257231
|
- |
|
hotscripts
|
hot_or_not_clone
|
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to co…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6603
|
2017-09-29 10:30 |
2008-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257232
|
- |
|
xcms
|
xcms
|
Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) th…
|
CWE-22
Path Traversal
|
CVE-2007-6604
|
2017-09-29 10:30 |
2008-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257233
|
- |
|
skyfex
|
skyfex_client
|
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four arguments to the St…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6605
|
2017-09-29 10:30 |
2008-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257234
|
- |
|
joovili
|
joovili
|
Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6620
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257235
|
- |
|
joovili
|
joovili
|
Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6621
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257236
|
- |
|
zeuscms
|
zeuscms
|
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
|
CWE-89
SQL Injection
|
CVE-2007-6622
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257237
|
- |
|
zeuscms
|
zeuscms
|
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6623
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257238
|
- |
|
pnphpbb
|
pnphpbb
|
Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6624
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257239
|
- |
|
xml2owl
|
xml2owl
|
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter.
|
CWE-94
Code Injection
|
CVE-2007-6632
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257240
|
- |
|
adobe
|
flash_player
|
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" an…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6637
|
2017-09-29 10:30 |
2008-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|