
CVE-2007-5127 – SimpGB 1.46.2 - '/admin/?l_username' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-5127
27 Sep 2007 — Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en SimpGB 1.46.02 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante los parámetros (1) l_username al URI por defecto bajo admin/ ... • https://www.exploit-db.com/exploits/30615 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2007-5129
https://notcve.org/view.php?id=CVE-2007-5129
27 Sep 2007 — SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc. SimpGB 1.46.02 almacena información sensible bajo la raíz de documentos web con control de acceso insuficiente, lo cual permite a atacantes remotos (1) obtener información sensible de... • http://forum.boesch-it.de/viewtopic.php?t=2790 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2007-5130
https://notcve.org/view.php?id=CVE-2007-5130
27 Sep 2007 — SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reveals the path in various error messages. SimpGB 1.46.02 permite a atacantes remotos obtener información sensible mediante (1) un parámetro lang a admin/index.php o (2) una petición directa a admin/trailer.php, lo cual revela la ruta en varios mensajes de error. • http://forum.boesch-it.de/viewtopic.php?t=2790 • CWE-20: Improper Input Validation •