CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2007-4928

    Last Modified: 23 Apr 2026

    The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information.

    Published: 18 Sept 2007
    4.3
    Medium

    CVE-2007-4929

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors.

    Published: 18 Sept 2007
    4.6
    Medium

    CVE-2007-4934

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php.

    Published: 18 Sept 2007
    7.5
    High

    CVE-2007-4925

    Last Modified: 23 Apr 2026

    The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.

    Published: 18 Sept 2007
    7.5
    High

    CVE-2007-4933

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters.

    Published: 18 Sept 2007
    9.3
    Critical

    CVE-2007-4926

    Last Modified: 23 Apr 2026

    The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors.

    Published: 18 Sept 2007
    2.1
    Low

    CVE-2007-4931

    Last Modified: 23 Apr 2026

    HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL.

    Published: 18 Sept 2007
    6.8
    Medium

    CVE-2007-4935

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) admin.php, (2) custom_pages.php, (3) draft.php, (4) faq.php, (5) leagues.php, (6) livedraft.php, (7) login.php, (8) my_team.php, (9) profile.php, (10) signup.php, (11) statistics.php, (12) transactions.php, (13) program_files/admin/custom_pages.php, or (14) program_files/common.php. NOTE: the program_files/livedraft/admin.php and program_files/livedraft/livedraft.php vectors are covered by CVE-2007-4934.

    Published: 18 Sept 2007
    4.3
    Medium

    CVE-2007-4930

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.

    Published: 18 Sept 2007
    7.5
    High

    CVE-2007-4932

    Last Modified: 23 Apr 2026

    admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel.

    Published: 18 Sept 2007
    2.1
    Low

    CVE-2007-3654

    Last Modified: 23 Apr 2026

    The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allocattr function.

    Published: 17 Sept 2007
    4.3
    Medium

    CVE-2007-4912

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4913

    Last Modified: 23 Apr 2026

    ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where they are saved with a .txt extension and are not executable. NOTE: there are limited usage scenarios under which this would be a vulnerability, but it is being tracked by CVE since the vendor has stated it is security-relevant.

    Published: 17 Sept 2007
    6
    Medium

    CVE-2007-4914

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.

    Published: 17 Sept 2007
    10
    Critical

    CVE-2007-4915

    Last Modified: 23 Apr 2026

    The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4919

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4920

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4921

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.

    Published: 17 Sept 2007
    6.8
    Medium

    CVE-2007-4923

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.

    Published: 17 Sept 2007
    10
    Critical

    CVE-2007-4910

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in netInvoicing before 2.7.3 has unknown impact and attack vectors, related to "security check soap".

    Published: 17 Sept 2007
    5
    Medium

    CVE-2007-4911

    Last Modified: 23 Apr 2026

    JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2007
    10
    Critical

    CVE-2007-4916

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

    Published: 17 Sept 2007
    4.3
    Medium

    CVE-2007-4917

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334.

    Published: 17 Sept 2007
    6.5
    Medium

    CVE-2007-4922

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information.

    Published: 17 Sept 2007
    9.3
    Critical

    CVE-2007-4909

    Last Modified: 23 Apr 2026

    Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.

    Published: 17 Sept 2007
    4.3
    Medium

    CVE-2007-4904

    Last Modified: 23 Apr 2026

    RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4905

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.

    Published: 17 Sept 2007
    6.8
    Medium

    CVE-2007-4906

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4907

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and (6) admin/auth.php.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4908

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.

    Published: 17 Sept 2007
    6.4
    Medium

    CVE-2007-4902

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.

    Published: 17 Sept 2007
    7.5
    High

    CVE-2007-4903

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.

    Published: 17 Sept 2007
    5
    Medium

    CVE-2007-4924

    Last Modified: 23 Apr 2026

    The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."

    Published: 17 Sept 2007
    9.3
    Critical

    CVE-2007-2834

    Last Modified: 23 Apr 2026

    Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.

    Published: 17 Sept 2007
    5.8
    Medium

    CVE-2007-4965

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

    Published: 16 Sept 2007
    7.5
    High

    CVE-2007-4974

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size.

    Published: 16 Sept 2007
    7.1
    High

    CVE-2007-6025

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in driver_wext.c in wpa_supplicant 0.6.0 and earlier allows remote attackers to cause a denial of service (crash) via crafted TSF data.

    Published: 15 Sept 2007
    7.5
    High

    CVE-2007-4892

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4896

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.

    Published: 14 Sept 2007
    2.1
    Low

    CVE-2007-4898

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, with administrative access to one wiki in a multiwiki environment, to obtain sensitive information via unknown attack vectors. NOTE: Some of these details are obtained from third party information.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4899

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4900

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 14 Sept 2007
    7.5
    High

    CVE-2007-4894

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."

    Published: 14 Sept 2007
    5
    Medium

    CVE-2007-4895

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter.

    Published: 14 Sept 2007
    5.8
    Medium

    CVE-2007-4901

    Last Modified: 23 Apr 2026

    The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4893

    Last Modified: 23 Apr 2026

    wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

    Published: 14 Sept 2007
    6.8
    Medium

    CVE-2007-4889

    Last Modified: 23 Apr 2026

    The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

    Published: 14 Sept 2007
    5.8
    Medium

    CVE-2007-4890

    Last Modified: 23 Apr 2026

    Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.

    Published: 14 Sept 2007
    6.8
    Medium

    CVE-2007-4891

    Last Modified: 23 Apr 2026

    A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

    Published: 14 Sept 2007