264901
|
- |
|
torrenttrader
|
torrenttrader
|
Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parame…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4831
|
2017-07-29 10:33 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264902
|
- |
|
immersion_games
|
cellfactor_revolution
|
Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-4832
|
2017-07-29 10:33 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264903
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
|
NVD-CWE-noinfo
|
CVE-2007-4833
|
2017-07-29 10:33 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264904
|
- |
|
immersion_games
|
cellfactor_revolution
|
Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4838
|
2017-07-29 10:33 |
2007-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264905
|
- |
|
ibm
|
tivoli_storage_manager_client
|
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4880
|
2017-07-29 10:33 |
2007-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264906
|
- |
|
swsoft
|
plesk
|
Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 o…
|
CWE-89
SQL Injection
|
CVE-2007-4892
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264907
|
- |
|
wordpress
|
wordpress
|
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cro…
|
CWE-352
Origin Validation Error
|
CVE-2007-4893
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264908
|
- |
|
wordpress
|
wordpress
|
There is an input validation error in the wp-admin/admin-functions.php script when processing the no_filter parameter.
|
CWE-352
Origin Validation Error
|
CVE-2007-4893
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264909
|
- |
|
wordpress
|
wordpress
|
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to th…
|
CWE-89
SQL Injection
|
CVE-2007-4894
|
2017-07-29 10:33 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264910
|
- |
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML int…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4912
|
2017-07-29 10:33 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|