Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-5661 EXPLOITDB text VERIFIED
VIRtech Netquery - Cross-Site Scripting via User-Agent HTTP Header
Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
by Tal Argoni
CVE-2006-5712 EXPLOITDB text VERIFIED
Mirapoint WebMail - Cross-Site Scripting via CSS Expression in IMG Width
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.
by LegendaryZion
CVE-2006-5652 EXPLOITDB text VERIFIED
Sun iPlanet Messaging Server Messenger Express - Cross-Site Scripting via CSS Expression
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.
by LegendaryZion
CVE-2006-5669 EXPLOITDB text VERIFIED
Gepi < 1.4.4 - Remote File Inclusion via gestion/savebackup.php filename Parameter
PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.
by Sumit Siddharth
EIP-2026-106702 EXPLOITDB text VERIFIED
Easy Web Portal 2.1.2 - Multiple Remote File Inclusions
by MEFISTO
CVE-2006-5653 EXPLOITDB text VERIFIED
Sun Java System Messenger Express 6 - Cross-Site Scripting via Error Parameter
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.
by Handrix
CVE-2006-5711 EXPLOITDB text VERIFIED
ECI Telecom B-FOCuS Wireless - Info Disclosure
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.
by LegendaryZion
EIP-2026-115713 EXPLOITDB text VERIFIED
Microsoft Internet Explorer 6.0/7.0 - 'RemoveChild' Denial of Service
by Wojciech H
EIP-2026-112641 EXPLOITDB text VERIFIED
The Search Engine Project 0.942 - 'Configfunction.php' Remote File Inclusion
by Cyber Security
EIP-2026-111586 EXPLOITDB text VERIFIED
PunBB 1.x - SQL Injection
by nmsh_sa
CVE-2006-5634 EXPLOITDB text VERIFIED
phpProfiles < 2.1_beta - Remote Code Execution via reqpath or usrinc Parameter
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php.
by v1per-haCker
EIP-2026-107765 EXPLOITDB text VERIFIED
IG Shop 1.4 - 'Change_Pass.php' Cross-Site Scripting
by SnipEr.X
CVE-2006-5716 EXPLOITDB text VERIFIED
FreeNews 2.1 - Directory Traversal via chemin Parameter
Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is not set to "1."
by MoHaNdKo
CVE-2006-5643 EXPLOITDB text VERIFIED
foresite CMS - Cross-Site Scripting via Search Query Parameter
Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.
by David Vieira-Kurz
CVE-2006-7184 EXPLOITDB text VERIFIED
Exhibit Engine < 1.22 - Remote File Inclusion via toroot Parameter
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
CVE-2006-7184 EXPLOITDB text VERIFIED
Exhibit Engine < 1.22 - Remote File Inclusion via toroot Parameter
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
CVE-2007-2065 EXPLOITDB text VERIFIED
Robert Ladstaetter ActionPoll 1.1.1 - RCE
PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Cyber Security
CVE-2007-2064 EXPLOITDB text VERIFIED
Robert Ladstaetter ActionPoll 1.1.0-1.1.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.
by Cyber Security
CVE-2006-5640 EXPLOITDB text VERIFIED
Techno Dreams Guest Book < 1.0 - SQL Injection via key Parameter
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
CVE-2006-5641 EXPLOITDB text VERIFIED
Techno Dreams Announcement - SQL Injection via MainAnnounce2.asp key Parameter
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.
by ajann
CVE-2006-5662 EXPLOITDB text VERIFIED
easy_notesmanager 0.0.1 - SQL Injection via Username Parameter or Search Page
SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."
by poplix
CVE-2006-5662 EXPLOITDB text VERIFIED
easy_notesmanager 0.0.1 - SQL Injection via Username Parameter or Search Page
SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."
by poplix
CVE-2006-5636 EXPLOITDB text VERIFIED
Simple Website Software <0.99 - RCE
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.
by Mehmet Ince
CVE-2006-5638 EXPLOITDB text VERIFIED
phpmyring < 4.2.1 - SQL Injection via cherche.php limite or mots Parameters
Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.
by ajann
CVE-2006-5637 EXPLOITDB text VERIFIED
Faq Administrator 2.1b - Remote File Inclusion via faq_reply.php Email Parameter
PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.
by v1per-haCker