267101
|
- |
|
sun
|
java_system_application_server
|
Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2007-4025
|
2017-07-29 10:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267102
|
- |
|
telaxus_llc
|
epesi
|
epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images uplo…
|
NVD-CWE-Other
|
CVE-2007-4026
|
2017-07-29 10:32 |
2007-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267103
|
- |
|
adempiere
|
bazaar
|
Unspecified vulnerability in WebUI in ADempiere Bazaar before 3.3 beta Victoria edition allows remote attackers to access system-level windows via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2007-4050
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267104
|
- |
|
ultradefrag
|
ultradefrag
|
Heap-based buffer overflow in the FindFiles function in UltraDefrag 1.0.3 allows local users to gain privileges via a file with a long pathname. NOTE: some of these details are obtained from third p…
|
NVD-CWE-Other
|
CVE-2007-4051
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267105
|
- |
|
nessus
|
vulnerability_scanner
|
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC me…
|
CWE-22
Path Traversal
|
CVE-2007-4062
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267106
|
- |
|
drupal
|
drupal
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileg…
|
NVD-CWE-Other
|
CVE-2007-4063
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267107
|
- |
|
drupal
|
drupal
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," in…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4064
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267108
|
- |
|
vikingboard
|
vikingboard
|
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components.
|
NVD-CWE-Other
|
CVE-2007-4089
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267109
|
- |
|
vikingboard
|
vikingboard
|
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) f, (3) quote, and (4) act parameters to cp.p…
|
NVD-CWE-Other
|
CVE-2007-4088
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267110
|
- |
|
mldonkey
|
mldonkey
|
MLDonkey before 2.9.0 does not load certain code from $MLDONKEY/web_infos/ before the network modules become active, which allows remote attackers to bypass the IP blocklist.
|
NVD-CWE-Other
|
CVE-2007-4100
|
2017-07-29 10:32 |
2007-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|