267021
|
- |
|
joomla
|
joomla
|
Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6644
|
2008-11-15 16:05 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267022
|
- |
|
joomla
|
joomla
|
Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered user privilege escalation vulnerability."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6645
|
2008-11-15 16:05 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267023
|
- |
|
fusion_news
|
fusion_news
|
Cross-site request forgery (CSRF) vulnerability in Fusion News 3.9.0 allows remote attackers to perform unauthorized actions via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2007-6300
|
2008-11-15 16:04 |
2007-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267024
|
- |
|
httplogger
|
httplogger
|
Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6308
|
2008-11-15 16:04 |
2007-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267025
|
- |
|
drupal
|
feature_module
|
Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks.
|
CWE-352
Origin Validation Error
|
CVE-2007-6320
|
2008-11-15 16:04 |
2007-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267026
|
- |
|
microsoft
|
access
|
Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6357
|
2008-11-15 16:04 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267027
|
- |
|
ibm
|
tivoli_netcool_security_manager
|
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without en…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6363
|
2008-11-15 16:04 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267028
|
- |
|
francisco_burzi
|
php-nuke
|
Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a …
|
CWE-22
Path Traversal
|
CVE-2007-6376
|
2008-11-15 16:04 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267029
|
- |
|
debian
|
debian_linux
|
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process a…
|
CWE-200
Information Exposure
|
CVE-2007-6418
|
2008-11-15 16:04 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267030
|
- |
|
flyspray
|
flyspray
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query string in an index a…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6461
|
2008-11-15 16:04 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|