|
283761
|
- |
|
interspire
|
activekb
|
SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId parameter in a hideQuestion ToDo action. NOTE: the…
|
CWE-94
Code Injection
|
CVE-2007-5425
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283762
|
- |
|
interspire
|
activekb_nx
|
Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page parameter to the default URI for some directories, …
|
CWE-79
Cross-site Scripting
|
CVE-2007-5426
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283763
|
- |
|
joomla
|
com_search_component joomla
|
Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: …
|
CWE-79
Cross-site Scripting
|
CVE-2007-5427
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283764
|
- |
|
umi-cms
|
umi_cms
|
Cross-site scripting (XSS) vulnerability in UMI CMS allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to the default URI in search_do/.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5428
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283765
|
- |
|
nucleus_cms
|
nucleus_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5429
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283766
|
- |
|
scottmanktelow
|
stride_cms
|
Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id paramete…
|
CWE-89
SQL Injection
|
CVE-2007-5430
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283767
|
- |
|
javaatwork scottmanktelow
|
myftpuploader_module stride
|
include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the …
|
CWE-200
Information Exposure
|
CVE-2007-5431
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283768
|
- |
|
scottmanktelow
|
stride_cms
|
Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php.
|
CWE-200
Information Exposure
|
CVE-2007-5432
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283769
|
- |
|
siteup
|
siteup
|
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Site-Up 2.64 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) search mask field.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5433
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283770
|
- |
|
pro.setun
|
pro-search
|
Cross-site scripting (XSS) vulnerability in PRO-search 0.17.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5434
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|