257971
|
- |
|
cyberlink
|
powerdvd
|
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or …
|
CWE-22
Path Traversal
|
CVE-2007-5219
|
2017-09-29 10:29 |
2007-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257972
|
- |
|
poppawid
|
poppawid
|
PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the form parameter.
|
CWE-94
Code Injection
|
CVE-2007-5221
|
2017-09-29 10:29 |
2007-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257973
|
- |
|
deonixscripts
|
web_template_management_system
|
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.
|
CWE-89
SQL Injection
|
CVE-2007-5233
|
2017-09-29 10:29 |
2007-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257974
|
- |
|
sun
|
jdk jre
|
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5237
|
2017-09-29 10:29 |
2007-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257975
|
- |
|
edraw
|
office_viewer_component
|
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-5257
|
2017-09-29 10:29 |
2007-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257976
|
- |
|
iscripts
|
multicart
|
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to…
|
CWE-89
SQL Injection
|
CVE-2007-5261
|
2017-09-29 10:29 |
2007-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257977
|
- |
|
trionic
|
cite_cms
|
Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) inte…
|
CWE-94
Code Injection
|
CVE-2007-5271
|
2017-09-29 10:29 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257978
|
- |
|
furkan_tastan_blog
|
furkan_tastan_blog
|
SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action.
|
CWE-89
SQL Injection
|
CVE-2007-5272
|
2017-09-29 10:29 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257979
|
- |
|
adobe
|
shockwave_player
|
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname…
|
CWE-20
Improper Input Validation
|
CVE-2007-5275
|
2017-09-29 10:29 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257980
|
- |
|
zomplog
|
zomplog
|
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5278
|
2017-09-29 10:29 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|