256901
|
- |
|
linux
|
linux_kernel
|
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-3740
|
2017-09-29 10:29 |
2007-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256902
|
- |
|
psnews
|
psnews
|
Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter.
|
NVD-CWE-Other
|
CVE-2007-3772
|
2017-09-29 10:29 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256903
|
- |
|
php
|
php
|
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument.
|
NVD-CWE-Other
|
CVE-2007-3790
|
2017-09-29 10:29 |
2007-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256904
|
- |
|
php
|
php
|
The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to mem…
|
CWE-399 CWE-20
Resource Management Errors Improper Input Validation
|
CVE-2007-3806
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256905
|
- |
|
php_arena
|
pafiledb
|
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a differen…
|
NVD-CWE-Other
|
CVE-2007-3808
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256906
|
- |
|
prozilla
|
prozilla_directory_script
|
Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unsp…
|
NVD-CWE-Other
|
CVE-2007-3809
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256907
|
- |
|
it747
|
realtor_747
|
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
|
NVD-CWE-Other
|
CVE-2007-3810
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256908
|
- |
|
esyndicat
|
esyndicat_directory
|
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php.
|
NVD-CWE-Other
|
CVE-2007-3811
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256909
|
- |
|
cmscout
|
cmscout
|
SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php.
|
NVD-CWE-Other
|
CVE-2007-3812
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256910
|
- |
|
mkportal
|
noboard_module
|
PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.
|
NVD-CWE-Other
|
CVE-2007-3813
|
2017-09-29 10:29 |
2007-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|