|
285011
|
- |
|
interspire
|
activekb_nx
|
Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page parameter to the default URI for some directories, …
|
CWE-79
Cross-site Scripting
|
CVE-2007-5426
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285012
|
- |
|
joomla
|
com_search_component joomla
|
Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: …
|
CWE-79
Cross-site Scripting
|
CVE-2007-5427
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285013
|
- |
|
umi-cms
|
umi_cms
|
Cross-site scripting (XSS) vulnerability in UMI CMS allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to the default URI in search_do/.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5428
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285014
|
- |
|
nucleus_cms
|
nucleus_cms
|
Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5429
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285015
|
- |
|
scottmanktelow
|
stride_cms
|
Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id paramete…
|
CWE-89
SQL Injection
|
CVE-2007-5430
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285016
|
- |
|
javaatwork scottmanktelow
|
myftpuploader_module stride
|
include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the …
|
CWE-200
Information Exposure
|
CVE-2007-5431
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285017
|
- |
|
scottmanktelow
|
stride_cms
|
Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php.
|
CWE-200
Information Exposure
|
CVE-2007-5432
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285018
|
- |
|
siteup
|
siteup
|
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Site-Up 2.64 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) search mask field.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5433
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285019
|
- |
|
pro.setun
|
pro-search
|
Cross-site scripting (XSS) vulnerability in PRO-search 0.17.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5434
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285020
|
- |
|
gdata
|
antivirus
|
Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath func…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5436
|
2018-10-16 06:44 |
2007-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|