Monthly Archive: June 2007

CVE-2007-2988

A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code,...

CVE-2007-2987

Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods. Date published :...

CVE-2007-2985

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator’s username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or...

CVE-2007-2984

Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method. Date published : 2007-06-01 http://www.securityfocus.com/bid/24220...