|
284751
|
- |
|
gekkoware
|
gekko
|
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrate…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6361
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284752
|
- |
|
joomla
|
rs_gallery2
|
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cati…
|
CWE-89
SQL Injection
|
CVE-2007-6362
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284753
|
- |
|
jlmforo_system
|
jlmforo_system
|
Cross-site scripting (XSS) vulnerability in modificarPerfil.php in JLMForo System allows remote authenticated users to inject arbitrary web script or HTML via a signature.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6364
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284754
|
- |
|
sinecms
|
sinecms
|
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Ca…
|
CWE-89
SQL Injection
|
CVE-2007-6366
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284755
|
- |
|
sinecms
|
sinecms
|
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comm…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6367
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284756
|
- |
|
ezcontents
|
ezcontents
|
Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6368
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284757
|
- |
|
bitweaver
|
bitweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) sea…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6374
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284758
|
- |
|
bitweaver
|
bitweaver
|
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highl…
|
CWE-89
SQL Injection
|
CVE-2007-6375
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284759
|
- |
|
badblue
|
badblue
|
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6377
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284760
|
- |
|
badblue
|
badblue
|
Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6378
|
2018-10-16 06:52 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|