|
288051
|
- |
|
zomplog
|
zomplog
|
admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this ca…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5230
|
2017-10-19 10:30 |
2007-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288052
|
- |
|
zomplog
|
zomplog
|
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modifi…
|
CWE-20
Improper Input Validation
|
CVE-2007-5231
|
2017-10-19 10:30 |
2007-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288053
|
- |
|
wzdftpd
|
wzdftpd
|
Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via …
|
CWE-189 CWE-119
Numeric Errors Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5300
|
2017-10-19 10:30 |
2007-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288054
|
- |
|
verlihub-project
|
verlihub_control_panel
|
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.
|
CWE-94 CWE-22
Code Injection Path Traversal
|
CVE-2007-5321
|
2017-10-19 10:30 |
2007-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288055
|
- |
|
verlihub-project
|
verlihub_control_panel
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
CWE-94 CWE-22
Code Injection Path Traversal
|
CVE-2007-5321
|
2017-10-19 10:30 |
2007-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288056
|
- |
|
cowon_america
|
jetaudio
|
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an EXTM3U section of a .m3u file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5487
|
2017-10-19 10:30 |
2007-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288057
|
- |
|
devmass
|
devmass_cart
|
PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the kfm_base_path param…
|
CWE-20
Improper Input Validation
|
CVE-2007-6133
|
2017-10-19 10:30 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288058
|
- |
|
phpkit
|
phpkit
|
SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a…
|
CWE-89
SQL Injection
|
CVE-2007-6134
|
2017-10-19 10:30 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288059
|
- |
|
p3mbo
|
content_injector
|
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. NOTE: some of these details are obtaine…
|
CWE-89
SQL Injection
|
CVE-2007-6137
|
2017-10-19 10:30 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288060
|
- |
|
iaprcommence
|
iapr_commence
|
Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_pa…
|
CWE-94
Code Injection
|
CVE-2007-6147
|
2017-10-19 10:30 |
2007-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|