Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6536 EXPLOITDB text VERIFIED
Cilem Haber Free Edition - Cross-Site Scripting via hata Parameter
Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by ShaFuck31
CVE-2006-6550 EXPLOITDB text VERIFIED
Phorum <= 3.2.11 - Remote File Inclusion via db_file Parameter
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
by Mr-m07
CVE-2006-6414 EXPLOITDB text VERIFIED
dol_storye - SQL Injection via id_doc or id_aut Parameter
Multiple SQL injection vulnerabilities in dettaglio.asp in dol storye allow remote attackers to execute arbitrary SQL commands via the (1) id_doc or (2) id_aut parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by WarGame
CVE-2006-6310 EXPLOITDB text VERIFIED
Microsoft Internet Explorer <6.0 SP1 - DoS
Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by Juan Pablo Lopez
CVE-2006-6364 EXPLOITDB text VERIFIED
Inside Systems Mail <= 2.0 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
by Vicente Aguilera Diaz
CVE-2006-6546 EXPLOITDB text VERIFIED
cutenews_aj-fork 167f - Remote File Inclusion via cutepath Parameter
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter.
by DeltahackingTEAM
CVE-2006-6366 EXPLOITDB text VERIFIED
Cerberus Helpdesk 0.97.3 2.0-2.7 3.2.1 3.3 - Cross-Site Scripting via Spellcheck js Parameter
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by En Douli
CVE-2006-6389 EXPLOITDB text VERIFIED
ac4p_mobile - Cross-Site Scripting via Taaa Parameter or Polls Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.
by SwEET-DeViL
CVE-2006-6389 EXPLOITDB text VERIFIED
ac4p_mobile - Cross-Site Scripting via Taaa Parameter or Polls Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.
by SwEET-DeViL
CVE-2006-6363 EXPLOITDB text VERIFIED
BlueSocket Secure Controller <5.2 - XSS
Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attackers to inject arbitrary web script or HTML via the ad_name parameter.
by Jesus Olmos Gonzalez
CVE-2006-6447 EXPLOITDB text VERIFIED
vt-forum_lite 1.3 and 1.5 - Cross-Site Scripting via StrMes Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.
by St@rExT
CVE-2006-6447 EXPLOITDB text VERIFIED
vt-forum_lite 1.3 and 1.5 - Cross-Site Scripting via StrMes Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.
by St@rExT
EIP-2026-100594 EXPLOITDB text VERIFIED
UApplication Uguestbook 1.0 - 'index.asp' SQL Injection
by Aria-Security Team
CVE-2006-4605 EXPLOITDB text VERIFIED
Longino Jacome php-Revista 1.1.2 - Code Injection
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the adodb parameter.
by Cold Zero
CVE-2006-6360 EXPLOITDB text VERIFIED
PHP Upload Center 2.0 - Remote File Inclusion via activate.php footerpage Parameter
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
by GregStar
CVE-2006-6376 EXPLOITDB text VERIFIED
Simple File Manager 0.24a - Path Traversal
Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.
by flame
CVE-2006-6356 EXPLOITDB text VERIFIED
PHPNews 1.3.0 - Cross-Site Scripting via URL, ID, Subject, Username, or Time Parameter
Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter.
by Detefix
CVE-2006-6295 EXPLOITDB text VERIFIED
mx_tinies 1.3.0 - Remote File Inclusion via module_root_path Parameter
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by bd0rk
CVE-2006-6300 EXPLOITDB text VERIFIED
CuteNews 1.3.6 - Cross-Site Scripting via Result Parameter
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
by Detefix
EIP-2026-105422 EXPLOITDB text VERIFIED
BBS E-Market Professional - Full Path Disclosure / File Inclusion
by y3dips
CVE-2006-6367 EXPLOITDB text VERIFIED
DUware DUdownload <1.1 - SQL Injection
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.
by Aria-Security Team
CVE-2006-6355 EXPLOITDB text VERIFIED
DuWare DuClassmate - SQL Injection via iCity Parameter
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.
by Aria-Security Team
CVE-2006-6380 EXPLOITDB text VERIFIED
Ultimate HelpDesk - Cross-Site Scripting via Index.asp Keyword Parameter
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
by ajann
EIP-2026-107907 EXPLOITDB text VERIFIED
Invision Gallery 2.0.7 - 'index.php?IMG' SQL Injection
by infection
CVE-2006-6369 EXPLOITDB text VERIFIED
Invision Community Blog Mod 1.2.4 - SQL Injection
SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
by anonymous