255711
|
- |
|
mcgallery
|
mcgallery
|
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
|
CWE-20
Improper Input Validation
|
CVE-2007-1478
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255712
|
- |
|
creative_guestbook
|
creative_guestbook
|
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
NVD-CWE-Other
|
CVE-2007-1479
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255713
|
- |
|
creative_guestbook
|
creative_guestbook
|
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
|
CWE-287
Improper Authentication
|
CVE-2007-1480
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255714
|
- |
|
wbblog
|
wbblog
|
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.
|
NVD-CWE-Other
|
CVE-2007-1481
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255715
|
- |
|
liqua
|
wbblog
|
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.
|
CWE-79
Cross-site Scripting
|
CVE-2007-1482
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255716
|
- |
|
cyber_inside cyberteddy sascha_schroeder
|
weblog
|
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in …
|
NVD-CWE-Other
|
CVE-2007-1487
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255717
|
- |
|
linux
|
linux_kernel
|
nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "…
|
NVD-CWE-Other
|
CVE-2007-1496
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255718
|
- |
|
linux
|
linux_kernel
|
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote…
|
NVD-CWE-Other
|
CVE-2007-1497
|
2017-10-11 10:31 |
2007-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255719
|
- |
|
avant_force
|
avant_browser
|
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.
|
NVD-CWE-Other
|
CVE-2007-1501
|
2017-10-11 10:31 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255720
|
- |
|
cicoandcico
|
ccmail
|
PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.
|
NVD-CWE-Other
|
CVE-2007-1516
|
2017-10-11 10:31 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|