|
283661
|
- |
|
nullsoft
|
shoutcast_server
|
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 800…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1229
|
2018-10-17 01:37 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283662
|
- |
|
sqlitemanager
|
sqlitemanager
|
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) v…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1231
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283663
|
- |
|
sqlite_manager
|
sqlite_manager
|
Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.
|
NVD-CWE-Other
|
CVE-2007-1232
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283664
|
- |
|
sqlite_manager
|
sqlite_manager
|
Successful exploitation requires that "magic_quotes_gpc" is disabled. Additionally, in order to exploit this vulnerability to execute arbitrary code, the attacker would first be required to upload a…
|
NVD-CWE-Other
|
CVE-2007-1232
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283665
|
- |
|
bj_sintay
|
sitex
|
Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to se…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1234
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283666
|
- |
|
bj_sintay
|
sitex
|
Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is s…
|
CWE-20
Improper Input Validation
|
CVE-2007-1235
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283667
|
- |
|
sitex
|
sitex
|
sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to cale…
|
NVD-CWE-Other
|
CVE-2007-1236
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283668
|
- |
|
bj_sintay
|
sitex
|
sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL erro…
|
CWE-200
Information Exposure
|
CVE-2007-1237
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283669
|
- |
|
microsoft
|
office
|
Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
|
CWE-399
Resource Management Errors
|
CVE-2007-1238
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283670
|
- |
|
microsoft
|
excel
|
Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted X…
|
NVD-CWE-Other
|
CVE-2007-1239
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|