|
285431
|
- |
|
virtual_hosting_control_system
|
virtual_hosting_control_system
|
Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
|
CWE-287
Improper Authentication
|
CVE-2007-3988
|
2018-10-16 06:32 |
2007-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285432
|
- |
|
cpanel
|
cpanel
|
Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.
|
NVD-CWE-Other
|
CVE-2007-4022
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285433
|
- |
|
areca
|
cli
|
Buffer overflow in cli32 in Areca CLI 1.72.250 and earlier might allow local users to gain privileges via a long argument. NOTE: this program is not setuid by default, but there are some usage scena…
|
NVD-CWE-Other
|
CVE-2007-4027
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285434
|
- |
|
webspell
|
webspell
|
Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of t…
|
NVD-CWE-Other
|
CVE-2007-4028
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285435
|
- |
|
webspell
|
webspell
|
Vendor has supplied a patch for this vulnerability: http://cms.webspell.org/index.php?site=files&cat=10
|
NVD-CWE-Other
|
CVE-2007-4028
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285436
|
- |
|
libvorbis
|
libvorbis
|
libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the…
|
NVD-CWE-Other
|
CVE-2007-4029
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285437
|
- |
|
libvorbis
|
libvorbis
|
Vendor has issued upgrade for this vulnerability: https://issues.rpath.com/browse/RPL-1590
|
NVD-CWE-Other
|
CVE-2007-4029
|
2018-10-16 06:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285438
|
- |
|
php t1lib
|
php t1lib
|
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this is…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4033
|
2018-10-16 06:32 |
2007-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285439
|
- |
|
sitescape
|
sitescape_forum
|
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and oth…
|
NVD-CWE-Other
|
CVE-2007-3807
|
2018-10-16 06:31 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285440
|
- |
|
mkportal
|
mkportal
|
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox …
|
NVD-CWE-Other
|
CVE-2007-3814
|
2018-10-16 06:31 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|