|
283721
|
- |
|
marcello_vitagliano
|
meganoides_news
|
PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.
|
NVD-CWE-Other
|
CVE-2007-1024
|
2018-10-17 01:36 |
2007-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283722
|
- |
|
scriptdungeon
|
xlatunes
|
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are ob…
|
CWE-89
SQL Injection
|
CVE-2007-1026
|
2018-10-17 01:36 |
2007-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283723
|
- |
|
quicksoft
|
easymail_objects
|
Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.
|
NVD-CWE-Other
|
CVE-2007-1029
|
2018-10-17 01:36 |
2007-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283724
|
- |
|
niels_provos
|
libevent
|
Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.
|
NVD-CWE-Other
|
CVE-2007-1030
|
2018-10-17 01:36 |
2007-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283725
|
- |
|
jboss
|
jboss_application_server
|
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1036
|
2018-10-17 01:36 |
2007-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283726
|
- |
|
ezboo
|
webstats
|
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
|
NVD-CWE-Other
|
CVE-2007-1043
|
2018-10-17 01:36 |
2007-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283727
|
- |
|
pearson_education
|
powerschool
|
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: …
|
CWE-200
Information Exposure
|
CVE-2007-1044
|
2018-10-17 01:36 |
2007-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283728
|
- |
|
malbum
|
malbum
|
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1045
|
2018-10-17 01:36 |
2007-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283729
|
- |
|
malbum
|
malbum
|
mAlbum should reconfigure their administrative login and password from their default values.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1045
|
2018-10-17 01:36 |
2007-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283730
|
- |
|
dem_trac
|
dem_trac
|
Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.
|
NVD-CWE-Other
|
CVE-2007-1046
|
2018-10-17 01:36 |
2007-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|