|
283571
|
- |
|
xoops
|
friendfinder_module
|
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2007-1838
|
2018-10-17 01:40 |
2007-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283572
|
- |
|
maptools
|
maplab
|
PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath …
|
CWE-94
Code Injection
|
CVE-2007-1843
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283573
|
- |
|
avatic
|
aardvark_topsites_php
|
Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) …
|
NVD-CWE-Other
|
CVE-2007-1844
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283574
|
- |
|
php_fusion
|
expanded_calendar_module
|
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.
|
NVD-CWE-Other
|
CVE-2007-1845
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283575
|
- |
|
drake_team
|
drake_cms
|
Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field. NOTE: Drake CMS has only…
|
NVD-CWE-Other
|
CVE-2007-1848
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283576
|
- |
|
drake_team
|
drake_cms
|
Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via …
|
NVD-CWE-Other
|
CVE-2007-1850
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283577
|
- |
|
webasyst_llc
|
shop-script
|
Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) s…
|
NVD-CWE-Other
|
CVE-2007-1855
|
2018-10-17 01:40 |
2007-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283578
|
- |
|
linux
|
linux_kernel
|
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infini…
|
CWE-399
Resource Management Errors
|
CVE-2007-1861
|
2018-10-17 01:40 |
2007-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283579
|
- |
|
microsoft
|
windows_2003_server windows_xp
|
\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using…
|
NVD-CWE-Other
|
CVE-2007-1537
|
2018-10-17 01:39 |
2007-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283580
|
- |
|
radscan
|
network_audio_system
|
Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long p…
|
NVD-CWE-Other
|
CVE-2007-1543
|
2018-10-17 01:39 |
2007-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|