Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1421 EXPLOITDB text VERIFIED
Premod SubDog 2 - Remote File Inclusion via phpbb_root_path Parameter
Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.
by Hasadya Raed
CVE-2007-1417 EXPLOITDB text VERIFIED
HC NEWSSYSTEM 1.0-4 - SQL Injection via ID Parameter
SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion.
by WiLdBoY
CVE-2007-1415 EXPLOITDB text VERIFIED
PMB Services < 3.0.13 - Remote Code Execution via Multiple PHP File Inclusion Parameters
Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.
by K-159
CVE-2007-1416 EXPLOITDB text VERIFIED
JCcorp URLshrink - Remote File Inclusion via createurl.php formurl Parameter
PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.
by Hasadya Raed
CVE-2007-1434 EXPLOITDB text VERIFIED
grayscale_blog < 0.8.0 - SQL Injection via id or url Parameter
SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.
by Omni
CVE-2007-1420 EXPLOITDB text VERIFIED
MySQL < 5.0.36 - Denial of Service via Information Schema Subselect with ORDER BY
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
by S.Streichsbier
EIP-2026-102687 EXPLOITDB text VERIFIED
Mozilla Firefox 2.0.0.2 - '.GIF' Handling Denial of Service
by Samuel
CVE-2007-1391 EXPLOITDB text VERIFIED
Leo West WEBO 1.0 - Remote File Inclusion via baseDir Parameter
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
by K-159
CVE-2007-1392 EXPLOITDB text VERIFIED
netForo! 0.1g - Directory Traversal via File Download Parameter
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_download parameter.
by GoLd_M
CVE-2007-1393 EXPLOITDB text VERIFIED
Magic CMS 4.2.747 - Remote File Inclusion via mysave.php file Parameter
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
by DNX
CVE-2007-1362 EXPLOITDB text VERIFIED
Firefox 1.5.x-1.5.0.11 and 2.x-2.0.0.3 - Denial of Service via Cookie Path Parameter
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies."
by Nicolas DEROUET
CVE-2007-1410 EXPLOITDB text VERIFIED
GaziYapBoz Game Portal - SQL Injection via kategori Parameter
SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.
by CyberGhost
CVE-2007-1372 EXPLOITDB text VERIFIED
PostGuestbook 0.6.1 - Remote File Inclusion via tpl_pgb_moddir Parameter
PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.
by GoLd_M
CVE-2007-1394 EXPLOITDB text VERIFIED
Flat Chat 2.0 - Remote Code Execution via Chat Name Field
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. NOTE: some of these details are obtained from third party information.
by Dj7xpl
CVE-2007-1359 EXPLOITDB text VERIFIED
ModSecurity <= 2.1.0 - Request Rule Bypass via ASCIIZ Byte in POST Data
Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.
by Stefan Esser
CVE-2007-1371 EXPLOITDB text VERIFIED
Conquest < 8.2a - Multiple Buffer Overflow via Metaserver Query and SP_CLIENTSTAT Packet
Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.
by Luigi Auriemma
CVE-2007-1347 EXPLOITDB text VERIFIED
Microsoft Windows Explorer - Denial of Service via Crafted Office File Document Summary
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
by Marsu
CVE-2007-1327 EXPLOITDB text VERIFIED
silc-server 1.0.2 - Denial of Service via Invalid HMAC Algorithm in SILC_SERVER_CMD_FUNC
The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.
by Frank Benkstein
CVE-2007-1331 EXPLOITDB text VERIFIED
TKS Banking Solutions ePortfolio 1.0 Java - Cross-Site Scripting via Search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program. NOTE: some of these details are obtained from third party information.
by Stefan Friedli
EIP-2026-102901 EXPLOITDB text VERIFIED
Linux Kernel 2.6.17 - 'Sys_Tee' Local Privilege Escalation
by Michael Kerrisk
CVE-2007-4229 EXPLOITDB text VERIFIED
KDE Konqueror < 3.5.7 - Denial of Service via Malformed HTML
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Thomas Waldegger
CVE-2007-1287 EXPLOITDB text VERIFIED
PHP 4.4.3-4.4.6 - Cross-Site Scripting via phpinfo GET POST or COOKIE Array Values
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.
by Stefan Esser
CVE-2007-1303 EXPLOITDB text VERIFIED
rrdbrowse < 1.6 - Directory Traversal via File Parameter
Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by Sebastian Wolfgarten
CVE-2007-1369 EXPLOITDB text VERIFIED
Zend Platform <2.2.3 - Local Privilege Escalation
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.
by Stefan Esser
CVE-2007-1251 EXPLOITDB text VERIFIED
Netrek Vanilla Server 2.12.0 - Remote Code Execution via Format String in Warning Message
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.
by Luigi Auriemma