255701
|
- |
|
creative_guestbook
|
creative_guestbook
|
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
|
CWE-287
Improper Authentication
|
CVE-2007-1480
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255702
|
- |
|
wbblog
|
wbblog
|
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.
|
NVD-CWE-Other
|
CVE-2007-1481
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255703
|
- |
|
liqua
|
wbblog
|
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.
|
CWE-79
Cross-site Scripting
|
CVE-2007-1482
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255704
|
- |
|
cyber_inside cyberteddy sascha_schroeder
|
weblog
|
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in …
|
NVD-CWE-Other
|
CVE-2007-1487
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255705
|
- |
|
linux
|
linux_kernel
|
nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "…
|
NVD-CWE-Other
|
CVE-2007-1496
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255706
|
- |
|
linux
|
linux_kernel
|
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote…
|
NVD-CWE-Other
|
CVE-2007-1497
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255707
|
- |
|
avant_force
|
avant_browser
|
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.
|
NVD-CWE-Other
|
CVE-2007-1501
|
2017-10-11 10:31 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255708
|
- |
|
cicoandcico
|
ccmail
|
PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.
|
NVD-CWE-Other
|
CVE-2007-1516
|
2017-10-11 10:31 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255709
|
- |
|
dayfox_designs
|
dayfox_blog
|
Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request t…
|
NVD-CWE-Other
|
CVE-2007-1525
|
2017-10-11 10:31 |
2007-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255710
|
- |
|
guestbara
|
guestbara
|
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modifie…
|
NVD-CWE-Other
|
CVE-2007-1553
|
2017-10-11 10:31 |
2007-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|