|
298451
|
- |
|
ibm
|
tivoli_storage_manager_client
|
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4880
|
2017-07-29 10:33 |
2007-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298452
|
- |
|
swsoft
|
plesk
|
Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 o…
|
CWE-89
SQL Injection
|
CVE-2007-4892
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298453
|
- |
|
wordpress
|
wordpress
|
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cro…
|
CWE-352
Origin Validation Error
|
CVE-2007-4893
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298454
|
- |
|
wordpress
|
wordpress
|
There is an input validation error in the wp-admin/admin-functions.php script when processing the no_filter parameter.
|
CWE-352
Origin Validation Error
|
CVE-2007-4893
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298455
|
- |
|
wordpress
|
wordpress
|
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to th…
|
CWE-89
SQL Injection
|
CVE-2007-4894
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298456
|
- |
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML int…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4912
|
2017-07-29 10:33 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298457
|
- |
|
invision_power_services
|
invision_power_board
|
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privile…
|
CWE-20
Improper Input Validation
|
CVE-2007-4914
|
2017-07-29 10:33 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298458
|
- |
|
jasmine_technologies
|
lettergrade
|
Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year parameter to genbrws/S…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4945
|
2017-07-29 10:33 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298459
|
- |
|
jasmine_technologies
|
lettergrade
|
LetterGrade allows remote attackers to obtain sensitive information (installation path or account existence) via unspecified vectors. NOTE: the provenance of this information is unknown; the details …
|
NVD-CWE-noinfo
|
CVE-2007-4946
|
2017-07-29 10:33 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298460
|
- |
|
tinywebgallery
|
tinywebgallery
|
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2) i_frames/i_login.p…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4958
|
2017-07-29 10:33 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|