|
289261
|
- |
|
digitizing_quote_and_ordering_system
|
digitizing_quote_and_ordering_system
|
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parame…
|
NVD-CWE-Other
|
CVE-2007-0144
|
2017-10-19 10:29 |
2007-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289262
|
- |
|
allmyphp
|
allmyvisitors
|
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.
|
NVD-CWE-Other
|
CVE-2007-0170
|
2017-10-19 10:29 |
2007-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289263
|
- |
|
l2j
|
statistik_script
|
Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute …
|
NVD-CWE-Other
|
CVE-2007-0173
|
2017-10-19 10:29 |
2007-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289264
|
- |
|
motionborg
|
motionborg_web_real_estate
|
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName paramet…
|
CWE-89
SQL Injection
|
CVE-2007-0196
|
2017-10-19 10:29 |
2007-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289265
|
- |
|
geoffrey_golliher
|
axiom_photo_news_gallery
|
PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiom…
|
NVD-CWE-Other
|
CVE-2007-0200
|
2017-10-19 10:29 |
2007-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289266
|
- |
|
virtual_programming
|
vp-asp
|
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.
|
NVD-CWE-Other
|
CVE-2007-0224
|
2017-10-19 10:29 |
2007-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289267
|
- |
|
virtual_programming
|
vp-asp
|
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
NVD-CWE-Other
|
CVE-2007-0225
|
2017-10-19 10:29 |
2007-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289268
|
- |
|
wordpress
|
wordpress
|
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which …
|
NVD-CWE-Other
|
CVE-2007-0233
|
2017-10-19 10:29 |
2007-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289269
|
- |
|
snews
|
snews
|
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an ad…
|
NVD-CWE-Other
|
CVE-2007-0261
|
2017-10-19 10:29 |
2007-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289270
|
- |
|
tlm_cms
|
tlm_cms
|
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
|
NVD-CWE-Other
|
CVE-2007-0300
|
2017-10-19 10:29 |
2007-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|