Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-3019 EXPLOITDB text VERIFIED
phpCMS 1.2.1pl2 - Remote Code Execution via PHPCMS_INCLUDEPATH Parameter
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.
by Federico Fazzi
CVE-2006-3019 EXPLOITDB text VERIFIED
phpCMS 1.2.1pl2 - Remote Code Execution via PHPCMS_INCLUDEPATH Parameter
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.
by Federico Fazzi
CVE-2006-6812 EXPLOITDB text VERIFIED
myPHPCalendar 10.1 - Remote File Inclusion via cal_dir Parameter
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.
by Cr@zy_King
EIP-2026-109659 EXPLOITDB text VERIFIED
mxBB Module pafiledb 2.0.1b - Remote File Inclusion
by bd0rk
CVE-2006-6788 EXPLOITDB text VERIFIED
LuckyBot 3 - Remote File Inclusion via dir Parameter
Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) run.php or (2) ircbot.class.php.
by Red_Casper
CVE-2006-6872 EXPLOITDB text VERIFIED
eNdonesia 8.4 - Directory Traversal via mod.php mod Parameter
Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.
by z1ckX(ru)
CVE-2006-6871 EXPLOITDB text VERIFIED
eNdonesia 8.4 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the informasi module in mod.php, (3) the "your Friend" field in friend.php, or (4) the "Main Text" field in admin.php.
by z1ckX(ru)
CVE-2006-6779 EXPLOITDB text VERIFIED
vBulletin - Cross-Site Scripting via SWF ActionScript
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.
by Ashraf Morad
CVE-2006-6850 EXPLOITDB text VERIFIED
Shadowed Portal 5.7 - Remote File Inclusion via mod_root Parameter
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter.
by Mehmet Ince
CVE-2006-6789 EXPLOITDB text VERIFIED
phpbbxtra 2.0 - Remote File Inclusion via phpbb_root_path Parameter
PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
by Mehmet Ince
CVE-2006-6793 EXPLOITDB text VERIFIED
Okul Merkezi Portal 1.0 - Remote File Inclusion via ataturk.php Page Parameter
PHP remote file inclusion vulnerability in ataturk.php in Okul Merkezi Portal 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
by ShaFuck31
CVE-2006-6795 EXPLOITDB text VERIFIED
myPHPNuke My_eGallery 2.5.6 - Remote File Inclusion via basepath Parameter
PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.
by Mehmet Ince
CVE-2006-6887 EXPLOITDB text VERIFIED
logahead UNU 1.0 - Remote Code Execution via WidgEd Plugin File Upload
Unrestricted file upload vulnerability in logahead UNU 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), a different vulnerability than CVE-2006-6783. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by CorryL
CVE-2006-6770 EXPLOITDB text VERIFIED
Jinzora Media Jukebox < 2.7 - Remote File Inclusion via Include Path Parameter
Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.
by nuffsaid
CVE-2006-6771 EXPLOITDB text VERIFIED
Irokez CMS < 0.7.1 - Remote File Inclusion via Multiple PHP Script Parameters
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[PTH][func] parameter in (a) scripts/gallery.scr.php; the (2) GLOBALS[PTH][spaw] parameter in (b) scripts/xtextarea.scr.php; and the (3) GLOBALS[PTH][classes] parameter in (c) sitemap.scr.php, (d) news.scr.php, (e) polls.scr.php, (f) rss.scr.php, (g) search.scr.php in scripts/, and (h) form.fun.php, (i) general.func.php, (j) groups.func.php, (k) js.func.php, (l) sections.func.php, and (m) users.func.php in functions/.
by nuffsaid
CVE-2006-6873 EXPLOITDB text VERIFIED
eNdonesia 8.4 - SQL Injection via mod.php did or cid Parameter
Multiple SQL injection vulnerabilities in mod.php in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via (1) the did parameter in a (a) viewdisk operation (diskusi mod), or the (2) cid parameter in a (b) viewlink (katalog mod) or (b) viewcat (diskusi mod) operation.
by z1ckX(ru)
CVE-2006-6807 EXPLOITDB text VERIFIED
Softwebs Nepal Ananda Real Estate <3.4 - SQL Injection
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.
by ajann
CVE-2006-6778 EXPLOITDB text VERIFIED
TimberWolf 1.2.2 - Cross-Site Scripting via shownews.php nid Parameter
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
by CorryL
CVE-2006-6791 EXPLOITDB text VERIFIED
chatwm 1.0 - SQL Injection via txtUse or txtPas Parameters
SQL injection vulnerability in SelGruFra.asp in chatwm 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) txtUse and (2) txtPas parameters.
by ShaFuq31
CVE-2010-4782 EXPLOITDB text VERIFIED
Softwebs Nepal Ananda Real Estate 3.4 - SQL Injection
Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807.
by ajann
CVE-2006-6830 EXPLOITDB text VERIFIED
b2_blog < 0.5 - Remote File Inclusion via index Parameter
PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the index parameter.
by mdx
CVE-2006-6777 EXPLOITDB text VERIFIED
Future Internet - Cross-Site Scripting via categoryId Parameter
Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.
by Linux_Drox
CVE-2006-6776 EXPLOITDB text VERIFIED
Future Internet - SQL Injection via newsId, categoryid, or langId Parameter
Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.
by Linux_Drox
CVE-2006-3027 EXPLOITDB text VERIFIED
Enthrallwebe ePhotos <2.2 - SQL Injection
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.
by ajann
CVE-2006-6204 EXPLOITDB text VERIFIED
Enthrallweb eHomes - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSub.asp; the (3) TYPE_ID parameter to (c) types.asp; the (4) AD_ID parameter to (d) homeDetail.asp; the (5) cat parameter to (e) result.asp; the (6) compare, (7) clear, and (8) adID parameters to (f) compareHomes.asp; and the (9) aminprice, (10) amaxprice, and (11) abedrooms parameters to (g) result.asp.
by ajann