266111
|
- |
|
proftpd_project
|
proftpd
|
The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that r…
|
NVD-CWE-Other
|
CVE-2007-2165
|
2017-07-29 10:31 |
2007-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266112
|
- |
|
aimstats
|
aimstats
|
Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this…
|
NVD-CWE-Other
|
CVE-2007-2168
|
2017-07-29 10:31 |
2007-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266113
|
- |
|
double_precision_incorporated
|
courier-imap
|
Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execut…
|
NVD-CWE-Other
|
CVE-2007-2173
|
2017-07-29 10:31 |
2007-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266114
|
- |
|
objective_development
|
sharity
|
Multiple unspecified vulnerabilities in Objective Development Sharity before 3.3 allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2007-2178
|
2017-07-29 10:31 |
2007-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266115
|
- |
|
freepbx
|
freepbx
|
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecifi…
|
NVD-CWE-Other
|
CVE-2007-2191
|
2017-07-29 10:31 |
2007-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266116
|
- |
|
ripe_website_manager
|
ripe_website_manager
|
Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" i…
|
CWE-79
Cross-site Scripting
|
CVE-2007-2206
|
2017-07-29 10:31 |
2007-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266117
|
- |
|
mybb
|
mybb
|
Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter…
|
NVD-CWE-Other
|
CVE-2007-2212
|
2017-07-29 10:31 |
2007-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266118
|
- |
|
microsoft
|
intelligent_application_gateway_2007
|
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-2238
|
2017-07-29 10:31 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266119
|
- |
|
axis
|
2100_network_camera 2110_network_camera 2120_network_camera 2130_ptz_network_camera 2400_video_server 2401_video_server 2411_video_server 2420-ir_network_camera 2420_network_c…
|
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 24…
|
NVD-CWE-Other
|
CVE-2007-2239
|
2017-07-29 10:31 |
2007-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266120
|
- |
|
openbsd
|
openssh
|
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a…
|
CWE-287
Improper Authentication
|
CVE-2007-2243
|
2017-07-29 10:31 |
2007-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|