268641
|
- |
|
iptel
|
serweb
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2007-3359
|
2008-11-15 15:52 |
2007-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268642
|
- |
|
ibm
|
websphere_application_server
|
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed con…
|
NVD-CWE-Other
|
CVE-2007-3397
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268643
|
- |
|
web-app.org
|
webapp
|
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string…
|
NVD-CWE-Other
|
CVE-2007-3417
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268644
|
- |
|
web-app.org
|
webapp
|
The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authentic…
|
NVD-CWE-Other
|
CVE-2007-3418
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268645
|
- |
|
web-app.org
|
webapp
|
The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.d…
|
NVD-CWE-Other
|
CVE-2007-3419
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268646
|
- |
|
web-app.org
|
webapp
|
The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4)…
|
NVD-CWE-Other
|
CVE-2007-3420
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268647
|
- |
|
web-app.org
|
webapp
|
The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0.9.…
|
NVD-CWE-Other
|
CVE-2007-3421
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268648
|
- |
|
web-app.org
|
webapp
|
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do n…
|
NVD-CWE-Other
|
CVE-2007-3422
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268649
|
- |
|
web-app.org
|
webapp
|
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function re…
|
NVD-CWE-Other
|
CVE-2007-3423
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268650
|
- |
|
web-app.org
|
webapp
|
The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impact …
|
NVD-CWE-Other
|
CVE-2007-3424
|
2008-11-15 15:52 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|