264761
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and a…
|
NVD-CWE-Other
|
CVE-2007-1178
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264762
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit…
|
NVD-CWE-Other
|
CVE-2007-1179
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264763
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.
|
NVD-CWE-Other
|
CVE-2007-1180
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264764
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2007-1181
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264765
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.
|
NVD-CWE-Other
|
CVE-2007-1182
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264766
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2007-1183
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264767
|
- |
|
web-app.org
|
webapp
|
The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.
|
CWE-16
Configuration
|
CVE-2007-1184
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264768
|
- |
|
web-app.org
|
webapp
|
The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote attack vectors.
|
NVD-CWE-Other
|
CVE-2007-1185
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264769
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
|
NVD-CWE-Other
|
CVE-2007-1186
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264770
|
- |
|
web-app.org
|
webapp
|
WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Recent Searches.
|
NVD-CWE-Other
|
CVE-2007-1187
|
2011-03-8 11:51 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|