|
284111
|
- |
|
php
|
php
|
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.
|
NVD-CWE-Other
|
CVE-2007-4255
|
2018-10-16 06:34 |
2007-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284112
|
- |
|
ez_photo_sales
|
ez_photo_sales
|
EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user interf…
|
NVD-CWE-Other
|
CVE-2007-4259
|
2018-10-16 06:34 |
2007-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284113
|
- |
|
ez_photo_sales
|
ez_photo_sales
|
EZPhotoSales 1.9.3 and earlier has a default "admin" account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username.
|
NVD-CWE-Other
|
CVE-2007-4260
|
2018-10-16 06:34 |
2007-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284114
|
- |
|
ez_photo_sales
|
ez_photo_sales
|
Unrestricted file upload vulnerability in EZPhotoSales 1.9.3 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP code under OnlineViewing/galleries/.
|
NVD-CWE-Other
|
CVE-2007-4262
|
2018-10-16 06:34 |
2007-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284115
|
- |
|
ez_photo_sales
|
ez_photo_sales
|
EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords vi…
|
CWE-255
Credentials Management
|
CVE-2007-4261
|
2018-10-16 06:34 |
2007-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284116
|
- |
|
coppermine
|
coppermine_photo_gallery
|
PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter.
|
NVD-CWE-Other
|
CVE-2007-4283
|
2018-10-16 06:34 |
2007-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284117
|
- |
|
cisco
|
meetingplace_web_confrencing
|
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1…
|
NVD-CWE-Other
|
CVE-2007-4284
|
2018-10-16 06:34 |
2007-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284118
|
- |
|
cisco
|
ios
|
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4286
|
2018-10-16 06:34 |
2007-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284119
|
- |
|
sun
|
java_system_portal_server
|
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a c…
|
NVD-CWE-Other
|
CVE-2007-4289
|
2018-10-16 06:34 |
2007-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284120
|
- |
|
adaptec
|
aacraid_controller
|
The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local user…
|
NVD-CWE-Other
|
CVE-2007-4308
|
2018-10-16 06:34 |
2007-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|