|
284121
|
- |
|
fermentigrafici
|
wineglass
|
WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.…
|
NVD-CWE-Other
|
CVE-2007-0090
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284122
|
- |
|
cms-center
|
simple_web_cms
|
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2007-0093
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284123
|
- |
|
sven_moderow
|
sven_moderow_guestbook
|
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct re…
|
NVD-CWE-Other
|
CVE-2007-0094
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284124
|
- |
|
conexware
|
powerarchiver_2006
|
Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execu…
|
NVD-CWE-Other
|
CVE-2007-0097
|
2018-10-17 01:31 |
2007-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284125
|
- |
|
microsoft
|
xml_core_services internet_explorer
|
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of s…
|
CWE-362
Race Condition
|
CVE-2007-0099
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284126
|
- |
|
perforce
|
perforce_client
|
The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client …
|
NVD-CWE-Other
|
CVE-2007-0100
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284127
|
- |
|
xpdf kde
|
xpdf kde
|
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impac…
|
CWE-20
Improper Input Validation
|
CVE-2007-0104
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284128
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token…
|
NVD-CWE-Other
|
CVE-2007-0106
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284129
|
- |
|
wordpress
|
wordpress
|
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and e…
|
NVD-CWE-Other
|
CVE-2007-0107
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284130
|
- |
|
wordpress
|
wordpress
|
Successful exploitation requires that the "mbstring" extension be enabled.
This vulnerability is addressed in the following product release:
WordPress, WordPress, 2.0.6
|
NVD-CWE-Other
|
CVE-2007-0107
|
2018-10-17 01:31 |
2007-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|