|
289281
|
- |
|
php
|
php
|
Failed exploit attempts will likely cause a denial of serivce on the webserver.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1413
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289282
|
- |
|
triexa
|
sonicmailer_pro
|
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.
|
NVD-CWE-Other
|
CVE-2007-1425
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289283
|
- |
|
x-ice
|
news_system
|
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2007-1438
|
2017-10-11 10:31 |
2007-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289284
|
- |
|
mcgallery
|
mcgallery
|
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
|
CWE-20
Improper Input Validation
|
CVE-2007-1478
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289285
|
- |
|
creative_guestbook
|
creative_guestbook
|
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
NVD-CWE-Other
|
CVE-2007-1479
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289286
|
- |
|
creative_guestbook
|
creative_guestbook
|
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
|
CWE-287
Improper Authentication
|
CVE-2007-1480
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289287
|
- |
|
wbblog
|
wbblog
|
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.
|
NVD-CWE-Other
|
CVE-2007-1481
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289288
|
- |
|
liqua
|
wbblog
|
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.
|
CWE-79
Cross-site Scripting
|
CVE-2007-1482
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289289
|
- |
|
cyber_inside cyberteddy sascha_schroeder
|
weblog
|
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in …
|
NVD-CWE-Other
|
CVE-2007-1487
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289290
|
- |
|
linux
|
linux_kernel
|
nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "…
|
NVD-CWE-Other
|
CVE-2007-1496
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|