|
284861
|
- |
|
scribe
|
scribe
|
Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a certain file in regged/ via the username parameter…
|
CWE-94
Code Injection
|
CVE-2007-5822
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284862
|
- |
|
scribe
|
scribe
|
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the username parameter in a Regist…
|
CWE-22
Path Traversal
|
CVE-2007-5823
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284863
|
- |
|
firefly
|
media_server
|
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (…
|
CWE-20
Improper Input Validation
|
CVE-2007-5824
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284864
|
- |
|
firefly
|
media_server
|
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-5825
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284865
|
- |
|
bosdev
|
bosmarket_business_directory_system
|
Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account de…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5833
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284866
|
- |
|
bosdev
|
bosnews
|
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5834
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284867
|
- |
|
bosdev
|
bosnews
|
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5835
|
2018-10-16 06:46 |
2007-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284868
|
- |
|
net-snmp
|
net-snmp
|
The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.
|
CWE-399
Resource Management Errors
|
CVE-2007-5846
|
2018-10-16 06:46 |
2007-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284869
|
- |
|
apple
|
mac_os_x
|
Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5848
|
2018-10-16 06:46 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284870
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution d…
|
CWE-310
Cryptographic Issues
|
CVE-2007-5863
|
2018-10-16 06:46 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|