264051
|
- |
|
apple
|
installer mac_os_x
|
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MP…
|
NVD-CWE-Other
|
CVE-2007-0465
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264052
|
- |
|
apple
|
mac_os_x
|
crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.
|
NVD-CWE-Other
|
CVE-2007-0467
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264053
|
- |
|
apple
|
mac_os_x
|
Successful exploitation requires that the attacker is already a part of the administrator group.
|
NVD-CWE-Other
|
CVE-2007-0467
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264054
|
- |
|
sun
|
ray_server_software
|
cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified loc…
|
NVD-CWE-Other
|
CVE-2007-0482
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264055
|
- |
|
enthusiast
|
enthusiast
|
Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php. NOTE: T…
|
NVD-CWE-Other
|
CVE-2007-0483
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264056
|
- |
|
enthusiast
|
enthusiast
|
Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other …
|
NVD-CWE-Other
|
CVE-2007-0484
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264057
|
- |
|
huawei
|
versatile_routing_platform
|
The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long sh…
|
NVD-CWE-Other
|
CVE-2007-0488
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264058
|
- |
|
webspell
|
webspell
|
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The pr…
|
NVD-CWE-Other
|
CVE-2007-0492
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264059
|
- |
|
drupal
|
project project_issue_tracking_module
|
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a…
|
NVD-CWE-Other
|
CVE-2007-0505
|
2017-07-29 10:30 |
2007-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264060
|
- |
|
drupal
|
project project_issue_tracking_module
|
The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain…
|
NVD-CWE-Other
|
CVE-2007-0506
|
2017-07-29 10:30 |
2007-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|