Exploitdb Exploits
31,394 exploits tracked across all sources.
SpoonLabs Vivvo Article Management CMS 3.40 - SQL Injection via RSS Show Webfeed wcHeadlines Parameter
SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by St[at]rExT
phpmyreports 3.0.11 - Remote File Inclusion via cfgPathModule Parameter
PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.
by GoLd_M
nsGalPHP 0.41 and earlier - Remote File Inclusion via racineTBS Parameter
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.
by S.W.A.T.
MAXdev MDPro 1.0.76 - SQL Injection via startrow Parameter
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
by adexior
ACGVclick 0.2.0 - Remote File Inclusion via path Parameter
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
by ajann
ACGVannu < 1.3 - Unauthenticated Password and Profile Modification via ID Parameter
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information.
by ajann
Telestream Flip4Mac <2.1.0.33 - RCE
Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.
by kf
Apple Installer 2.1.5 - Remote Code Execution via Format String in Package Filename
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
by LMH
chernobile 1.0 - SQL Injection via User Field
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.
by ajann
Yahoo Messenger < 8.1.0.209 - Stored Cross-Site Scripting via Contact Details IMG SRC Attribute
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
by Hai Nam Luke
PHP Membership Manager 1.5 - Cross-Site Scripting via _p Parameter
Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.
by Doz
MyPHPCommander 2.0 - Code Injection
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.
by Cold Zero
FD Script <= 1.3.2 - Unauthenticated Arbitrary File Read via download.php fname Parameter
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
by ajann
FD Script <= 1.3.2 - Unauthenticated Arbitrary File Read via download.php fname Parameter
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
by ajann
Ad Fundum Integratable News Script <0.02b - RCE
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.
by ThE dE@Th
PHP 5.2.0 - Arbitrary File Read via Invalid URI Handler in fopen
The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.
by Maksymilian Arciemowicz
Forum Livre 1.0 - SQL Injection via User Parameter
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.
by ajann
Microsoft Word 2000 and 2003 - Remote Code Execution and Denial of Service via Memory Corruption
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
by Symantec
Vu Le An Virtual Path 1.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by GoLd_M
Apple Software Update 2.0.5 - Remote Code Execution via Format String Specifiers
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.
by kf
Newsposter Script 3 - SQL Injection via uid Parameter
SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.
by ajann
Guo Xu Guos Posting System 1.2 - SQL Injection via print.asp id Parameter
SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
Forum Livre 1.0 - Cross-Site Scripting via busca2.asp palavra Parameter
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.
by ajann
Virtual Host Administrator 0.1 - Modules_Dir Remote File Inclusion
by Dr Max Virus
Inter7 vHostAdmin 1.0 - Remote File Inclusion via MODULES_DIR Parameter
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.
by 3l3ctric-Cracker
By Source