Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0574 EXPLOITDB text VERIFIED
SpoonLabs Vivvo Article Management CMS 3.40 - SQL Injection via RSS Show Webfeed wcHeadlines Parameter
SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by St[at]rExT
CVE-2007-0571 EXPLOITDB text VERIFIED
phpmyreports 3.0.11 - Remote File Inclusion via cfgPathModule Parameter
PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.
by GoLd_M
CVE-2007-0573 EXPLOITDB text VERIFIED
nsGalPHP 0.41 and earlier - Remote File Inclusion via racineTBS Parameter
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.
by S.W.A.T.
CVE-2007-0623 EXPLOITDB text VERIFIED
MAXdev MDPro 1.0.76 - SQL Injection via startrow Parameter
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
by adexior
CVE-2007-0577 EXPLOITDB text VERIFIED
ACGVclick 0.2.0 - Remote File Inclusion via path Parameter
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by ajann
CVE-2007-0697 EXPLOITDB text VERIFIED
ACGVannu < 1.3 - Unauthenticated Password and Profile Modification via ID Parameter
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information.
by ajann
CVE-2007-0466 EXPLOITDB text VERIFIED
Telestream Flip4Mac <2.1.0.33 - RCE
Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.
by kf
CVE-2007-0465 EXPLOITDB text VERIFIED
Apple Installer 2.1.5 - Remote Code Execution via Format String in Package Filename
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
by LMH
CVE-2007-0582 EXPLOITDB text VERIFIED
chernobile 1.0 - SQL Injection via User Field
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.
by ajann
CVE-2007-0768 EXPLOITDB text VERIFIED
Yahoo Messenger < 8.1.0.209 - Stored Cross-Site Scripting via Contact Details IMG SRC Attribute
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
by Hai Nam Luke
CVE-2007-0567 EXPLOITDB text VERIFIED
PHP Membership Manager 1.5 - Cross-Site Scripting via _p Parameter
Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.
by Doz
CVE-2007-0568 EXPLOITDB text VERIFIED
MyPHPCommander 2.0 - Code Injection
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.
by Cold Zero
CVE-2007-0620 EXPLOITDB text VERIFIED
FD Script <= 1.3.2 - Unauthenticated Arbitrary File Read via download.php fname Parameter
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
by ajann
CVE-2007-0620 EXPLOITDB text VERIFIED
FD Script <= 1.3.2 - Unauthenticated Arbitrary File Read via download.php fname Parameter
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
by ajann
CVE-2007-0570 EXPLOITDB text VERIFIED
Ad Fundum Integratable News Script <0.02b - RCE
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.
by ThE dE@Th
CVE-2007-0448 EXPLOITDB text VERIFIED
PHP 5.2.0 - Arbitrary File Read via Invalid URI Handler in fopen
The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.
by Maksymilian Arciemowicz
CVE-2007-0589 EXPLOITDB text VERIFIED
Forum Livre 1.0 - SQL Injection via User Parameter
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.
by ajann
CVE-2007-0515 EXPLOITDB text VERIFIED
Microsoft Word 2000 and 2003 - Remote Code Execution and Denial of Service via Memory Corruption
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
by Symantec
CVE-2007-0591 EXPLOITDB text VERIFIED
Vu Le An Virtual Path 1.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by GoLd_M
CVE-2007-0463 EXPLOITDB text VERIFIED
Apple Software Update 2.0.5 - Remote Code Execution via Format String Specifiers
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.
by kf
CVE-2007-0600 EXPLOITDB text VERIFIED
Newsposter Script 3 - SQL Injection via uid Parameter
SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.
by ajann
CVE-2007-0554 EXPLOITDB text VERIFIED
Guo Xu Guos Posting System 1.2 - SQL Injection via print.asp id Parameter
SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2007-0590 EXPLOITDB text VERIFIED
Forum Livre 1.0 - Cross-Site Scripting via busca2.asp palavra Parameter
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.
by ajann
EIP-2026-113113 EXPLOITDB text VERIFIED
Virtual Host Administrator 0.1 - Modules_Dir Remote File Inclusion
by Dr Max Virus
CVE-2007-0558 EXPLOITDB text VERIFIED
Inter7 vHostAdmin 1.0 - Remote File Inclusion via MODULES_DIR Parameter
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.
by 3l3ctric-Cracker