|
284061
|
- |
|
cvstrac
|
cvstrac
|
An SQL injection via this technique is somewhat limited as is_eow() bails on whitespace. So while one _can_ do an SQL injection, one is limited to SQL queries containing only characters which get pas…
|
NVD-CWE-Other
|
CVE-2007-0347
|
2018-10-17 01:32 |
2007-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284062
|
- |
|
cvstrac
|
cvstrac
|
The DoS vulnerability exists because the is_eow() function in "format.c" does NOT just check the FIRST character of the supplied string for an End-Of-Word terminating character, but instead iterates …
|
NVD-CWE-Other
|
CVE-2007-0347
|
2018-10-17 01:32 |
2007-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284063
|
- |
|
cvstrac
|
cvstrac
|
Successful remote unauthenticated exploit requires that CVSTrac is explicitly configured to allow anonymous users to add tickets (it is not by default).
|
NVD-CWE-Other
|
CVE-2007-0347
|
2018-10-17 01:32 |
2007-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284064
|
- |
|
interactual_technologies intervideo roxio
|
interactual_player windvd cineplayer
|
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-0348
|
2018-10-17 01:32 |
2007-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284065
|
- |
|
nicecoder
|
indexu
|
Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.
|
NVD-CWE-Other
|
CVE-2007-0349
|
2018-10-17 01:32 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284066
|
- |
|
zonelabs
|
zonealarm
|
Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unloa…
|
NVD-CWE-Other
|
CVE-2007-0351
|
2018-10-17 01:32 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284067
|
- |
|
microsoft
|
html_help_workshop
|
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer f…
|
NVD-CWE-Other
|
CVE-2007-0352
|
2018-10-17 01:32 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284068
|
- |
|
mywebland
|
mybloggie
|
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.
|
NVD-CWE-Other
|
CVE-2007-0353
|
2018-10-17 01:32 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284069
|
- |
|
oreon_project
|
oreon
|
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
|
NVD-CWE-Other
|
CVE-2007-0360
|
2018-10-17 01:32 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284070
|
- |
|
nicecoder
|
indexu
|
Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) sugges…
|
CWE-79
Cross-site Scripting
|
CVE-2007-0364
|
2018-10-17 01:32 |
2007-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|