267441
|
- |
|
dropafew
|
dropafew
|
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-…
|
NVD-CWE-Other
|
CVE-2007-1363
|
2017-07-29 10:30 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267442
|
- |
|
dropafew
|
dropafew
|
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter i…
|
NVD-CWE-Other
|
CVE-2007-1364
|
2017-07-29 10:30 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267443
|
- |
|
drupal
|
drupal_project_issue_tracking
|
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to rea…
|
NVD-CWE-Other
|
CVE-2007-1368
|
2017-07-29 10:30 |
2007-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267444
|
- |
|
zend
|
zend_platform
|
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a sy…
|
NVD-CWE-Other
|
CVE-2007-1369
|
2017-07-29 10:30 |
2007-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267445
|
- |
|
zend
|
zend_platform
|
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_…
|
NVD-CWE-Other
|
CVE-2007-1370
|
2017-07-29 10:30 |
2007-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267446
|
- |
|
pmail
|
mercury_mail_transport_system
|
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the sa…
|
NVD-CWE-Other
|
CVE-2007-1373
|
2017-07-29 10:30 |
2007-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267447
|
- |
|
snitz_communications
|
snitz_forums_2000
|
Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of …
|
NVD-CWE-Other
|
CVE-2007-1374
|
2017-07-29 10:30 |
2007-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267448
|
- |
|
fish
|
fish
|
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.
|
NVD-CWE-Other
|
CVE-2007-1397
|
2017-07-29 10:30 |
2007-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267449
|
- |
|
pecl_zip php
|
1.8.3 php
|
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as d…
|
NVD-CWE-Other
|
CVE-2007-1399
|
2017-07-29 10:30 |
2007-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267450
|
- |
|
edgewall_software
|
trac
|
Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web…
|
NVD-CWE-Other
|
CVE-2007-1405
|
2017-07-29 10:30 |
2007-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|