|
284051
|
- |
|
openmedia
|
openmedia
|
Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_…
|
NVD-CWE-Other
|
CVE-2007-0088
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284052
|
- |
|
jgbbs
|
jgbbs
|
jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.
|
NVD-CWE-Other
|
CVE-2007-0089
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284053
|
- |
|
fermentigrafici
|
wineglass
|
WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.…
|
NVD-CWE-Other
|
CVE-2007-0090
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284054
|
- |
|
cms-center
|
simple_web_cms
|
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2007-0093
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284055
|
- |
|
sven_moderow
|
sven_moderow_guestbook
|
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct re…
|
NVD-CWE-Other
|
CVE-2007-0094
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284056
|
- |
|
conexware
|
powerarchiver_2006
|
Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execu…
|
NVD-CWE-Other
|
CVE-2007-0097
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284057
|
- |
|
microsoft
|
xml_core_services internet_explorer
|
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of s…
|
CWE-362
Race Condition
|
CVE-2007-0099
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284058
|
- |
|
perforce
|
perforce_client
|
The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client …
|
NVD-CWE-Other
|
CVE-2007-0100
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284059
|
- |
|
xpdf kde
|
xpdf kde
|
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impac…
|
CWE-20
Improper Input Validation
|
CVE-2007-0104
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284060
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token…
|
NVD-CWE-Other
|
CVE-2007-0106
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|