Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6338 EXPLOITDB text VERIFIED
deV!L`z Clanportal < 1.3.6.1 - Unauthenticated Arbitrary File Upload via Image File Embedding
Unrestricted file upload vulnerability in upload/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to upload and execute arbitrary .php files by embedding PHP code in a JPEG or GIF file that is uploaded to inc/images/uploads/userpics/.
by Tim Weber
CVE-2006-6339 EXPLOITDB text VERIFIED
deV!L'z Clanportal <1.3.6.1 - SQL Injection
SQL injection vulnerability in sites/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to execute arbitrary SQL commands via the show element in a GET request.
by Tim Weber
CVE-2006-6277 EXPLOITDB text VERIFIED
ContentServ 4.x - Directory Traversal via admin/FileServer.php src Parameter
Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter, a different vector than CVE-2005-3086.
by qobaiashi
CVE-2006-6381 EXPLOITDB text VERIFIED
Ultimate HelpDesk - Directory Traversal via getfile.asp Filename Parameter
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
by ajann
CVE-2006-6343 EXPLOITDB text VERIFIED
Neocrome Seditio <1.10 - SQL Injection
SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2006-6577 EXPLOITDB text VERIFIED
Neocrome Land Down Under 8.x and earlier - SQL Injection via polls.php id Parameter
SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by ajann
CVE-2006-6417 EXPLOITDB text VERIFIED
b2evolution 1.8.5-1.9 beta - Remote File Inclusion via inc_path Parameter
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
by tarkus
CVE-2006-7114 EXPLOITDB text VERIFIED
P-News 2.0 - Unauthenticated Sensitive Information Exposure via db/user.txt
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. NOTE: this might be the same issue as CVE-2006-6888.
by Lu7k
CVE-2006-6247 EXPLOITDB text VERIFIED
Uapplication UPhotoGallery 1.1 - SQL Injection via ci Parameter
Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp.
by Aria-Security Team
CVE-2006-6247 EXPLOITDB text VERIFIED
Uapplication UPhotoGallery 1.1 - SQL Injection via ci Parameter
Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp.
by Aria-Security Team
CVE-2006-6207 EXPLOITDB text VERIFIED
Evolve Merchant - SQL Injection via products.asp partno Parameter
SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error
by Aria-Security Team
CVE-2006-6181 EXPLOITDB text VERIFIED
ClickTech ClickContact - SQL Injection via AlphaSort, In, or orderby Parameters
Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters.
by Aria-Security Team
CVE-2006-6189 EXPLOITDB text VERIFIED
ClickTech ClickBlog - SQL Injection via displayCalendar.asp Date Parameter
SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter.
by Aria-Security Team
EIP-2026-100201 EXPLOITDB text VERIFIED
Click Gallery - Multiple Input Validation Vulnerabilities
by Aria-Security Team
CVE-2006-6203 EXPLOITDB text VERIFIED
Flyspray ME 1.0.1 - Directory Traversal via File Parameter
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by 3l3ctric-Cracker
CVE-2006-6216 EXPLOITDB text VERIFIED
Nivisec Hacks List < 1.21 - SQL Injection via hack_id Parameter
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remote attackers to execute arbitrary SQL commands via the hack_id parameter.
by the master
CVE-2006-6129 EXPLOITDB text VERIFIED
Mac OS X - Denial of Service and Possible Remote Code Execution via Crafted Mach-O Universal Program
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.
by LMH
CVE-2006-6191 EXPLOITDB text VERIFIED
8pixel.net simpleblog <= 2.3 - SQL Injection via admin/edit.asp id Parameter
SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by bolivar
CVE-2006-6138 EXPLOITDB text VERIFIED
Sisfo Kampus 0.8 - Directory Traversal via download.php dir Parameter
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.
by Wawan Firmansyah
CVE-2006-6137 EXPLOITDB text VERIFIED
Sisfo Kampus 0.8 - Remote File Inclusion via exec or print Parameter
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) print parameter to print.php, which is also accessible via the print command to index.php.
by Wawan Firmansyah
CVE-2006-6140 EXPLOITDB text VERIFIED
Sisfo Kampus 2006 - Remote File Inclusion via slnt Parameter
PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by Wawan Firmansyah
CVE-2006-7183 EXPLOITDB text VERIFIED
Exhibit Engine 2 < 1.22 - Remote File Inclusion via toroot Parameter
PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.
by Kacper
CVE-2006-6198 EXPLOITDB text VERIFIED
cPanel WebHost Manager 3.1.0 - Authenticated Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
by Aria-Security Team
CVE-2006-6198 EXPLOITDB text VERIFIED
cPanel WebHost Manager 3.1.0 - Authenticated Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
by Aria-Security Team
CVE-2006-6198 EXPLOITDB text VERIFIED
cPanel WebHost Manager 3.1.0 - Authenticated Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) email parameter to (a) scripts2/dochangeemail, the (2) supporturl parameter to (b) cgi/addon_configsupport.cgi, the (3) pkg parameter to (c) scripts/editpkg, the (4) domain parameter to (d) scripts2/domts2 and (e) scripts/editzone, the (5) feature parameter to (g) scripts2/dofeaturemanager, and the (6) ndomain parameter to (h) scripts/park.
by Aria-Security Team