|
285471
|
- |
|
dvbbs
|
dvbbs
|
Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb.
|
NVD-CWE-Other
|
CVE-2007-3774
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285472
|
- |
|
grisoft
|
avg_antivirus
|
avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges …
|
NVD-CWE-Other
|
CVE-2007-3777
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285473
|
- |
|
mysql
|
community_server
|
MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2007-3780
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285474
|
- |
|
mysql
|
community_server
|
MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive info…
|
NVD-CWE-Other
|
CVE-2007-3781
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285475
|
- |
|
mysql
|
community_server
|
MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-3782
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285476
|
- |
|
envivosoft
|
envivo_cms
|
SQL injection vulnerability in default.asp in enVivo!CMS allows remote attackers to execute arbitrary SQL commands via the ID parameter in an article action. NOTE: this is probably different from CV…
|
NVD-CWE-Other
|
CVE-2007-3783
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285477
|
- |
|
esoft
|
instagate_ex2_utm
|
The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, maki…
|
NVD-CWE-Other
|
CVE-2007-3787
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285478
|
- |
|
esoft
|
instagate_ex2_utm
|
The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document.
|
NVD-CWE-Other
|
CVE-2007-3788
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285479
|
- |
|
azerbaijan_development_group
|
azdgdating
|
Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php…
|
NVD-CWE-Other
|
CVE-2007-3792
|
2018-10-16 06:30 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285480
|
- |
|
sun
|
jdk jre sdk
|
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows …
|
CWE-22
Path Traversal
|
CVE-2007-3504
|
2018-10-16 06:29 |
2007-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|