257751
|
- |
|
adultscript
|
adultscript
|
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credent…
|
CWE-255
Credentials Management
|
CVE-2007-6414
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257752
|
- |
|
xen
|
xen
|
The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6416
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257753
|
- |
|
hp
|
hp-ux
|
Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2007-6419
|
2017-09-29 10:29 |
2007-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257754
|
- |
|
my123tkshop
|
e-commerce-suite
|
SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php.
|
CWE-89
SQL Injection
|
CVE-2007-6458
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257755
|
- |
|
php_real_estate_classifieds
|
php_real_estate_classifieds_premium_plus
|
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2007-6462
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257756
|
- |
|
form_tools
|
form_tools
|
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) c…
|
CWE-94
Code Injection
|
CVE-2007-6464
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257757
|
- |
|
freewebshop
|
freewebshop
|
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter…
|
CWE-89
SQL Injection
|
CVE-2007-6466
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257758
|
- |
|
phpmyrealty
|
phpmyrealty
|
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated admini…
|
CWE-89
SQL Injection
|
CVE-2007-6472
|
2017-09-29 10:29 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257759
|
- |
|
texas_imperial_software
|
wftpd_pro_explorer
|
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6473
|
2017-09-29 10:29 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257760
|
- |
|
gf_3xplorer
|
gf_3xplorer
|
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other ve…
|
CWE-79
Cross-site Scripting
|
CVE-2007-6474
|
2017-09-29 10:29 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|