Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-1125 EXPLOITDB text VERIFIED
XeroXer Simple one-file gallery < 0.6 - Cross-Site Scripting via Gallery f Parameter
Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.
by laurent gaffie
CVE-2007-1127 EXPLOITDB text VERIFIED
shopkitplus - Directory Traversal via changetheme Parameter
Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.
by laurent gaffie
CVE-2007-1133 EXPLOITDB text VERIFIED
FCRing 1.3 - Remote File Inclusion via s_fuss Parameter
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.
by kezzap66345
CVE-2007-1152 EXPLOITDB text VERIFIED
Pyrophobia 2.1.3.1 - Path Traversal
Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php. NOTE: some of these details are obtained from third party information.
by laurent gaffie
CVE-2007-1159 EXPLOITDB text VERIFIED
Pyrophobia 2.1.3.1 - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-1138 EXPLOITDB text VERIFIED
Cromosoft Simple Plantilla PHP - Path Traversal and Arbitrary File Read via nfolder Parameter
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.
by laurent gaffie
CVE-2007-1140 EXPLOITDB text VERIFIED
barekoncept pheap - Path Traversal via edit.php filename Parameter
Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.
by laurent gaffie
CVE-2007-1149 EXPLOITDB text VERIFIED
LoveCMS 1.4 - Path Traversal via Step or Load Parameter
Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.
by laurent gaffie
CVE-2007-1148 EXPLOITDB text VERIFIED
LoveCMS 1.4 - Remote Code Execution via Install Step Parameter
PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.
by laurent gaffie
CVE-2007-1149 EXPLOITDB text VERIFIED
LoveCMS 1.4 - Path Traversal via Step or Load Parameter
Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.
by laurent gaffie
CVE-2007-1151 EXPLOITDB text VERIFIED
LoveCMS 1.4 - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.
by laurent gaffie
CVE-2007-1078 EXPLOITDB text VERIFIED
FlashGameScript 1.5.4 - Remote Code Execution via index.php func Parameter
PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.
by JuMp-Er
CVE-2007-1118 EXPLOITDB text VERIFIED
efiction < 3.1.1 - Remote File Inclusion via path_to_smf Parameter
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.
by ThE dE@Th
CVE-2007-1076 EXPLOITDB text VERIFIED
phpTrafficA <1.4.1 - Path Traversal
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.
by Hamid Ebadi
CVE-2007-1076 EXPLOITDB text VERIFIED
phpTrafficA <1.4.1 - Path Traversal
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.
by Hamid Ebadi
CVE-2007-1142 EXPLOITDB text VERIFIED
Magic News Plus 1.0.2 - Cross-Site Scripting via link_parameters Parameter
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.
by HACKERS PAL
CVE-2007-1142 EXPLOITDB text VERIFIED
Magic News Plus 1.0.2 - Cross-Site Scripting via link_parameters Parameter
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.
by HACKERS PAL
CVE-2007-1167 EXPLOITDB text VERIFIED
deV!L`z Clanportal <1.4.5 - Info Disclosure
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.
by Kiba
CVE-2007-1164 EXPLOITDB text VERIFIED
DBImageGallery 1.2.2 - Remote Code Execution via donsimg_base_path Parameter
Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.
by Denven
CVE-2007-1165 EXPLOITDB text VERIFIED
DBGuestbook 1.1 - Remote Code Execution via dbs_base_path Parameter
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.
by Denven
CVE-2007-1020 EXPLOITDB text VERIFIED
CedStat 1.31 - Cross-Site Scripting via hier Parameter
Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.
by sn0oPy
CVE-2007-1085 EXPLOITDB text VERIFIED
Google Desktop - Cross-Site Scripting via Advanced Search 'under' Parameter
Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.
by Yair Amit
CVE-2007-1059 EXPLOITDB text VERIFIED
Ultimate Fun Book 1.02 - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter. NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.
by kezzap66345
CVE-2007-1060 EXPLOITDB text VERIFIED
Interspire SendStudio <2004.14 - RCE
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.
by K-159
CVE-2007-1050 EXPLOITDB text VERIFIED
AbleDesign MyCalendar - Cross-Site Scripting via Index.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
by sn0oPy