Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104922 EXPLOITDB text VERIFIED
Active PHP BookMarks 1.1.2 - Multiple Remote File Inclusions
by ThE-LoRd-Of-CrAcKiNg
EIP-2026-115744 EXPLOITDB text VERIFIED
Microsoft Office 97 - HTMLMARQ.OCX Library Denial of Service
by Michal Bucko
CVE-2006-6158 EXPLOITDB text VERIFIED
Ace Helpdesk 2.31 - Cross-Site Scripting via Ticket View and Ticket Parameters
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
by SwEET-DeViL
CVE-2006-6158 EXPLOITDB text VERIFIED
Ace Helpdesk 2.31 - Cross-Site Scripting via Ticket View and Ticket Parameters
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
by SwEET-DeViL
CVE-2006-6078 EXPLOITDB text VERIFIED
a-ConMan 3.2 beta - Remote File Inclusion via cm_basedir Parameter
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the cm_basedir parameter.
by Matdhule
CVE-2006-6117 EXPLOITDB text VERIFIED
fipsgallery < 1.5 - SQL Injection via which Parameter
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.
by ajann
CVE-2006-6116 EXPLOITDB text VERIFIED
fipsforum < 2.6 - SQL Injection via kat Parameter
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.
by ajann
CVE-2006-6177 EXPLOITDB text VERIFIED
Neocrome Seditio < 1.10 - Authenticated SQL Injection via Double-Encoded ID Parameter
SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).
by nukedx
EIP-2026-111968 EXPLOITDB text VERIFIED
Seditio 1.10 - 'Users.Profile.Inc.php' SQL Injection
by Mustafa Can Bjorn
CVE-2006-7136 EXPLOITDB text VERIFIED
PHP Poll Creator < 1.04 - Remote File Inclusion via relativer_pfad Parameter
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.
by iss4m
CVE-2006-6093 EXPLOITDB text VERIFIED
PicturesPro Photo Cart 3.9 - Remote File Inclusion via admin_folder or path Parameter
Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.
by irvian
EIP-2026-110534 EXPLOITDB text VERIFIED
Pearl Forums 2.4 - Multiple Remote File Inclusions
by 3l3ctric-Cracker
CVE-2006-6087 EXPLOITDB text VERIFIED
my_little_weblog - Cross-Site Scripting via Action Parameter
Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.
by the_Edit0r
CVE-2006-6577 EXPLOITDB text VERIFIED
Neocrome Land Down Under 8.x and earlier - SQL Injection via polls.php id Parameter
SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by nukedx
EIP-2026-106304 EXPLOITDB text VERIFIED
CuteNews 1.4.5 - 'show_news.php' Cross-Site Scripting
by Alireza Hassani
EIP-2026-106303 EXPLOITDB text VERIFIED
CuteNews 1.4.5 - 'rss_title' Cross-Site Scripting
by Alireza Hassani
CVE-2006-6084 EXPLOITDB text VERIFIED
aBitWhizzy - Directory Traversal via f Parameter
Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.
by Security Access Point
CVE-2006-6062 EXPLOITDB text VERIFIED
Apple Mac OS X 10.4.8 - Denial of Service via Malformed UDTO HFS+ Disk Image
Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.
by LMH
EIP-2026-100394 EXPLOITDB text VERIFIED
Link Exchange Lite 1.0 - Multiple SQL Injections
by laurent gaffie
CVE-2006-6147 EXPLOITDB text VERIFIED
JiRos Links Manager - SQL Injection via LinkID or CategoryID Parameter
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
by laurent gaffie
CVE-2006-6147 EXPLOITDB text VERIFIED
JiRos Links Manager - SQL Injection via LinkID or CategoryID Parameter
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
by laurent gaffie
CVE-2006-6082 EXPLOITDB text VERIFIED
CreaScripts Creadirectory - Cross-Site Scripting via cat Parameter or search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
by laurent gaffie
CVE-2006-6083 EXPLOITDB text VERIFIED
CreaScripts Creadirectory - SQL Injection via search.asp Category Parameter
SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.
by laurent gaffie
CVE-2006-6082 EXPLOITDB text VERIFIED
CreaScripts Creadirectory - Cross-Site Scripting via cat Parameter or search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
by laurent gaffie
CVE-2006-6185 EXPLOITDB text VERIFIED
Wabbit PHP Gallery 0.9 - Directory Traversal via Dir Parameter
Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.
by the_Edit0r