258161
|
- |
|
p3mbo
|
content_injector
|
Patch Information - http://www.p3mbo.com/index.php?pg=10004
|
CWE-89
SQL Injection
|
CVE-2007-6394
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258162
|
- |
|
poldoc
|
poldoc_document_management_system
|
Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2007-6400
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258163
|
- |
|
adultscript
|
adultscript
|
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credent…
|
CWE-255
Credentials Management
|
CVE-2007-6414
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258164
|
- |
|
xen
|
xen
|
The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-6416
|
2017-09-29 10:29 |
2007-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258165
|
- |
|
hp
|
hp-ux
|
Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2007-6419
|
2017-09-29 10:29 |
2007-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258166
|
- |
|
my123tkshop
|
e-commerce-suite
|
SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php.
|
CWE-89
SQL Injection
|
CVE-2007-6458
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258167
|
- |
|
php_real_estate_classifieds
|
php_real_estate_classifieds_premium_plus
|
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2007-6462
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258168
|
- |
|
form_tools
|
form_tools
|
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) c…
|
CWE-94
Code Injection
|
CVE-2007-6464
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258169
|
- |
|
freewebshop
|
freewebshop
|
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter…
|
CWE-89
SQL Injection
|
CVE-2007-6466
|
2017-09-29 10:29 |
2007-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258170
|
- |
|
phpmyrealty
|
phpmyrealty
|
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated admini…
|
CWE-89
SQL Injection
|
CVE-2007-6472
|
2017-09-29 10:29 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|