|
284741
|
- |
|
vu
|
mass_mailer
|
SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of the…
|
CWE-89
SQL Injection
|
CVE-2007-6138
|
2018-10-16 06:50 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284742
|
- |
|
mp3
|
toolbox
|
PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter.
|
CWE-94
Code Injection
|
CVE-2007-6139
|
2018-10-16 06:50 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284743
|
- |
|
vbtube
|
vbtube
|
Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6141
|
2018-10-16 06:50 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284744
|
- |
|
vu
|
case_manager
|
SQL injection vulnerability in default.asp (aka the Login Page) in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
CWE-89
SQL Injection
|
CVE-2007-6143
|
2018-10-16 06:50 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284745
|
- |
|
simplegallery
|
simplegallery
|
Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6157
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284746
|
- |
|
proverbs
|
proverbs_web_calendar
|
Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname (aka Username) and (…
|
CWE-89
SQL Injection
|
CVE-2007-6158
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284747
|
- |
|
tilde
|
tilde_cms
|
SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector th…
|
CWE-89
SQL Injection
|
CVE-2007-6159
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284748
|
- |
|
tilde
|
tilde_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a yeardetail action.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6160
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284749
|
- |
|
tilde
|
tilde_cms
|
index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search action, which reveals the path.
|
CWE-200
Information Exposure
|
CVE-2007-6161
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284750
|
- |
|
wsdeluxe
|
fmdeluxe
|
Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6162
|
2018-10-16 06:50 |
2007-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|