CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-6138

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.

    Published: 27 Nov 2007
    6.8
    Medium

    CVE-2007-6139

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter.

    Published: 27 Nov 2007
    7.5
    High

    CVE-2007-6140

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Dora Emlak 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) emlak_detay.asp and (b) haber_detay.asp, the (2) kategori parameter to (c) kategorisirala.asp, and the (3) tip parameter to (d) tipsirala.asp.

    Published: 27 Nov 2007
    4.3
    Medium

    CVE-2007-6142

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Nov 2007
    5
    Medium

    CVE-2007-6146

    Last Modified: 23 Apr 2026

    Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-02 on Windows might allow remote attackers to cause a denial of service (service stop) via a "specific file" argument to an FTP command.

    Published: 27 Nov 2007
    7.5
    High

    CVE-2007-6143

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp (aka the Login Page) in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 27 Nov 2007
    Unknown

    CVE-2007-6132

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Nov 2007
    7.5
    High

    CVE-2007-6134

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a different vector than CVE-2006-1773.

    Published: 27 Nov 2007
    4.3
    Medium

    CVE-2007-6135

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file.

    Published: 27 Nov 2007
    4.3
    Medium

    CVE-2007-6136

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details are obtained from third party information.

    Published: 27 Nov 2007
    4.3
    Medium

    CVE-2007-6141

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 27 Nov 2007
    5
    Medium

    CVE-2007-6145

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vectors.

    Published: 27 Nov 2007
    6
    Medium

    CVE-2007-6144

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the PPlayer.XPPlayer.1 ActiveX control in pplayer.dll_1_work in Xunlei Thunder 5.7.4.401 allows remote attackers to execute arbitrary code via a long string in a FlvPlayerUrl property value. NOTE: some of these details are obtained from third party information.

    Published: 27 Nov 2007
    6.8
    Medium

    CVE-2007-6147

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/.

    Published: 27 Nov 2007
    Unknown

    CVE-2006-2938

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2937. Reason: This candidate was withdrawn by its CNA. it was incorrectly used to identify CVE-2006-2937. Notes: none

    Published: 27 Nov 2007
    Unknown

    CVE-2006-2939

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 27 Nov 2007
    9
    Critical

    CVE-2007-5742

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".." sequences in unknown vectors.

    Published: 27 Nov 2007
    6.8
    Medium

    CVE-2007-6183

    Last Modified: 23 Apr 2026

    Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows context-dependent attackers to execute arbitrary code via format string specifiers in the message parameter.

    Published: 27 Nov 2007
    5
    Medium

    CVE-2007-6122

    Last Modified: 23 Apr 2026

    The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information.

    Published: 26 Nov 2007
    10
    Critical

    CVE-2007-6123

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IRC Services 5.1.8 has unknown impact and attack vectors.

    Published: 26 Nov 2007
    7.5
    High

    CVE-2007-6128

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL commands via the idevent parameter.

    Published: 26 Nov 2007
    5.8
    Medium

    CVE-2007-6129

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 26 Nov 2007
    4.3
    Medium

    CVE-2007-6126

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.

    Published: 26 Nov 2007
    5
    Medium

    CVE-2007-6130

    Last Modified: 23 Apr 2026

    gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.

    Published: 26 Nov 2007
    4.3
    Medium

    CVE-2007-6124

    Last Modified: 6 Apr 2026

    Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

    Published: 26 Nov 2007
    7.5
    High

    CVE-2007-6125

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.

    Published: 26 Nov 2007
    7.5
    High

    CVE-2007-6127

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.

    Published: 26 Nov 2007
    9.3
    Critical

    CVE-2007-5959

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.

    Published: 26 Nov 2007
    4.3
    Medium

    CVE-2007-5960

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.

    Published: 26 Nov 2007
    6.8
    Medium

    CVE-2008-2310

    Last Modified: 23 Apr 2026

    Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.

    Published: 26 Nov 2007
    2.6
    Low

    CVE-2007-6100

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

    Published: 23 Nov 2007
    4
    Medium

    CVE-2007-6101

    Last Modified: 23 Apr 2026

    Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages.

    Published: 23 Nov 2007
    4.3
    Medium

    CVE-2007-6102

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Feed to JavaScript (Feed2JS) 1.91 allows remote attackers to inject arbitrary web script or HTML via a URL in a feed.

    Published: 23 Nov 2007
    5
    Medium

    CVE-2007-6103

    Last Modified: 23 Apr 2026

    I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size field in its header, which is improperly handled by the Receiver::processPacket function; and (2) a denial of service (daemon crash) via an (a) IHU_INFO_INIT or a (b) IHU_INFO_RING packet that does not specify the mode, which is improperly handled by the Player::ring function in Player.cpp.

    Published: 23 Nov 2007
    7.5
    High

    CVE-2007-6106

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action.

    Published: 23 Nov 2007
    6.8
    Medium

    CVE-2007-6105

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php.

    Published: 23 Nov 2007
    4.3
    Medium

    CVE-2007-6104

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Nov 2007
    7.8
    High

    CVE-2007-6694

    Last Modified: 23 Apr 2026

    The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which triggers a NULL pointer dereference.

    Published: 23 Nov 2007
    10
    Critical

    CVE-2008-5316

    Last Modified: 23 Apr 2026

    Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

    Published: 22 Nov 2007
    9.3
    Critical

    CVE-2007-6082

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

    Published: 22 Nov 2007
    7.5
    High

    CVE-2007-6083

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Published: 22 Nov 2007
    7.5
    High

    CVE-2007-6084

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Nov 2007
    4.3
    Medium

    CVE-2007-6085

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module.

    Published: 22 Nov 2007
    9.3
    Critical

    CVE-2007-6086

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter.

    Published: 22 Nov 2007
    6.8
    Medium

    CVE-2007-6087

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module.

    Published: 22 Nov 2007
    10
    Critical

    CVE-2007-6092

    Last Modified: 23 Apr 2026

    Buffer overflow in libsrtp in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 22 Nov 2007
    7.1
    High

    CVE-2007-6093

    Last Modified: 23 Apr 2026

    The SRTP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (kernel crash) via an RTCP index that is "much more than expected."

    Published: 22 Nov 2007
    4.3
    Medium

    CVE-2007-6094

    Last Modified: 23 Apr 2026

    The IPsec module in the VPN component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (module crash) via an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS).

    Published: 22 Nov 2007
    10
    Critical

    CVE-2007-6099

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 might leave "media pinholes" open upon a restart of the SIP module, which might make it easier for remote attackers to conduct unauthorized activities.

    Published: 22 Nov 2007
    7.5
    High

    CVE-2007-6098

    Last Modified: 23 Apr 2026

    Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection.

    Published: 22 Nov 2007