258131
|
- |
|
rayzz
|
rayzz_script
|
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[site][project_path…
|
CWE-94
Code Injection
|
CVE-2007-6229
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258132
|
- |
|
rayzz
|
rayzz_script
|
Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CFG[…
|
NVD-CWE-noinfo CWE-22
Path Traversal
|
CVE-2007-6230
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258133
|
- |
|
tellmatic
|
tellmatic
|
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statis…
|
CWE-94
Code Injection
|
CVE-2007-6231
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258134
|
- |
|
ftp
|
admin
|
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
|
CWE-79
Cross-site Scripting
|
CVE-2007-6232
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258135
|
- |
|
ftp_admin
|
ftp_admin
|
Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in so…
|
CWE-22
Path Traversal
|
CVE-2007-6233
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258136
|
- |
|
ftp_admin
|
ftp_admin
|
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
|
CWE-287
Improper Authentication
|
CVE-2007-6234
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258137
|
- |
|
microsoft
|
windows_media_player
|
Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.
|
CWE-189
Numeric Errors
|
CVE-2007-6236
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258138
|
- |
|
squid
|
squid_web_proxy_cache
|
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP heade…
|
CWE-20
Improper Input Validation
|
CVE-2007-6239
|
2017-09-29 10:29 |
2007-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258139
|
- |
|
adobe
|
flash_player
|
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6243
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258140
|
- |
|
adobe
|
flash_player
|
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6246
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|