Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-0081 EXPLOITDB text VERIFIED
Sunbelt Kerio Personal Firewall <4.3.268-4.3.246 - Local Privilege ...
Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.
by Matousec Transparent security
CVE-1999-0953 EXPLOITDB text VERIFIED
WWWBoard - Unauthenticated Password File Exposure
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
by bd0rk
CVE-2007-0052 EXPLOITDB text VERIFIED
Vizayn Haber - SQL Injection via haberdetay.asp id Parameter
SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.
by chernobiLe
EIP-2026-100519 EXPLOITDB text VERIFIED
RBlog 1.0 - 'admin.mdb' Remote Password Disclosure
by Aria-Security Team
CVE-2007-0091 EXPLOITDB text VERIFIED
newsCMSlite - Unauthenticated Sensitive Information Exposure via Direct Database Download
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.
by KaBuS
CVE-2007-0053 EXPLOITDB text VERIFIED
ASP SiteWare autoDealer < 2.0 - SQL Injection via detail.asp iPro Parameter
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.
by ajann
CVE-2006-6891 EXPLOITDB text VERIFIED
Vz (Adp) Forum 2.0.3 - Info Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt.
by 3l3ctric-Cracker
CVE-2006-6888 EXPLOITDB text VERIFIED
P-News 1.16 and 1.17 - Unauthenticated Sensitive Information Exposure via Direct Request
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for db/user.dat.
by 3l3ctric-Cracker
CVE-2006-6867 EXPLOITDB text VERIFIED
Vladimir Menshakov buratinable templator 0.9.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different vectors and a different affected version than CVE-2006-6809.
by DeltahackingTEAM
CVE-2002-1656 EXPLOITDB text VERIFIED
X-News 1.1 - Authentication Bypass via MD5 Password Hash Cookie
X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.
by bd0rk
CVE-2006-6863 EXPLOITDB CRITICAL text VERIFIED
Enigma WordPress Bridge Enigma2.php - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value
by Mehmet Ince
CVSS 9.8
CVE-2006-6890 EXPLOITDB text VERIFIED
Voodoo chat 1.0RC1b - Info Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
by bd0rk
CVE-2006-6889 EXPLOITDB text VERIFIED
FreeStyle Wiki <3.6.2 - Info Disclosure
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat.
by bd0rk
CVE-2006-6864 EXPLOITDB text VERIFIED
Enigma2 Coppermine Bridge 1.0 - RCE
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter.
by Mehmet Ince
CVE-2006-6861 EXPLOITDB text VERIFIED
Outfront Spooky Login 2.7 - SQL Injection
Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp.
by Doz
CVE-2006-6865 EXPLOITDB text VERIFIED
SoftArtisans FileUp <5.0.14 - Path Traversal
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitrary files via a %c0%ae. (Unicode dot dot) in the path parameter, which bypasses the checks for ".." sequences.
by Inge Henriksen
CVE-2006-6851 EXPLOITDB text VERIFIED
ac4p Mobilelib gold 2 - Cross-Site Scripting via Email or Error Parameter
Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary web script or HTML via the (1) email or (2) errr parameter.
by viP HaCKEr
CVE-2006-6866 EXPLOITDB text VERIFIED
STphp EasyNews PRO 4.0 - Info Disclosure
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt.
by bd0rk
EIP-2026-104026 EXPLOITDB text VERIFIED
Oracle 10g Portal - 'Key' Cross-Site Scripting
by Pham Duc Hai
CVE-2006-6842 EXPLOITDB text VERIFIED
phpBB2 Plus 1.53 - Acronym Mod 0.9.5 - SQL Injection
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by the master
CVE-2006-6846 EXPLOITDB text VERIFIED
WYWO InOut Board 1.0 - SQL Injection
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp.
by ajann
CVE-2006-6848 EXPLOITDB text VERIFIED
ASPTicker 1.0 - SQL Injection via admin.asp PATH_INFO
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO, possibly related to the Password parameter.
by ajann
CVE-2006-6831 EXPLOITDB text VERIFIED
aFAQ 1.0 - SQL Injection via catcode Parameter
SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter.
by ajann
CVE-2006-1154 EXPLOITDB text VERIFIED
Fantastic News 2.1.2 and 2.1.4 - Remote File Inclusion via CONFIG[script_path] Parameter
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable.
by Mr-m07
CVE-2006-6808 EXPLOITDB text VERIFIED
WordPress 2.0.5 - Cross-Site Scripting via File Parameter in wp-admin/templates.php
Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_description function in wp-admin/admin-functions.php.
by David Kierznowski