267031
|
- |
|
wordpress
|
wordpress
|
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functiona…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1893
|
2017-07-29 10:31 |
2007-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267032
|
- |
|
aol
|
icq instant_messenger
|
Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .…
|
NVD-CWE-Other
|
CVE-2007-1904
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267033
|
- |
|
pineapple_technologies
|
quizshock
|
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special character…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1905
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267034
|
- |
|
tru-zone
|
nukeet
|
The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticat…
|
NVD-CWE-Other
|
CVE-2007-1925
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267035
|
- |
|
ichitaro
|
ichitaro
|
Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly d…
|
CWE-79 CWE-119
Cross-site Scripting Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1938
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267036
|
- |
|
ibm
|
tivoli_business_service_manager
|
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.
|
NVD-CWE-Other
|
CVE-2007-1940
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267037
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2007-1945
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267038
|
- |
|
archivexpert
|
archivexpert
|
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .ta…
|
NVD-CWE-Other
|
CVE-2007-1954
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267039
|
- |
|
dotclear
|
dotclear
|
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the…
|
NVD-CWE-Other
|
CVE-2007-1989
|
2017-07-29 10:31 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267040
|
- |
|
youngzsoft
|
cmailserver
|
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment paramete…
|
NVD-CWE-Other
|
CVE-2007-1991
|
2017-07-29 10:31 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|