Exploitdb Exploits
31,394 exploits tracked across all sources.
WordPress 2.1.1 - Remote Code Execution via Backdoor in Feed and Theme PHP Files
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
by Ivan Fratric
WordPress 2.1.1 - Remote Code Execution via Backdoor in Feed and Theme PHP Files
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
by Ivan Fratric
Woltlab Burning Board 2.3.6 - Multiple HTML Injection Vulnerabilities
by Samenspender
Mani Stats Reader <= 1.2 - Remote File Inclusion via index.php ipath Parameter
PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.
by mozi
Novell Access Management SSLVPN Server - Security Bypass
by anonymous
Comodo Firewall Pro <2.4.18.184 - Privilege Escalation
Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.
by Matousec Transparent security
S9Y Serendipity 1.1.1 - 'index.php' SQL Injection
by Samenspender
built2go News Manager Blog 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
by the_Edit0r
built2go News Manager Blog 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
by the_Edit0r
aWebNews 1.5 - Remote Code Execution via path_to_news Parameter
Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.
by mostafa_ragab
PHP 4.4.2 and 5.1.2 - Denial of Service via Recursive Function Execution
PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.
by Maksymilian Arciemowicz
PHP 4.x < 4.4.7 and 5.x < 5.2.2 - Denial of Service via Deeply Nested Arrays
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
by Stefan Esser
CVSS 7.5
ANGEL Learning Management Suite 7.1 - SQL Injection via id Parameter
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Craig Heffner
EmbeddedWB Web Browser - Remote Code Execution
Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by shinnai
Adobe Reader/Acrobat Trial - Info Disclosure
Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045.
by pdp
Nullsoft ShoutcastServer 1.9.7 - XSS
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.
by SaMuschie
Kiwi CatTools <3.2.0 - Path Traversal
Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command.
by Sergey Gordeychik
WordPress Core 2.1.1 - Multiple Cross-Site Scripting Vulnerabilities
by Stefan Friedli
Admin Phorum 3.3.1a - Code Injection
PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
by GoLd_M
Red Hat Enterprise Linux 4 - Denial of Service via Audit Subsystem File Watch
The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.
by Steve Grubb
Microsoft Publisher 2007 - Remote Denial of Service
by Tom Ferris
WordPress < 2.1.1 - Cross-Site Request Forgery via AdminPanel Delete Action
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.
by Samenspender
Tyger Bug Tracking System 1.1.3 - SQL Injection via ViewBugs.php s Parameter
SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.
by CorryL
Tyger Bug Tracking System 1.1.3 - Cross-Site Scripting via PATH_INFO to Login.php and Register.php
Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.
by CorryL
Tyger Bug Tracking System 1.1.3 - Cross-Site Scripting via PATH_INFO to Login.php and Register.php
Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.
by CorryL
By Source