Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 378 419

Количество 378 419

nvd логотип

CVE-2007-1143

больше 19 лет назад

Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-1142

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1141

больше 19 лет назад

PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1140

больше 19 лет назад

Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

CVSS2: 9.4
EPSS: Низкий
nvd логотип

CVE-2007-1139

больше 19 лет назад

Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2007-1138

больше 19 лет назад

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1137

больше 19 лет назад

putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1136

больше 19 лет назад

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1135

больше 19 лет назад

Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1134

больше 19 лет назад

Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2007-1133

больше 19 лет назад

PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1132

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1131

больше 19 лет назад

PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1130

больше 19 лет назад

PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1129

больше 19 лет назад

Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1128

больше 19 лет назад

shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1127

больше 19 лет назад

Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2007-1126

больше 19 лет назад

Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1125

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1124

больше 19 лет назад

Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-1143

Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1142

Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.

CVSS2: 4.3
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1141

PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.

CVSS2: 7.5
6%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1140

Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

CVSS2: 9.4
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1139

Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.

CVSS2: 10
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1138

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

CVSS2: 5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1137

putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1136

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

CVSS2: 6.8
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1135

Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.

CVSS2: 6.8
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1134

Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."

CVSS2: 10
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1133

PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.

CVSS2: 7.5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1132

Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.

CVSS2: 4.3
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1131

PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

CVSS2: 7.5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1130

PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

CVSS2: 7.5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1129

Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1128

shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1127

Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.

CVSS2: 6.4
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1126

Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

CVSS2: 5
5%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1125

Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.

CVSS2: 4.3
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1124

Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

CVSS2: 5
3%
Низкий
больше 19 лет назад

Уязвимостей на страницу