Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1232 EXPLOITDB text VERIFIED
SQLiteManager 1.2.0 - Path Traversal
Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.
by Simon Bonnard
CVE-2006-7099 EXPLOITDB text VERIFIED
SolarPay - Directory Traversal via Read Parameter
Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot dot) in the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Hasadya Raed
CVE-2007-1158 EXPLOITDB text VERIFIED
Pagesetter 6.2.0-6.3.0 - Path Traversal
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
by D. Matscheko
CVE-2007-1243 EXPLOITDB text VERIFIED
Audins Audiens 3.3 - Unauthenticated Authentication Bypass via uninstall.php
Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by r00t
CVE-2007-1241 EXPLOITDB text VERIFIED
Audins Audiens 3.3 - Cross-Site Scripting via PATH_INFO in setup.php
Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by r00t
CVE-2007-1242 EXPLOITDB text VERIFIED
Audins Audiens 3.3 - SQL Injection via PHPSESSID Cookie
SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by r00t
EIP-2026-115740 EXPLOITDB text VERIFIED
Microsoft Office 2003 - Denial of Service
by sehato
CVE-2007-1104 EXPLOITDB text VERIFIED
PHP-MIP 0.1 - Remote File Inclusion via laypath Parameter
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.
by GoLd_M
CVE-2007-1100 EXPLOITDB text VERIFIED
Ahmet Sacan Pickle <20070301 - Path Traversal
Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by laurent gaffie
CVE-2007-1101 EXPLOITDB text VERIFIED
Photostand 1.2.0 - Cross-Site Scripting via Message Name or Search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.
by Simon Bonnard
CVE-2007-1240 EXPLOITDB text VERIFIED
Docebo CMS 3.0.3-3.0.5 - Cross-Site Scripting via Searchkey or Chat Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by r00t
CVE-2007-1240 EXPLOITDB text VERIFIED
Docebo CMS 3.0.3-3.0.5 - Cross-Site Scripting via Searchkey or Chat Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by r00t
CVE-2007-1110 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Path Traversal
Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1111 EXPLOITDB text VERIFIED
ActiveCalendar 1.2.0 - Cross-Site Scripting via CSS Parameter
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
by Simon Bonnard
CVE-2007-1126 EXPLOITDB text VERIFIED
xt-commerce - Path Traversal via Template Parameter
Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
by laurent gaffie
CVE-2007-1131 EXPLOITDB text VERIFIED
Sinapis Forum 2.2 - Remote File Inclusion via fuss Parameter
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
by kezzap66345
CVE-2007-1130 EXPLOITDB text VERIFIED
Sinapis Gastebuch 2.2 - Remote File Inclusion via fuss Parameter
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
by kezzap66345
CVE-2007-1124 EXPLOITDB text VERIFIED
XeroXer Simple Gallery - Directory Traversal
Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
by laurent gaffie