|
284241
|
- |
|
norman
|
norman_virus_control
|
Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around."
|
NVD-CWE-Other
|
CVE-2007-3951
|
2018-10-16 06:32 |
2007-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284242
|
- |
|
norman
|
normon_antivirus
|
The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an "integer cast around".
|
NVD-CWE-Other
|
CVE-2007-3952
|
2018-10-16 06:32 |
2007-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284243
|
- |
|
norman
|
norman_virus_control
|
The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to cause a denial of service via a crafted DOC file that triggers a divide-by-zero error.
|
NVD-CWE-Other
|
CVE-2007-3953
|
2018-10-16 06:32 |
2007-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284244
|
- |
|
usebb
|
usebb
|
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1…
|
NVD-CWE-Other
|
CVE-2007-3963
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284245
|
- |
|
iexpress
|
munch_pro
|
SQL injection vulnerability in Munch Pro allows remote attackers to execute arbitrary SQL commands via the login field to /admin, a different vulnerability than CVE-2006-5880.
|
NVD-CWE-Other
|
CVE-2007-3966
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284246
|
- |
|
jblog
|
jblog
|
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter o…
|
NVD-CWE-Other
|
CVE-2007-3973
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284247
|
- |
|
jblog
|
jblog
|
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters.
|
NVD-CWE-Other
|
CVE-2007-3974
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284248
|
- |
|
elite_forum
|
elite_forum
|
Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vul…
|
NVD-CWE-Other
|
CVE-2007-3975
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284249
|
- |
|
junction_quest
|
image_racer
|
SQL injection vulnerability in SearchResults.asp in ImageRacer 1.0, when WordSearchCrit is enabled, allows remote attackers to execute arbitrary SQL commands via the SearchWord parameter.
|
NVD-CWE-Other
|
CVE-2007-3987
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284250
|
- |
|
virtual_hosting_control_system
|
virtual_hosting_control_system
|
Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2007-3988
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|