Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0649 EXPLOITDB text VERIFIED
OpenEMR < 2.8.2 - Remote Code Execution via Variable Overwrite in interface/globals.php
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.
by Michael Melewski
CVE-2007-0649 EXPLOITDB text VERIFIED
OpenEMR < 2.8.2 - Remote Code Execution via Variable Overwrite in interface/globals.php
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.
by trzindan
CVE-2007-0683 EXPLOITDB text VERIFIED
Omegaboard 1.0beta4 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2007-0687 EXPLOITDB text VERIFIED
Michelle's L2J Dropcalc <4 - SQL Injection
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.
by Codebreak
CVE-2007-0682 EXPLOITDB text VERIFIED
JV2 Folder Gallery < 3.0.2 - Remote File Inclusion via galleryfilesdir Parameter
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.
by ThE dE@Th
CVE-2007-0662 EXPLOITDB text VERIFIED
Hailboards 1.2.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2007-0676 EXPLOITDB text VERIFIED
ExoPHPDesk <= 1.2.1 - SQL Injection via FAQ ID Parameter
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2007-0684 EXPLOITDB text VERIFIED
Cerulean Portal System 0.7b - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2007-0677 EXPLOITDB text VERIFIED
Cadre PHP Framework <20020724 - RCE
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.
by y3dips
CVE-2007-0688 EXPLOITDB text VERIFIED
Hunkaray Duyuru Scripti - SQL Injection
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.
by cl24zy
CVE-2007-0678 EXPLOITDB text VERIFIED
Fullaspsite Asp Hosting Sitesi - SQL Injection
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.
by cl24zy
CVE-2007-0631 EXPLOITDB text VERIFIED
CascadianFAQ < 4.1 - SQL Injection via catid Parameter
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
by ajann
CVE-2007-0638 EXPLOITDB text VERIFIED
Vlad Alexa Mancini PHPFootball 1.6 - Info Disclosure
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.
by ajann
CVE-2007-0656 EXPLOITDB text VERIFIED
phpBB2-MODificat 0.2.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2007-0633 EXPLOITDB text VERIFIED
MyNews < 4.2.2 - Remote File Inclusion via myNewsConf[path][sys][index] Parameter
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
by GoLd_M
CVE-2007-0635 EXPLOITDB text VERIFIED
EncapsCMS 0.3.6 - Remote File Inclusion via config[path] or config[theme] Parameter
Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.
by Tr_ZiNDaN
CVE-2007-0663 EXPLOITDB text VERIFIED
CascadianFAQ <= 4.1 - SQL Injection via qid Parameter
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ajann
CVE-2007-0644 EXPLOITDB text VERIFIED
Apple Safari 2.0.4 - Denial of Service via Format String in Filename Handling
Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.
by LMH
CVE-2007-0645 EXPLOITDB text VERIFIED
iPhoto 6.0.5 - Denial of Service via Format String in Filename
Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.
by LMH
CVE-2007-0646 EXPLOITDB text VERIFIED
iMovie HD 6.0.3 and Safari in Mac OS X 10.4-10.4.10 - Denial of Service via Format String in Filename
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
by LMH
CVE-2007-0647 EXPLOITDB text VERIFIED
macOS Help Viewer 3.0.0 - Denial of Service via Format String in Filename
Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.
by LMH
CVE-2007-0585 EXPLOITDB text VERIFIED
webfwlog < 0.92 - Remote Source Code Disclosure via conffile Parameter
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks.
by GoLd_M
CVE-2007-0569 EXPLOITDB text VERIFIED
xNews 1.3 - SQL Injection via id Parameter
SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.
by ajann
CVE-2007-0584 EXPLOITDB text VERIFIED
PhP Generic Library & Framework - RCE
PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
by Mehmet Ince
CVE-2007-0576 EXPLOITDB text VERIFIED
Xt-Stats 2.3.x to 2.4.0.b3 - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.
by ThE dE@Th