Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6803 EXPLOITDB text VERIFIED
Enthrallweb eCars 1.0 - SQL Injection
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.
by ajann
CVE-2006-6804 EXPLOITDB text VERIFIED
Dragon Business Directory - Pro <3.01.12 - SQL Injection
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
by ajann
CVE-2006-6792 EXPLOITDB text VERIFIED
Calendar MX BASIC <1.0.2 - SQL Injection
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ajann
CVE-2006-6764 EXPLOITDB text VERIFIED
Keep It Simple Guest Book 5.1.1 - Remote File Inclusion Code Execution
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.
by mdx
CVE-2006-6747 EXPLOITDB text VERIFIED
dreaxteam xt-news 0.1 - SQL Injection via id_news Parameter
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.
by Mr_KaLiMaN
CVE-2006-6746 EXPLOITDB text VERIFIED
Xt-News 0.1 - Cross-Site Scripting via id_news Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
by Mr_KaLiMaN
CVE-2006-6746 EXPLOITDB text VERIFIED
Xt-News 0.1 - Cross-Site Scripting via id_news Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
by Mr_KaLiMaN
CVE-2006-6703 EXPLOITDB text VERIFIED
Oracle Portal 9i and 10g - Cross-Site Scripting via tc Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other unspecified vectors.
by putosoft softputo
CVE-2008-1635 EXPLOITDB text VERIFIED
Keep It Simple Guest Book <5.1.1 - Path Traversal
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.
by mdx
CVE-2003-1314 EXPLOITDB text VERIFIED
EternalMart Guestbook 1.1 - Remote File Inclusion via emgb_admin_path Parameter
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.
by mdx
CVE-2006-6729 EXPLOITDB text VERIFIED
a-blog < 1.51 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
by Fukumori
CVE-2006-6877 EXPLOITDB text VERIFIED
Matteo Lucarelli 3editor CMS <0.42 - Path Traversal
Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.
by 3l3ctric-Cracker
EIP-2026-103724 EXPLOITDB text VERIFIED
WikiReader 1.12 - URL Field Local Buffer Overflow
by Umesh Wanve
CVE-2006-6752 EXPLOITDB text VERIFIED
FTPRush 1.0.0.610 - Buffer Overflow
Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. Also, it is not clear whether this issue crosses security boundaries.
by Umesh Wanve
CVE-2006-6794 EXPLOITDB text VERIFIED
Efkan Forum 1.0 - SQL Injection via Grup Parameter
SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter.
by ShaFuq31
CVE-2006-6715 EXPLOITDB text VERIFIED
PowerClan < 1.14a - Remote File Inclusion via footer.inc.php settings[footer] Parameter
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings[footer] parameter.
by nuffsaid
EIP-2026-110907 EXPLOITDB text VERIFIED
PHP/Mysql Site Builder 0.0.2 - 'htm2PHP.php' File Disclosure
by the master
CVE-2006-6710 EXPLOITDB text VERIFIED
PgmReloaded < 0.8.5 - Remote Code Execution via PHP File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c) form_header.php.
by nuffsaid
CVE-2006-6711 EXPLOITDB text VERIFIED
Newxooper 0.9.1 - Remote File Inclusion via compteur/mapage.php chemin Parameter
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
by 3l3ctric-Cracker
CVE-2006-6741 EXPLOITDB text VERIFIED
mkportal - Cross-Site Request Forgery via img BBcode Tag
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.
by Demential
CVE-2006-6726 EXPLOITDB text VERIFIED
inertianews 0.02 beta - Remote Code Execution via inews_path Parameter
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.
by bd0rk
CVE-2006-6691 EXPLOITDB text VERIFIED
Valdersoft Shopping Cart <3.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.
by mdx
CVE-2006-6690 EXPLOITDB text VERIFIED
Typo3 <4.0.3, 3.7, 3.8, 4.1 beta - Authenticated Command Injection
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
by D. Fabian
CVE-2006-6686 EXPLOITDB text VERIFIED
textsend < 1.5 - Remote File Inclusion via ROOT_PATH Parameter
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.
by nuffsaid
EIP-2026-105688 EXPLOITDB text VERIFIED
Calacode @Mail Webmail 4.51 - Filtering Engine HTML Injection
by Philippe C. Caturegli