|
298631
|
- |
|
picoflat_cms
|
picoflat_cms
|
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can…
|
CWE-22
Path Traversal
|
CVE-2007-5920
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298632
|
- |
|
openbase_international_ltd
|
openbase
|
OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other sto…
|
CWE-20
Improper Input Validation
|
CVE-2007-5926
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298633
|
- |
|
openbase_international_ltd
|
openbase
|
Buffer overflow in OpenBase 10.0.5 and earlier might allow remote authenticated users to execute arbitrary code or cause a denial of service (daemon crash) by creating a stored procedure with a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5929
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298634
|
- |
|
cerberus
|
ftp_server
|
Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5930
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298635
|
- |
|
orangehrm
|
orangehrm
|
The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecifi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5931
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298636
|
- |
|
fatwire
|
fatwire_content_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5932
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298637
|
- |
|
bandersnatch
|
bandersnatch
|
Bandersnatch 0.4 allows remote attackers to obtain sensitive information via a malformed request for index.php with (1) a certain func parameter value; or (2) certain func, jid, page, and limit param…
|
NVD-CWE-noinfo
|
CVE-2007-5942
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298638
|
- |
|
usvn
|
user-friendly_svn
|
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5945
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298639
|
- |
|
ibm
|
tivoli_service_desk
|
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change actio…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5949
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298640
|
- |
|
netcommons
|
netcommons
|
Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11, and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5950
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|