264001
|
- |
|
drupal
|
shoutbox
|
Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block mess…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6298
|
2017-08-8 10:29 |
2007-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264002
|
- |
|
drupal
|
drupal
|
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonom…
|
CWE-89 CWE-20
SQL Injection Improper Input Validation
|
CVE-2007-6299
|
2017-08-8 10:29 |
2007-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264003
|
- |
|
clam_anti-virus
|
clamav
|
Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.
|
CWE-189 CWE-119
Numeric Errors Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6336
|
2017-08-8 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264004
|
- |
|
akamai_technologies
|
download_manager
|
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified…
|
CWE-94
Code Injection
|
CVE-2007-6339
|
2017-08-8 10:29 |
2008-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264005
|
- |
|
aurora
|
aurora_framework
|
SQL injection vulnerability in aurora framework before 20071208 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the value parameter to the pack_var functio…
|
CWE-89
SQL Injection
|
CVE-2007-6345
|
2017-08-8 10:29 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264006
|
- |
|
rainboard
|
rainboard
|
Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6346
|
2017-08-8 10:29 |
2007-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264007
|
- |
|
apple
|
mac_os_x
|
The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) …
|
CWE-189
Numeric Errors
|
CVE-2007-6359
|
2017-08-8 10:29 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264008
|
- |
|
sun
|
extended_system_control_facility_xcp_1040
|
Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attack…
|
NVD-CWE-noinfo
|
CVE-2007-6360
|
2017-08-8 10:29 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264009
|
- |
|
gestdown
|
gestdown
|
Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) do…
|
CWE-89
SQL Injection
|
CVE-2007-6373
|
2017-08-8 10:29 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264010
|
- |
|
typo3
|
typo3
|
SQL injection vulnerability in the indexed_search system extension in TYPO3 3.x, 4.0 through 4.0.7, and 4.1 through 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspe…
|
CWE-89
SQL Injection
|
CVE-2007-6381
|
2017-08-8 10:29 |
2007-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|