255601
|
- |
|
e107
|
e107
|
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with…
|
NVD-CWE-Other
|
CVE-2007-3429
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255602
|
- |
|
simple_invoices
|
simple_invoices
|
SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.
|
NVD-CWE-Other
|
CVE-2007-3430
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255603
|
- |
|
valerio_capello
|
dagger_-_the_cutting_edge
|
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang pa…
|
NVD-CWE-Other
|
CVE-2007-3431
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255604
|
- |
|
valerio_capello
|
dagger_-_the_cutting_edge
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2007-3431
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255605
|
- |
|
netart_media
|
pharmacy_system
|
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
|
NVD-CWE-Other
|
CVE-2007-3433
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255606
|
- |
|
netart_media
|
pharmacy_system
|
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
|
NVD-CWE-Other
|
CVE-2007-3434
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255607
|
- |
|
bugmall
|
shopping_cart
|
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
|
NVD-CWE-Other
|
CVE-2007-3446
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255608
|
- |
|
bugmall
|
shopping_cart
|
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also b…
|
CWE-89
SQL Injection
|
CVE-2007-3447
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255609
|
- |
|
bugmall
|
shopping_cart
|
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and …
|
CWE-79
Cross-site Scripting
|
CVE-2007-3448
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255610
|
- |
|
gorani_network
|
6alblog
|
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
|
NVD-CWE-Other
|
CVE-2007-3449
|
2017-10-11 10:32 |
2007-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|