|
284681
|
- |
|
perforce
|
p4web
|
P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-L…
|
CWE-399
Resource Management Errors
|
CVE-2007-6349
|
2018-10-16 06:52 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284682
|
- |
|
libexif
|
libexif
|
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail f…
|
CWE-189
Numeric Errors
|
CVE-2007-6352
|
2018-10-16 06:52 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284683
|
- |
|
gekkoware
|
gekko
|
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrate…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6361
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284684
|
- |
|
joomla
|
rs_gallery2
|
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cati…
|
CWE-89
SQL Injection
|
CVE-2007-6362
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284685
|
- |
|
jlmforo_system
|
jlmforo_system
|
Cross-site scripting (XSS) vulnerability in modificarPerfil.php in JLMForo System allows remote authenticated users to inject arbitrary web script or HTML via a signature.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6364
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284686
|
- |
|
sinecms
|
sinecms
|
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Ca…
|
CWE-89
SQL Injection
|
CVE-2007-6366
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284687
|
- |
|
sinecms
|
sinecms
|
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comm…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6367
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284688
|
- |
|
ezcontents
|
ezcontents
|
Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6368
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284689
|
- |
|
bitweaver
|
bitweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) sea…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6374
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284690
|
- |
|
bitweaver
|
bitweaver
|
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highl…
|
CWE-89
SQL Injection
|
CVE-2007-6375
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|