Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0785 EXPLOITDB text VERIFIED
Flipsource Flip <2.01-final 1.0 - RCE
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
by GoLd_M
CVE-2006-6516 EXPLOITDB text VERIFIED
KDPics < 1.16 - Remote File Inclusion via Page or Lib Path Parameter
Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) page parameter to (a) index.php3, or the (2) lib_path parameter to (b) authenticate.inc.php3 or (c) lib/exifer/exif.php.
by AsTrex
CVE-2007-0515 EXPLOITDB text VERIFIED
Microsoft Word 2000 and 2003 - Remote Code Execution and Denial of Service via Memory Corruption
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
by xCuter
CVE-2007-0820 EXPLOITDB text VERIFIED
Cedric CLAIRE PortailPhp 2 - Remote File Inclusion via chemin Parameter
Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-0821 EXPLOITDB text VERIFIED
Cedric CLAIRE PortailPhp 2 - Path Traversal
Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-0820 EXPLOITDB text VERIFIED
Cedric CLAIRE PortailPhp 2 - Remote File Inclusion via chemin Parameter
Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-0821 EXPLOITDB text VERIFIED
Cedric CLAIRE PortailPhp 2 - Path Traversal
Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-0820 EXPLOITDB text VERIFIED
Cedric CLAIRE PortailPhp 2 - Remote File Inclusion via chemin Parameter
Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by laurent gaffie
CVE-2007-0786 EXPLOITDB text VERIFIED
Noname Media Photo Galerie <1.1.1 - SQL Injection
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2006-6517 EXPLOITDB text VERIFIED
kdpics < 1.16 - Cross-Site Scripting via Categories Parameter
Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) categories parameter to (a) index.php3 or (b) galeries.inc.php3.
by AsTrex
EIP-2026-112853 EXPLOITDB text VERIFIED
Uebimiau 2.7.10 - 'index.php' Cross-Site Scripting
by Doz
CVE-2007-0758 EXPLOITDB text VERIFIED
PHPProbid 5.24 - Remote File Inclusion via lang Parameter
PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by Hasadya Raed
CVE-2007-0761 EXPLOITDB text VERIFIED
phpBB ezBoard converter 0.2 - Remote File Inclusion via ezconvert_dir Parameter
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.
by Mehmet Ince
CVE-2006-3683 EXPLOITDB text VERIFIED
flipper_poll < 1.1 - Remote File Inclusion via poll.php root_path Parameter
PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
by Mehmet Ince
CVE-2007-0760 EXPLOITDB text VERIFIED
EQdkp <= 1.3.1 - Unauthenticated Account Access via HTTP Referer Spoofing
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.
by Eight10
CVE-2007-0759 EXPLOITDB text VERIFIED
EasyMoblog 0.5.1 - SQL Injection via i or post_id Parameter
Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.
by Tal Argoni
CVE-2007-0765 EXPLOITDB text VERIFIED
dB Masters Curium CMS <1.03 - SQL Injection
SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.
by ajann
CVE-2007-0757 EXPLOITDB text VERIFIED
Miguel Nunes CoD2 DreamStats <4.2 - RCE
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.
by ThE dE@Th
CVE-2007-0703 EXPLOITDB text VERIFIED
WebBuilder < 2.0 - Remote File Inclusion via GLOBALS[core][module_path] Parameter
PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.
by GoLd_M
CVE-2006-4733 EXPLOITDB text VERIFIED
sips < 0.3.1 - Remote File Inclusion via config[sipssys] Parameter
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.
by ajann
CVE-2007-0699 EXPLOITDB text VERIFIED
Guernion Sylvain Portail Web Php <2.5.1.1 - RCE
PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.
by laurent gaffié
CVE-2007-0702 EXPLOITDB text VERIFIED
phpEventMan 1.0.2 - Remote File Inclusion via Level Parameter
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.
by Mehmet Ince
CVE-2007-0701 EXPLOITDB text VERIFIED
Epistemon 1.0 - Remote File Inclusion via inc_path Parameter
PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
by GoLd_M
CVE-2007-0679 EXPLOITDB text VERIFIED
nicolas_grandjean phpmyring < 4.1.3b - Remote File Inclusion via lang/leslangues.php fichier Parameter
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.
by ajann
CVE-2007-0680 EXPLOITDB text VERIFIED
phpbb_tweaked < 3 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince