257041
|
- |
|
phpbg
|
phpbg
|
Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) int…
|
CWE-20
Improper Input Validation
|
CVE-2007-4636
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257042
|
- |
|
xgb
|
xgb
|
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.
|
NVD-CWE-noinfo
|
CVE-2007-4637
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257043
|
- |
|
pakupaku
|
pakupaku_cms
|
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.
|
CWE-94 CWE-264
Code Injection Permissions, Privileges, and Access Controls
|
CVE-2007-4640
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257044
|
- |
|
pakupaku
|
pakupaku_cms
|
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demons…
|
CWE-22
Path Traversal
|
CVE-2007-4641
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257045
|
- |
|
nmdeluxe
|
nmdeluxe
|
SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2…
|
CWE-94
Code Injection
|
CVE-2007-4645
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257046
|
- |
|
hexamail
|
hexamail_server
|
Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.
|
CWE-94
Code Injection
|
CVE-2007-4646
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257047
|
- |
|
2coolcode
|
our_space
|
newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4647
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257048
|
- |
|
phpbb
|
phpbb
|
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search …
|
CWE-89
SQL Injection
|
CVE-2007-4653
|
2017-09-29 10:29 |
2007-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257049
|
- |
|
enetman
|
enetman
|
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
|
CWE-94
Code Injection
|
CVE-2007-4712
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257050
|
- |
|
yvora
|
yvora
|
SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2007-4714
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|