Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0335 EXPLOITDB text VERIFIED
Jax Petition Book 1.0.3.06 - Directory Traversal via Languagepack Parameter
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
by ilker Kandemir
CVE-2007-0335 EXPLOITDB text VERIFIED
Jax Petition Book 1.0.3.06 - Directory Traversal via Languagepack Parameter
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
by ilker Kandemir
CVE-2007-0342 EXPLOITDB HIGH text VERIFIED
Apple Safari - Denial of Service via TD ROWSPAN Attribute
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
by Tom Ferris
CVSS 7.5
CVE-2006-6767 EXPLOITDB HIGH text VERIFIED
oftpd < 0.3.7 - Denial of Service via LPRT or LPASV Command
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure.
by anonymous
CVSS 7.5
CVE-2007-0235 EXPLOITDB text VERIFIED
libgtop < 2.14.6 - Stack-Based Buffer Overflow via Long Process Filename
Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.
by Liu Qishuai
CVE-2007-0305 EXPLOITDB text VERIFIED
Okul Web Otomasyon Sistemi 4.0.1 - SQL Injection via etkinlikbak.asp id Parameter
SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ilker Kandemir
CVE-2007-0302 EXPLOITDB text VERIFIED
InstantASP 4.1.0 - Cross-Site Scripting via SessionID, Username, or Update Parameters
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.
by Doz
CVE-2007-0302 EXPLOITDB text VERIFIED
InstantASP 4.1.0 - Cross-Site Scripting via SessionID, Username, or Update Parameters
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.
by Doz
CVE-2007-0267 EXPLOITDB text VERIFIED
Mac OS X 10.4.8 - Denial of Service via Crafted UFS DMG Image
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function. NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.
by LMH
EIP-2026-104557 EXPLOITDB text VERIFIED
Apple Mac OSX 10.4.8 - DMG HFS+ DO_HFS_TRUNCATE Denial of Service
by LMH
CVE-2007-0264 EXPLOITDB text VERIFIED
WinZip 9.0 - Buffer Overflow via Long Command Line Argument
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by Umesh Wanve
CVE-2007-0300 EXPLOITDB text VERIFIED
tlm_cms < 1.1 - Remote File Inclusion via chemin Parameter
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
by GoLd_M
CVE-2007-0307 EXPLOITDB text VERIFIED
Poplar Gedcom Viewer < 2.0 - Remote File Inclusion via env[rootPath] Parameter
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.
by GoLd_M
CVE-2007-0304 EXPLOITDB text VERIFIED
MiNT Haber Sistemi < 2.7 - SQL Injection via duyuru.asp id Parameter
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by chernobiLe
CVE-2007-0298 EXPLOITDB text VERIFIED
LunarPoll - Remote File Inclusion via PollDir Parameter
PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter.
by ilker Kandemir
EIP-2026-107008 EXPLOITDB text VERIFIED
Ezboxx 0.7.6 Beta - Multiple Input Validation Vulnerabilities
by Doron P
CVE-2007-0316 EXPLOITDB text VERIFIED
All In One Control Panel < 1.3.010 - SQL Injection via xuser_name or did Parameter
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.
by Coloss
EIP-2026-104610 EXPLOITDB text VERIFIED
Apple Mac OSX 10.4.8 - DMG UFS Byte_Swap_Sbin() Integer Overflow
by LMH
CVE-2007-0224 EXPLOITDB text VERIFIED
VP-ASP Shopping Cart <= 6.09 - SQL Injection via LoginLastname Parameter
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.
by ajann
CVE-2007-0314 EXPLOITDB text VERIFIED
Article System 1.0 - Remote File Inclusion via INCLUDE_DIR Parameter
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.
by 3l3ctric-Cracker
CVE-2007-0225 EXPLOITDB text VERIFIED
VP-ASP Shopping Cart <= 6.09 - Cross-Site Scripting via shopcustadmin.asp msg Parameter
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by ajann
CVE-2007-0232 EXPLOITDB text VERIFIED
Jshop Server 1.3 - Remote File Inclusion via jssShopFileSystem Parameter
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.
by irvian
CVE-2007-0229 EXPLOITDB text VERIFIED
Mac OS X 10.4.8 - Local Denial of Service and Privilege Escalation via Crafted DMG Image
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.
by LMH
CVE-2007-0226 EXPLOITDB text VERIFIED
uniForum < 4 - SQL Injection via TXbyuser Parameter
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter).
by ajann
CVE-2007-0167 EXPLOITDB text VERIFIED
WGS-PPC Search Engine - PHP File Inclusion Code Execution
Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.
by IbnuSina