Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-3193 | 1 Phpwiki | 1 Phpwiki | 2017-07-28 | 10.0 HIGH | N/A |
lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations. | |||||
CVE-2007-3195 | 1 Erfan Wiki | 1 Erfan Wiki | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in ERFAN WIKI 1.00 allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3200 | 1 Novell | 1 Modular Authentication Service | 2017-07-28 | 4.9 MEDIUM | N/A |
NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file. | |||||
CVE-2007-3203 | 1 Software602 | 1 602pro Lan Suite | 2017-07-28 | 7.5 HIGH | N/A |
Stack-based buffer overflow in smtpdll.dll in the SMTP service in 602Pro LAN SUITE 2003 2003.0.03.0828 allows remote attackers to execute arbitrary code via an e-mail message with a long address. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3204 | 1 Jffnms | 1 Just For Fun Network Management System | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3207 | 1 Novell | 1 Client | 2017-07-28 | 7.1 HIGH | N/A |
Buffer overflow in the NFS mount daemon (XNFS.NLM) in Novell NetWare 6.5 SP6, and probably earlier, allows remote attackers to cause a denial of service (abend) via a long path in a mount request. | |||||
CVE-2007-3208 | 1 Yabb | 1 Yabb | 2017-07-28 | 10.0 HIGH | N/A |
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code. | |||||
CVE-2007-3209 | 1 Nongnu | 1 Mail Notification | 2017-07-28 | 7.8 HIGH | N/A |
Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2007-3210 | 1 Cellosoft | 1 Cellosoft Tokens Object | 2017-07-28 | 9.3 HIGH | N/A |
Stack-based buffer overflow in nptoken.mox in the Cellosoft Tokens Object 2.0.0.6 extension for Vitalize! allows remote attackers to execute arbitrary code via a long string argument to the RemoveChr method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3211 | 1 Domain Technologie Control | 1 Domain Technologie Control | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3212 | 1 Beehive Forum | 1 Beehive Forum | 2017-07-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460. | |||||
CVE-2007-3213 | 1 Sporum Forum | 1 Sporum Forum | 2017-07-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters. | |||||
CVE-2007-3218 | 1 Php Live | 1 Php Live | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in request.php in PHP Live! 3.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the pagex parameter. | |||||
CVE-2007-3219 | 1 Invision Power Services | 1 Invision Power Board | 2017-07-28 | 7.8 HIGH | N/A |
Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profile data, such as an AIM screen name or Yahoo! identity. | |||||
CVE-2007-3224 | 1 Sun | 2 Java System Directory Server, One Directory Server | 2017-07-28 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors. | |||||
CVE-2007-3225 | 1 Sun | 1 Java System Directory Server | 2017-07-28 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors. | |||||
CVE-2007-3226 | 1 Dotproject | 1 Dotproject | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240. | |||||
CVE-2007-3231 | 1 Mecab | 1 Mecab | 2017-07-28 | 7.5 HIGH | N/A |
Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors. | |||||
CVE-2007-3232 | 1 Ibm | 1 Totalstorage Ds400 | 2017-07-28 | 10.0 HIGH | N/A |
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000. | |||||
CVE-2007-3243 | 1 Bbpress | 1 Bbpress | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header. |