268561
|
- |
|
clanlite
|
clanlite
|
Multiple PHP remote file inclusion vulnerabilities in ClanLite 1.23.01.2005 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules/serveur_jeux.php o…
|
CWE-20
Improper Input Validation
|
CVE-2007-5168
|
2008-11-15 15:59 |
2007-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268562
|
- |
|
matteo
|
barbo91
|
Unrestricted file upload vulnerability in upload.php in Barbo91 1.1 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is …
|
CWE-20
Improper Input Validation
|
CVE-2007-4761
|
2008-11-15 15:58 |
2007-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268563
|
- |
|
domino_blogsphere
|
domino_blogsphere
|
Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information …
|
CWE-79
Cross-site Scripting
|
CVE-2007-4813
|
2008-11-15 15:58 |
2007-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268564
|
- |
|
google
|
picasa
|
Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.
|
NVD-CWE-Other
|
CVE-2007-4824
|
2008-11-15 15:58 |
2007-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268565
|
- |
|
google
|
picasa
|
Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.
|
NVD-CWE-Other
|
CVE-2007-4847
|
2008-11-15 15:58 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268566
|
- |
|
techexcel_inc.
|
customerwise
|
Multiple cross-site scripting (XSS) vulnerabilities in TechExcel CustomerWise (formerly TechExcel CRM) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2007-4882
|
2008-11-15 15:58 |
2007-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268567
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4883
|
2008-11-15 15:58 |
2007-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268568
|
- |
|
media_player_classic
|
media_player_classic
|
Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.
|
NVD-CWE-noinfo
|
CVE-2007-4884
|
2008-11-15 15:58 |
2007-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268569
|
- |
|
xwiki
|
xwiki
|
The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote…
|
NVD-CWE-Other
|
CVE-2007-4888
|
2008-11-15 15:58 |
2007-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268570
|
- |
|
xwiki
|
xwiki
|
Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, with administrative access to one wiki in a multiwiki environment, to obtain se…
|
NVD-CWE-noinfo
|
CVE-2007-4898
|
2008-11-15 15:58 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|