Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 380 183

Количество 380 183

nvd логотип

CVE-2007-3243

около 19 лет назад

Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3242

около 19 лет назад

The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a personal menu.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-3241

около 19 лет назад

Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3240

около 19 лет назад

Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3239

около 19 лет назад

Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3238

около 19 лет назад

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2007-3237

около 19 лет назад

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2007-3236

около 19 лет назад

PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2007-3235

около 19 лет назад

Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3234

около 19 лет назад

SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-3233

около 19 лет назад

The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-3232

около 19 лет назад

The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2007-3231

около 19 лет назад

Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-3230

около 19 лет назад

PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2007-3229

около 19 лет назад

index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-3228

около 19 лет назад

PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2007-3227

около 19 лет назад

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3226

около 19 лет назад

Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3225

около 19 лет назад

Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2007-3224

около 19 лет назад

Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-3243

Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.

CVSS2: 4.3
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3242

The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a personal menu.

CVSS2: 7.5
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3241

Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.

CVSS2: 4.3
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3240

Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3239

Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3237

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

CVSS2: 6.8
68%
Средний
около 19 лет назад
nvd логотип
CVE-2007-3236

PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.

CVSS2: 7.5
77%
Высокий
около 19 лет назад
nvd логотип
CVE-2007-3235

Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.

CVSS2: 4.3
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3234

SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.

CVSS2: 7.5
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3233

The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method.

CVSS2: 5
6%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3232

The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.

CVSS2: 10
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3231

Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.

CVSS2: 7.5
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3230

PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.

CVSS2: 6.8
68%
Средний
около 19 лет назад
nvd логотип
CVE-2007-3229

index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.

CVSS2: 6.8
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3228

PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.

CVSS2: 6.8
67%
Средний
около 19 лет назад
nvd логотип
CVE-2007-3227

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

CVSS2: 4.3
4%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3226

Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.

CVSS2: 4.3
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3225

Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.

CVSS2: 6.4
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3224

Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.

CVSS2: 5
2%
Низкий
около 19 лет назад

Уязвимостей на страницу