255731
|
- |
|
prosysinfo
|
tftp_server_tftpdwin
|
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might…
|
NVD-CWE-Other
|
CVE-2007-1404
|
2017-10-11 10:31 |
2007-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255732
|
- |
|
gaziyapboz
|
game_portal
|
SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.
|
NVD-CWE-Other
|
CVE-2007-1410
|
2017-10-11 10:31 |
2007-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255733
|
- |
|
php
|
php
|
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.
|
NVD-CWE-Other
|
CVE-2007-1412
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255734
|
- |
|
php
|
php
|
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1413
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255735
|
- |
|
php
|
php
|
Failed exploit attempts will likely cause a denial of serivce on the webserver.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-1413
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255736
|
- |
|
triexa
|
sonicmailer_pro
|
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.
|
NVD-CWE-Other
|
CVE-2007-1425
|
2017-10-11 10:31 |
2007-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255737
|
- |
|
x-ice
|
news_system
|
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2007-1438
|
2017-10-11 10:31 |
2007-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255738
|
- |
|
mcgallery
|
mcgallery
|
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
|
CWE-20
Improper Input Validation
|
CVE-2007-1478
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255739
|
- |
|
creative_guestbook
|
creative_guestbook
|
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
NVD-CWE-Other
|
CVE-2007-1479
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255740
|
- |
|
creative_guestbook
|
creative_guestbook
|
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
|
CWE-287
Improper Authentication
|
CVE-2007-1480
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|