|
298801
|
- |
|
dotclear
|
dotclear
|
Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multip…
|
NVD-CWE-Other
|
CVE-2007-3688
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298802
|
- |
|
drupal
|
print_module
|
The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and ot…
|
NVD-CWE-Other
|
CVE-2007-3689
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298803
|
- |
|
drupal
|
forward_module
|
The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and …
|
NVD-CWE-Other
|
CVE-2007-3690
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298804
|
- |
|
av_scripts
|
av_tutorial_script
|
Multiple SQL injection vulnerabilities in changePW.php in AV Tutorial Script (avtutorial) 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) …
|
NVD-CWE-Other
|
CVE-2007-3691
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298805
|
- |
|
av_scripts
|
av_tutorial_script
|
Successful exploitation allows e.g. to change the administrator's password but requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2007-3691
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298806
|
- |
|
kddi
|
ezfactory_download_cgi
|
Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.
|
NVD-CWE-Other
|
CVE-2007-3692
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298807
|
- |
|
sun
|
java_system_access_manager
|
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properti…
|
NVD-CWE-Other
|
CVE-2007-3700
|
2017-07-29 10:32 |
2007-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298808
|
- |
|
silc
|
silc_client silc_toolkit
|
Buffer overflow in lib/silcclient/client_notify.c of SILC Client and SILC Toolkit before 1.1.2 allows remote attackers to cause a denial of service via "NICK_CHANGE" notifications.
|
NVD-CWE-Other
|
CVE-2007-3728
|
2017-07-29 10:32 |
2007-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298809
|
- |
|
hp
|
openvms
|
The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 generates different responses depending on whether or not a username is valid, which allows remote attackers to e…
|
NVD-CWE-Other
|
CVE-2007-3729
|
2017-07-29 10:32 |
2007-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298810
|
- |
|
apple
|
safari
|
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows re…
|
CWE-59 CWE-16
Link Following Configuration
|
CVE-2007-3742
|
2017-07-29 10:32 |
2007-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|