|
284671
|
- |
|
microsoft
|
office
|
Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fi…
|
CWE-255
Credentials Management
|
CVE-2007-6329
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284672
|
- |
|
meridian_software
|
prolog_manager
|
Meridian Prolog Manager 2007, and 7.5 and earlier, sends all usernames and passwords to the client in a (1) cleartext or (2) weakly encrypted format to support client-side login authentication, which…
|
NVD-CWE-Other
|
CVE-2007-6330
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284673
|
- |
|
hp
|
info_center quick_launch_button
|
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe,…
|
CWE-22
Path Traversal
|
CVE-2007-6331
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284674
|
- |
|
hp
|
info_center quick_launch_button
|
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft W…
|
NVD-CWE-Other
|
CVE-2007-6332
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284675
|
- |
|
hp
|
info_center quick_launch_button
|
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote …
|
NVD-CWE-Other
|
CVE-2007-6333
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284676
|
- |
|
ingres
|
ingres
|
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attacker…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6334
|
2018-10-16 06:52 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284677
|
- |
|
trivantis
|
coursemill_enterprise_learning_management_system
|
SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (us…
|
CWE-89
SQL Injection
|
CVE-2007-6338
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284678
|
- |
|
moernaut
|
lsrunase supercrypt
|
Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.
|
CWE-255
Credentials Management
|
CVE-2007-6340
|
2018-10-16 06:52 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284679
|
- |
|
david_castro
|
apache_authcas
|
SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (sessi…
|
CWE-89
SQL Injection
|
CVE-2007-6342
|
2018-10-16 06:52 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284680
|
- |
|
squirrelmail
|
squirrelmail
|
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, whi…
|
CWE-94
Code Injection
|
CVE-2007-6348
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|