261411
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (…
|
CWE-399
Resource Management Errors
|
CVE-2007-5896
|
2017-07-29 10:33 |
2007-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261412
|
- |
|
adobe
|
coldfusion
|
Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN…
|
CWE-255
Credentials Management
|
CVE-2007-5905
|
2017-07-29 10:33 |
2007-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261413
|
- |
|
picoflat_cms
|
picoflat_cms
|
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can…
|
CWE-22
Path Traversal
|
CVE-2007-5920
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261414
|
- |
|
openbase_international_ltd
|
openbase
|
OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other sto…
|
CWE-20
Improper Input Validation
|
CVE-2007-5926
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261415
|
- |
|
openbase_international_ltd
|
openbase
|
Buffer overflow in OpenBase 10.0.5 and earlier might allow remote authenticated users to execute arbitrary code or cause a denial of service (daemon crash) by creating a stored procedure with a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5929
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261416
|
- |
|
cerberus
|
ftp_server
|
Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5930
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261417
|
- |
|
orangehrm
|
orangehrm
|
The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecifi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5931
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261418
|
- |
|
fatwire
|
fatwire_content_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5932
|
2017-07-29 10:33 |
2007-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261419
|
- |
|
bandersnatch
|
bandersnatch
|
Bandersnatch 0.4 allows remote attackers to obtain sensitive information via a malformed request for index.php with (1) a certain func parameter value; or (2) certain func, jid, page, and limit param…
|
NVD-CWE-noinfo
|
CVE-2007-5942
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261420
|
- |
|
usvn
|
user-friendly_svn
|
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5945
|
2017-07-29 10:33 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|