Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6197 EXPLOITDB text VERIFIED
b2evolution 1.8.2-1.9 beta - Cross-Site Scripting via app_name, baseurl, or ReqURI Parameters
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
by lotto fischer
CVE-2006-6197 EXPLOITDB text VERIFIED
b2evolution 1.8.2-1.9 beta - Cross-Site Scripting via app_name, baseurl, or ReqURI Parameters
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
by lotto fischer
CVE-2006-6937 EXPLOITDB text VERIFIED
Pensacola WEB Designs Xtremeasp Photogallery - SQL Injection
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.
by Aria-Security Team
CVE-2006-6936 EXPLOITDB text VERIFIED
Pensacola WEB Designs Xtremeasp Photogallery - XSS
Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. NOTE: vector 1 likely overlaps CVE-2006-3032.
by Aria-Security Team
CVE-2006-6932 EXPLOITDB text VERIFIED
Image Gallery with Access Database - SQL Injection via id, order, or page Parameter
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
by Aria-Security Team
CVE-2006-6932 EXPLOITDB text VERIFIED
Image Gallery with Access Database - SQL Injection via id, order, or page Parameter
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
by Aria-Security Team
CVE-2006-6088 EXPLOITDB text VERIFIED
BlueCollar i-Gallery 3.4 - Cross-Site Scripting via n or d Parameter
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field, or the myquery parameter, in search.asp. NOTE: some of these details are obtained from third party information.
by Aria-Security Team
CVE-2006-6329 EXPLOITDB text VERIFIED
TorrentFlux 2.2 - Unauthenticated Arbitrary File Deletion via delfile Parameter
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.
by r0ut3r
CVE-2006-6328 EXPLOITDB text VERIFIED
TorrentFlux 2.2 - Directory Traversal and Arbitrary File Write via Alias File Parameter
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.
by r0ut3r
CVE-2006-6124 EXPLOITDB text VERIFIED
SeleniumServer Web Server 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Greg Linares
EIP-2026-118388 EXPLOITDB text VERIFIED
Conxint FTP 2.2.603 - Multiple Directory Traversal Vulnerabilities
by Greg Linares
CVE-2006-6330 EXPLOITDB text VERIFIED
TorrentFlux 2.2 - Command Injection
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.
by r0ut3r
CVE-2006-7086 EXPLOITDB text VERIFIED
Hot Links - Exposure of Sensitive Information via Direct Request with Modified dl Parameter
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
by hack2prison
EIP-2026-100634 EXPLOITDB text VERIFIED
Yetihost Helm 3.2.10 - Multiple Cross-Site Scripting Vulnerabilities
by Aria-Security Team
EIP-2026-100553 EXPLOITDB text VERIFIED
SitesOutlet eCommerce Kit - Multiple SQL Injections
by laurent gaffie
CVE-2006-6066 EXPLOITDB text VERIFIED
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
CVE-2006-6066 EXPLOITDB text VERIFIED
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
CVE-2006-6066 EXPLOITDB text VERIFIED
Dragon Calendar / Events Listing 2.x - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp.
by Benjamin Moss
CVE-2006-6109 EXPLOITDB text VERIFIED
CandyPress Store 3.5.2.14 - SQL Injection via Policy or Brand Parameter
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
by laurent gaffie
CVE-2006-6109 EXPLOITDB text VERIFIED
CandyPress Store 3.5.2.14 - SQL Injection via Policy or Brand Parameter
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
by laurent gaffie
EIP-2026-100133 EXPLOITDB text VERIFIED
ASPIntranet 2.1 - Multiple SQL Injections
by Aria-Security Team
CVE-2006-5975 EXPLOITDB text VERIFIED
BlogMe 3.0 - Stored Cross-Site Scripting via Name URL or Comments Field
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.
by Security Access Point
CVE-2006-5954 EXPLOITDB text VERIFIED
NetVIOS < 2.0 - SQL Injection via NewsID Parameter
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.
by ajann
CVE-2006-5863 EXPLOITDB text VERIFIED
otterware letterit2 - Remote File Inclusion via lang Parameter
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
by Security Access Point
CVE-2006-6451 EXPLOITDB text VERIFIED
Plesk < 8.0.1 - Cross-Site Scripting via get_password.php or login_up.php3 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.
by David Vieira-Kurz