|
283841
|
- |
|
comscripts
|
j-web_pics_navigator
|
Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.
|
CWE-22
Path Traversal
|
CVE-2007-1144
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283842
|
- |
|
comscripts
|
j-web_pics_navigator
|
J-Web Pics Navigator is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve and edit the…
|
CWE-22
Path Traversal
|
CVE-2007-1144
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283843
|
- |
|
kayako
|
esupport
|
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1145
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283844
|
- |
|
delmaa.com
|
arabhost
|
PHP remote file inclusion vulnerability in function.php in arabhost allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.
|
NVD-CWE-Other
|
CVE-2007-1146
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283845
|
- |
|
hbm
|
hbm
|
PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.
|
CWE-94
Code Injection
|
CVE-2007-1147
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283846
|
- |
|
lovecms
|
lovecms
|
PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.
|
CWE-94
Code Injection
|
CVE-2007-1148
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283847
|
- |
|
lovecms
|
lovecms
|
Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter …
|
CWE-22
Path Traversal
|
CVE-2007-1149
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283848
|
- |
|
lovecms
|
lovecms
|
Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1150
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283849
|
- |
|
lovecms
|
lovecms
|
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.
|
CWE-79
Cross-site Scripting
|
CVE-2007-1151
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283850
|
- |
|
webspell
|
webspell
|
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
|
CWE-89
SQL Injection
|
CVE-2007-1154
|
2018-10-17 01:36 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|