Server Portal - Cross-Site Scripting via p_oldurl and p_newurl Parameters
Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.
by d3nx
CVE-2007-1481 EXPLOITDB text VERIFIED
WBBlog - SQL Injection via e_id Parameter
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.
by Mehmet Ince
CVE-2007-1479 EXPLOITDB text VERIFIED
Creative Guestbook 1.0 - Cross-Site Scripting in Guestbook.php
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
by Dj7xpl
CVE-2007-1476 EXPLOITDB text VERIFIED
Symantec Client Security - Denial of Service via SymTDI Driver Input Buffer
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.
by David Matousek
CVE-2007-1487 EXPLOITDB text VERIFIED
Sascha Schroeder WebLog - Directory Traversal via File Parameter in Showarticles Action
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.
by Dj7xpl
CVE-2007-1483 EXPLOITDB text VERIFIED
WebCalendar 0.9.45 - Remote Code Execution via includedir Parameter
Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.
by Drackanz
CVE-2007-1482 EXPLOITDB text VERIFIED
WBBlog - Cross-Site Scripting via e_id Parameter
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.
by Mehmet Ince
CVE-2007-1514 EXPLOITDB text VERIFIED
ViperWeb Portal alpha 0.1 - Remote File Inclusion via modpath Parameter
PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.
by Abdus Samad
CVE-2007-1478 EXPLOITDB text VERIFIED
McGallery 0.5b - Unauthenticated Arbitrary File Read via Filename Parameter
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
by Piker
CVE-2007-1515 EXPLOITDB text VERIFIED
Horde IMP < 4.1.3 - Cross-Site Scripting via Email Subject Header or Search Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php. NOTE: some of these details are obtained from third party information.
by Immerda Project Group
CVE-2007-1473 EXPLOITDB text VERIFIED
Horde Application Framework - Cross-Site Scripting via new_lang Parameter
Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.
by Moritz Naumann
CVE-2007-1472 EXPLOITDB text VERIFIED
Groupit 2.00b5 - Remote Code Execution via Global Variable Overwrite
Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.
by the_day
CVE-2007-1480 EXPLOITDB text VERIFIED
Creative Guestbook 1.0 - Unauthenticated Administrative Account Creation via Direct Request
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
by Dj7xpl
CVE-2007-1513 EXPLOITDB text VERIFIED
GraFX Company WebSite Builder (CWB) PRO 1.9.8 - RCE
PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.
by the_day