257451
|
- |
|
pakupaku
|
pakupaku_cms
|
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.
|
CWE-94 CWE-264
Code Injection Permissions, Privileges, and Access Controls
|
CVE-2007-4640
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257452
|
- |
|
pakupaku
|
pakupaku_cms
|
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demons…
|
CWE-22
Path Traversal
|
CVE-2007-4641
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257453
|
- |
|
nmdeluxe
|
nmdeluxe
|
SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2…
|
CWE-94
Code Injection
|
CVE-2007-4645
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257454
|
- |
|
hexamail
|
hexamail_server
|
Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.
|
CWE-94
Code Injection
|
CVE-2007-4646
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257455
|
- |
|
2coolcode
|
our_space
|
newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4647
|
2017-09-29 10:29 |
2007-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257456
|
- |
|
phpbb
|
phpbb
|
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search …
|
CWE-89
SQL Injection
|
CVE-2007-4653
|
2017-09-29 10:29 |
2007-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257457
|
- |
|
enetman
|
enetman
|
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
|
CWE-94
Code Injection
|
CVE-2007-4712
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257458
|
- |
|
yvora
|
yvora
|
SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
CWE-89
SQL Injection
|
CVE-2007-4714
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257459
|
- |
|
move_networks_inc
|
move_media_player
|
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4722
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257460
|
- |
|
weboddity
|
weboddity
|
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
|
CWE-22
Path Traversal
|
CVE-2007-4726
|
2017-09-29 10:29 |
2007-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|