263991
|
- |
|
pineapple_technologies
|
quizshock
|
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special character…
|
CWE-79
Cross-site Scripting
|
CVE-2007-1905
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263992
|
- |
|
tru-zone
|
nukeet
|
The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticat…
|
NVD-CWE-Other
|
CVE-2007-1925
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263993
|
- |
|
ichitaro
|
ichitaro
|
Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly d…
|
CWE-79 CWE-119
Cross-site Scripting Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1938
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263994
|
- |
|
ibm
|
tivoli_business_service_manager
|
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.
|
NVD-CWE-Other
|
CVE-2007-1940
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263995
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2007-1945
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263996
|
- |
|
archivexpert
|
archivexpert
|
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .ta…
|
NVD-CWE-Other
|
CVE-2007-1954
|
2017-07-29 10:31 |
2007-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263997
|
- |
|
dotclear
|
dotclear
|
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the…
|
NVD-CWE-Other
|
CVE-2007-1989
|
2017-07-29 10:31 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263998
|
- |
|
youngzsoft
|
cmailserver
|
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment paramete…
|
NVD-CWE-Other
|
CVE-2007-1991
|
2017-07-29 10:31 |
2007-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263999
|
- |
|
clam_anti-virus
|
clamav
|
Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafte…
|
NVD-CWE-Other
|
CVE-2007-1997
|
2017-07-29 10:31 |
2007-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264000
|
- |
|
bftpd
|
bftpd
|
Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-2010
|
2017-07-29 10:31 |
2007-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|