|
283671
|
- |
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the del…
|
NVD-CWE-Other
|
CVE-2007-1244
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283672
|
- |
|
irfanview
|
irfanview
|
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1245
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283673
|
- |
|
mplayer
|
mplayer
|
The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1246
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283674
|
- |
|
mplayer
|
mplayer
|
Failed exploit attempts will likely result in a denial-of-service condition.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1246
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283675
|
- |
|
aweb_labs
|
awebnews
|
Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) vis…
|
CWE-94
Code Injection
|
CVE-2007-1247
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283676
|
- |
|
aweb_labs
|
awebnews
|
Successful exploitation requires that "register_globals" is enabled.
|
CWE-94
Code Injection
|
CVE-2007-1247
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283677
|
- |
|
built2go
|
news_manager_blog
|
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1248
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283678
|
- |
|
angel_learning
|
learning_management_suite
|
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2007-1250
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283679
|
- |
|
netrek
|
netrek_vanilla_server
|
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-1251
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283680
|
- |
|
netrek
|
netrek_vanilla_server
|
This vulnerability is addressed in the following product update:
http://sourceforge.net/project/shownotes.php?release_id=490561
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-1251
|
2018-10-17 01:37 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|