|
290021
|
- |
|
raphael_limbach
|
crea-book
|
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.
|
CWE-89
SQL Injection
|
CVE-2007-2000
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290022
|
- |
|
crea-book
|
crea-book
|
Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la…
|
NVD-CWE-Other
|
CVE-2007-2001
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290023
|
- |
|
inoutmailinglistmanager
|
inoutmailinglistmanager
|
InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.
|
NVD-CWE-Other
|
CVE-2007-2002
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290024
|
- |
|
inoutmailinglistmanager
|
inoutmailinglistmanager
|
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality…
|
NVD-CWE-Other
|
CVE-2007-2003
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290025
|
- |
|
inoutmailinglistmanager
|
inoutmailinglistmanager
|
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified…
|
NVD-CWE-Other
|
CVE-2007-2004
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290026
|
- |
|
joomla mambo
|
taskhopper_component
|
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path …
|
CWE-94
Code Injection
|
CVE-2007-2005
|
2017-10-11 10:32 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290027
|
- |
|
adobe opera
|
flash_player opera_browser
|
Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to…
|
CWE-200
Information Exposure
|
CVE-2007-2022
|
2017-10-11 10:32 |
2007-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290028
|
- |
|
elinks
|
elinks
|
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalo…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-2027
|
2017-10-11 10:32 |
2007-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290029
|
- |
|
elinks
|
elinks
|
An untrusted message catalog might lead to a format-string attack when an
attacker tricks user into launching links from a particular directory.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-2027
|
2017-10-11 10:32 |
2007-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290030
|
- |
|
freeradius
|
freeradius
|
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format…
|
NVD-CWE-Other
|
CVE-2007-2028
|
2017-10-11 10:32 |
2007-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|