|
283921
|
- |
|
proxy_anket
|
proxy_anket
|
SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2007-4837
|
2018-10-16 06:38 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283922
|
- |
|
php
|
php
|
PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in…
|
CWE-20
Improper Input Validation
|
CVE-2007-4840
|
2018-10-16 06:38 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283923
|
- |
|
enriva_development
|
magellan_explorer
|
Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename…
|
CWE-22
Path Traversal
|
CVE-2007-4842
|
2018-10-16 06:38 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283924
|
- |
|
x-diesel
|
unreal_commander
|
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this ca…
|
CWE-22
Path Traversal
|
CVE-2007-4843
|
2018-10-16 06:38 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283925
|
- |
|
x-diesel
|
unreal_commander
|
X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CWD /" command, which allows remote FTP servers to cause a denial of service (inf…
|
CWE-20
Improper Input Validation
|
CVE-2007-4844
|
2018-10-16 06:38 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283926
|
- |
|
php
|
php
|
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4850
|
2018-10-16 06:38 |
2008-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283927
|
- |
|
quirm
|
saxon
|
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-ite…
|
CWE-200
Information Exposure
|
CVE-2007-4861
|
2018-10-16 06:38 |
2007-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283928
|
- |
|
quirm
|
saxon
|
Vendor patch information can be found at:
http://www.quirm.net/page.php?id=38
|
CWE-200
Information Exposure
|
CVE-2007-4861
|
2018-10-16 06:38 |
2007-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283929
|
- |
|
quirm
|
saxon
|
Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-4862
|
2018-10-16 06:38 |
2007-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283930
|
- |
|
quirm
|
saxon
|
SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.
|
CWE-89
SQL Injection
|
CVE-2007-4863
|
2018-10-16 06:38 |
2007-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|