Total
277445 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2007-0395 | 1 Comvironment | 1 Comvironment | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter. | ||||
CVE-2007-0394 | 1 Hp | 1 Hp-ux | 2024-11-21 | N/A |
HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572. | ||||
CVE-2007-0393 | 1 Sun | 1 Solaris | 2024-11-21 | N/A |
Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572. | ||||
CVE-2007-0392 | 1 Ibm | 1 Aix | 2024-11-21 | N/A |
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572. | ||||
CVE-2007-0391 | 1 Bitdefender | 1 Bitdefender Client | 2024-11-21 | N/A |
Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings. | ||||
CVE-2007-0390 | 1 Sabros.us | 1 Sabros.us | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter. | ||||
CVE-2007-0389 | 1 Arsdigita | 2 Arsdigita Community Education Solution, Arsdigita Community System | 2024-11-21 | N/A |
Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI. | ||||
CVE-2007-0388 | 1 Woltlab | 1 Burning Board | 2024-11-21 | N/A |
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters. | ||||
CVE-2007-0387 | 1 Joomla | 1 Joomla | 2024-11-21 | N/A |
SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter. | ||||
CVE-2007-0386 | 1 Postnuke Software Foundation | 1 Postnuke | 2024-11-21 | N/A |
Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug." | ||||
CVE-2007-0385 | 1 Postnuke Software Foundation | 1 Postnuke | 2024-11-21 | N/A |
The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable. | ||||
CVE-2007-0384 | 1 Postnuke Software Foundation | 1 Postnuke | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
CVE-2007-0383 | 1 Wdaemon | 1 Wdaemon | 2024-11-21 | N/A |
WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact. NOTE: The researcher reports that the vendor response was "this is not a security bug. | ||||
CVE-2007-0382 | 1 Letterman | 1 Letterman | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions. | ||||
CVE-2007-0381 | 1 Adaptive Technology Resource Centre | 1 Atutor | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. NOTE: CVE analysis suggests that the vendor fixed these issues. | ||||
CVE-2007-0380 | 1 Docman | 1 Docman | 2024-11-21 | N/A |
DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors. | ||||
CVE-2007-0379 | 1 Docman | 1 Docman | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
CVE-2007-0378 | 1 Docman | 1 Docman | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2007-0377 | 1 Xoops | 1 Xoops | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors. | ||||
CVE-2007-0376 | 1 Virtuemart | 1 Virtuemart | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |