|
289321
|
- |
|
imgallery
|
imgallery
|
users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.
|
NVD-CWE-Other
|
CVE-2007-0082
|
2017-10-19 10:29 |
2007-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289322
|
- |
|
katy_whitton_web_development
|
newscmslite
|
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCM…
|
NVD-CWE-Other
|
CVE-2007-0091
|
2017-10-19 10:29 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289323
|
- |
|
e-smart_cart
|
e-smart_cart
|
SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.
|
NVD-CWE-Other
|
CVE-2007-0092
|
2017-10-19 10:29 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289324
|
- |
|
verliadmin
|
verliadmin
|
Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot …
|
NVD-CWE-Other
|
CVE-2007-0098
|
2017-10-19 10:29 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289325
|
- |
|
acunetix
|
web_vulnerability_scanner
|
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-…
|
NVD-CWE-Other
|
CVE-2007-0120
|
2017-10-19 10:29 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289326
|
- |
|
digiappz
|
digirez
|
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
|
NVD-CWE-Other
|
CVE-2007-0128
|
2017-10-19 10:29 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289327
|
- |
|
locazo
|
locazolist_classifieds
|
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.
|
NVD-CWE-Other
|
CVE-2007-0129
|
2017-10-19 10:29 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289328
|
- |
|
aratix
|
aratix
|
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in t…
|
NVD-CWE-Other
|
CVE-2007-0135
|
2017-10-19 10:29 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289329
|
- |
|
digitizing_quote_and_ordering_system
|
digitizing_quote_and_ordering_system
|
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parame…
|
NVD-CWE-Other
|
CVE-2007-0144
|
2017-10-19 10:29 |
2007-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289330
|
- |
|
allmyphp
|
allmyvisitors
|
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.
|
NVD-CWE-Other
|
CVE-2007-0170
|
2017-10-19 10:29 |
2007-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|