CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-4881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4883

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a similar issue to CVE-2007-4828.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4885

    Last Modified: 23 Apr 2026

    Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4882

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TechExcel CustomerWise (formerly TechExcel CRM) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Sept 2007
    3.5
    Low

    CVE-2007-4888

    Last Modified: 23 Apr 2026

    The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

    Published: 14 Sept 2007
    6.8
    Medium

    CVE-2007-4749

    Last Modified: 23 Apr 2026

    The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

    Published: 14 Sept 2007
    6.5
    Medium

    CVE-2006-7223

    Last Modified: 23 Apr 2026

    PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.

    Published: 14 Sept 2007
    9.3
    Critical

    CVE-2007-1688

    Last Modified: 23 Apr 2026

    Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4884

    Last Modified: 23 Apr 2026

    Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

    Published: 14 Sept 2007
    6.8
    Medium

    CVE-2007-4886

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.

    Published: 14 Sept 2007
    4.3
    Medium

    CVE-2007-4887

    Last Modified: 23 Apr 2026

    The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.

    Published: 14 Sept 2007
    5
    Medium

    CVE-2007-4879

    Last Modified: 23 Apr 2026

    Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.

    Published: 13 Sept 2007
    6.1
    Medium

    CVE-2007-4465

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

    Published: 13 Sept 2007
    5.8
    Medium

    CVE-2007-4843

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-4844

    Last Modified: 23 Apr 2026

    X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CWD /" command, which allows remote FTP servers to cause a denial of service (infinite loop) by (1) repeatedly sending a 550 error response, or (2) sending a 550 error response and then disconnecting.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4845

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik go action.

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-4847

    Last Modified: 23 Apr 2026

    Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory.

    Published: 12 Sept 2007
    9.3
    Critical

    CVE-2007-4842

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-4840

    Last Modified: 23 Apr 2026

    PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

    Published: 12 Sept 2007
    4.4
    Medium

    CVE-2007-4849

    Last Modified: 23 Apr 2026

    JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions.

    Published: 12 Sept 2007
    9.3
    Critical

    CVE-2007-4841

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-4848

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-3871

    Last Modified: 23 Apr 2026

    Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of service (stamp invalidation) via a SOAP request with an id value for a stamp that has not yet been printed.

    Published: 12 Sept 2007
    6.8
    Medium

    CVE-2007-4727

    Last Modified: 23 Apr 2026

    Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow."

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-4828

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4832

    Last Modified: 23 Apr 2026

    Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-4833

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4834

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4835

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-4836

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4837

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Sept 2007
    2.6
    Low

    CVE-2007-4831

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4839

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-4830

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4838

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.

    Published: 12 Sept 2007
    4.3
    Medium

    CVE-2007-2930

    Last Modified: 23 Apr 2026

    The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.

    Published: 12 Sept 2007
    6.9
    Medium

    CVE-2007-3036

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."

    Published: 12 Sept 2007
    Unknown

    CVE-2007-4019

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2930. Reason: This candidate is a reservation duplicate of CVE-2007-2930. Notes: All CVE users should reference CVE-2007-2930 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-4651

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Connect Enterprise Server 6 allows remote attackers to read certain pages that are restricted to the administrator via unknown vectors.

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4825

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.

    Published: 12 Sept 2007
    9.3
    Critical

    CVE-2007-3040

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.

    Published: 12 Sept 2007
    10
    Critical

    CVE-2007-4731

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.

    Published: 12 Sept 2007
    5
    Medium

    CVE-2007-4897

    Last Modified: 23 Apr 2026

    pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).

    Published: 12 Sept 2007
    7.5
    High

    CVE-2007-4817

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.

    Published: 11 Sept 2007
    7.5
    High

    CVE-2007-4818

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in modules/.

    Published: 11 Sept 2007
    4.3
    Medium

    CVE-2007-4819

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2007
    7.5
    High

    CVE-2007-4820

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.

    Published: 11 Sept 2007
    9.3
    Critical

    CVE-2007-4821

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169.

    Published: 11 Sept 2007
    7.5
    High

    CVE-2007-4816

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.

    Published: 11 Sept 2007