CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-6569

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6571

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6575

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6579

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6588

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows remote attackers to inject arbitrary web script or HTML via the username field in an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6589

    Last Modified: 23 Apr 2026

    The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.

    Published: 28 Dec 2007
    8.8
    High

    CVE-2007-6593

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.

    Published: 28 Dec 2007
    6.4
    Medium

    CVE-2007-6567

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.

    Published: 28 Dec 2007
    7.8
    High

    CVE-2007-6573

    Last Modified: 23 Apr 2026

    QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551.

    Published: 28 Dec 2007
    6.4
    Medium

    CVE-2007-6584

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6587

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6545

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.

    Published: 28 Dec 2007
    6.4
    Medium

    CVE-2007-6546

    Last Modified: 23 Apr 2026

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6551

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Dec 2007
    6
    Medium

    CVE-2007-6552

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6554

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) register.php, (3) login.php, or (4) statistics.php.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6559

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to execute arbitrary SQL commands via (1) the from parameter to index.php or (2) the page parameter to update.php.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6560

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.

    Published: 28 Dec 2007
    5
    Medium

    CVE-2007-6562

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the use of FD_SET in TCPreen before 1.4.4 allow remote attackers to cause a denial of service via multiple concurrent connections, which result in overflows in the (1) SocketAddress::Connect function in libsolve/sockprot.cpp and (2) monitor_bridge function in src/bridge.cpp.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6544

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6549

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6556

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to default.asp in a news page action or (2) the pageid parameter to default.asp.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6564

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6543

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6548

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (3) the disclaimer parameter to modules/system/admin.php in a disclaimer action, (4) the disclaimer parameter to modules/mydownloads/admin/index.php in a mydownloadsConfigAdmin action, (5) the disclaimer parameter to modules/newbb_plus/admin/forum_config.php, (6) the disclaimer parameter to modules/mylinks/admin/index.php in a myLinksConfigAdmin action, or (7) the intro parameter to modules/sections/admin/index.php in a secconfig action, which inject PHP sequences into (a) sections/cache/intro.php, (b) mylinks/cache/disclaimer.php, (c) mydownloads/cache/disclaimer.php, (d) newbb_plus/cache/disclaimer.php, (e) system/cache/disclaimer.php, (f) system/cache/footer.php, (g) system/cache/header.php, or (h) system/cache/maintenance.php in modules/.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6550

    Last Modified: 23 Apr 2026

    form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6558

    Last Modified: 23 Apr 2026

    TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288.

    Published: 28 Dec 2007
    6.8
    Medium

    CVE-2007-6547

    Last Modified: 23 Apr 2026

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

    Published: 28 Dec 2007
    6.8
    Medium

    CVE-2007-6553

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845.

    Published: 28 Dec 2007
    9.3
    Critical

    CVE-2007-6555

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

    Published: 28 Dec 2007
    5.7
    Medium

    CVE-2007-6561

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF_load_image function that results in an overflow in the pdc_fsearch_fopen function, and possibly other vectors.

    Published: 28 Dec 2007
    10
    Critical

    CVE-2007-6563

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in WinAce 2.65 and earlier, and possibly other versions before 2.69, allows user-assisted remote attackers to execute arbitrary code via a long filename in a compressed UUE archive.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6557

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.

    Published: 28 Dec 2007
    6.8
    Medium

    CVE-2007-6534

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.

    Published: 27 Dec 2007
    6.8
    Medium

    CVE-2007-6535

    Last Modified: 23 Apr 2026

    Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary code via a long string to the IsTaggedBM method.

    Published: 27 Dec 2007
    6.8
    Medium

    CVE-2007-6536

    Last Modified: 23 Apr 2026

    The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attackers to spoof domain names and trick users into installing malicious button XML files, as demonstrated by presenting www.google.com when the button was downloaded from an arbitrary site through an open redirector on www.google.com.

    Published: 27 Dec 2007
    6.8
    Medium

    CVE-2007-6537

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbitrary code via a long filename in a gzipped archive, such as a (1) gz, (2) adz, (3) roz, or (4) hdz archive in a compressed floppy disk image.

    Published: 27 Dec 2007
    7.5
    High

    CVE-2007-6538

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Dec 2007
    7.5
    High

    CVE-2007-6540

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.

    Published: 27 Dec 2007
    7.5
    High

    CVE-2007-6533

    Last Modified: 23 Apr 2026

    Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message.

    Published: 27 Dec 2007
    7.5
    High

    CVE-2007-6542

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.

    Published: 27 Dec 2007
    6.8
    Medium

    CVE-2007-6539

    Last Modified: 23 Apr 2026

    PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file parameter.

    Published: 27 Dec 2007
    4.3
    Medium

    CVE-2007-6541

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.

    Published: 27 Dec 2007
    4.3
    Medium

    CVE-2007-6526

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.

    Published: 27 Dec 2007
    5.8
    Medium

    CVE-2007-6527

    Last Modified: 23 Apr 2026

    uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type.

    Published: 27 Dec 2007
    5
    Medium

    CVE-2007-6528

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

    Published: 27 Dec 2007
    10
    Critical

    CVE-2007-6529

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php.

    Published: 27 Dec 2007
    9.3
    Critical

    CVE-2007-6530

    Last Modified: 23 Apr 2026

    Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.

    Published: 27 Dec 2007
    9.3
    Critical

    CVE-2007-4474

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

    Published: 27 Dec 2007
    10
    Critical

    CVE-2007-6525

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, related to "scripting."

    Published: 27 Dec 2007