CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-4122

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi JP1/Cm2/Hierarchical Viewer (HV) 06-00 through 06-71-/B allows remote attackers to cause a denial of service (application stop and web interface outage) via certain "unexpected data."

    Published: 1 Aug 2007
    4.9
    Medium

    CVE-2007-4124

    Last Modified: 23 Apr 2026

    The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.

    Published: 1 Aug 2007
    7.1
    High

    CVE-2007-4125

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.

    Published: 1 Aug 2007
    6.8
    Medium

    CVE-2007-4127

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0

    Published: 1 Aug 2007
    5
    Medium

    CVE-2007-4123

    Last Modified: 23 Apr 2026

    The Groupmax Scheduler_Facilities management tool in Hitachi Groupmax Groupware Server 07-00-/F through 07-32-/A before 20070731 does not properly manage schedule server configuration data, which might allow attackers to obtain sensitive information via unspecified vectors.

    Published: 1 Aug 2007
    1.2
    Low

    CVE-2007-3108

    Last Modified: 23 Apr 2026

    The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.

    Published: 1 Aug 2007
    5
    Medium

    CVE-2007-3847

    Last Modified: 23 Apr 2026

    The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.

    Published: 1 Aug 2007
    6
    Medium

    CVE-2007-4211

    Last Modified: 23 Apr 2026

    The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.

    Published: 1 Aug 2007
    6.8
    Medium

    CVE-2007-4101

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.

    Published: 31 Jul 2007
    4.3
    Medium

    CVE-2007-4102

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/></> sequence in the search string.

    Published: 31 Jul 2007
    4.3
    Medium

    CVE-2007-4104

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.

    Published: 31 Jul 2007
    9.3
    Critical

    CVE-2007-4105

    Last Modified: 23 Apr 2026

    A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4109

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4110

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 31 Jul 2007
    6.8
    Medium

    CVE-2007-4112

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."

    Published: 31 Jul 2007
    6.8
    Medium

    CVE-2007-4116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might be related to CVE-2007-0920 or CVE-2007-3884.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4107

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in editpost.php in phpMyForum before 4.1.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 31 Jul 2007
    5
    Medium

    CVE-2007-4100

    Last Modified: 23 Apr 2026

    MLDonkey before 2.9.0 does not load certain code from $MLDONKEY/web_infos/ before the network modules become active, which allows remote attackers to bypass the IP blocklist.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4103

    Last Modified: 23 Apr 2026

    The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when configured to allow unauthenticated calls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of calls that do not complete a 3-way handshake, which causes an ast_channel to be allocated but not released.

    Published: 31 Jul 2007
    6.8
    Medium

    CVE-2007-4106

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4108

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 31 Jul 2007
    6.8
    Medium

    CVE-2007-4111

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.

    Published: 31 Jul 2007
    7.5
    High

    CVE-2007-4114

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in unuttum.asp in SuskunDuygular Uyelik Sistemi 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) kadi or (2) email parameter. NOTE: some of these details are obtained from third party information.

    Published: 31 Jul 2007
    4.3
    Medium

    CVE-2007-4115

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.

    Published: 31 Jul 2007
    3.5
    Low

    CVE-2007-4113

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Advanced Webhost Billing System (AWBS) before 2.6.0 allows remote authenticated users to obtain configuration data about other dedicated servers via unspecified vectors.

    Published: 31 Jul 2007
    4.3
    Medium

    CVE-2007-3844

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.

    Published: 31 Jul 2007
    5.8
    Medium

    CVE-2007-4096

    Last Modified: 23 Apr 2026

    Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 30 Jul 2007
    6.4
    Medium

    CVE-2007-4097

    Last Modified: 23 Apr 2026

    Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

    Published: 30 Jul 2007
    5.8
    Medium

    CVE-2007-4099

    Last Modified: 23 Apr 2026

    Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks.

    Published: 30 Jul 2007
    5.8
    Medium

    CVE-2007-4098

    Last Modified: 23 Apr 2026

    Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

    Published: 30 Jul 2007
    7.8
    High

    CVE-2007-4093

    Last Modified: 23 Apr 2026

    Minb Is Not a Blog (minb) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing usernames and encrypted passwords via a direct request for db/users.db.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4094

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in library/authorize.php in IDevSpot PhpHostBot allows remote attackers to execute arbitrary PHP code via a URL in the login_form parameter, a different vector than CVE-2006-3776.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4095

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp.

    Published: 30 Jul 2007
    5
    Medium

    CVE-2007-4092

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. (dot dot) in the dir parameter.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4055

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this may be related to CVE-2006-4300.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4056

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.

    Published: 30 Jul 2007
    6.5
    Medium

    CVE-2007-4057

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png.

    Published: 30 Jul 2007
    4.3
    Medium

    CVE-2007-4058

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method.

    Published: 30 Jul 2007
    5.8
    Medium

    CVE-2007-4059

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SetLogFileName method.

    Published: 30 Jul 2007
    7.5
    High

    CVE-2007-4053

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the order parameter to new_images.php.

    Published: 30 Jul 2007
    4.3
    Medium

    CVE-2007-4071

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in uploader/index.php in Webbler CMS before 3.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) login parameter.

    Published: 30 Jul 2007
    5
    Medium

    CVE-2007-4072

    Last Modified: 23 Apr 2026

    Webbler CMS before 3.1.6 provides the full installation path within HTML comments in certain documents, which allows remote attackers to obtain sensitive information by viewing the HTML source, as demonstrated by viewing the source generated from index.php.

    Published: 30 Jul 2007
    5
    Medium

    CVE-2007-4073

    Last Modified: 23 Apr 2026

    Webbler CMS before 3.1.6 does not properly restrict use of "mail a friend" forms, which allows remote attackers to send arbitrary amounts of forged e-mail. NOTE: this could be leveraged for spam or phishing attacks.

    Published: 30 Jul 2007
    4.3
    Medium

    CVE-2007-4075

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.asp in Alisveris Sitesi Scripti allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search mod action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jul 2007
    6.4
    Medium

    CVE-2007-4080

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php AlstraSoft E-Friends allows remote attackers to inject arbitrary web script or HTML via the p_id parameter in a people_card action. NOTE: this might overlap CVE-2006-2564.

    Published: 30 Jul 2007
    4.3
    Medium

    CVE-2007-4082

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in contact_author.php AlstraSoft Article Manager Pro allows remote attackers to inject arbitrary web script or HTML via the userid parameter.

    Published: 30 Jul 2007
    6.8
    Medium

    CVE-2007-4086

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AlstraSoft Video Share Enterprise allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to gmembers.php, or (2) the UID parameter to (a) uvideos.php, (b) ugroups.php, (c) uprofile.php, (d) ufavour.php, (e) ufriends.php, or (f) uplaylist.php.

    Published: 30 Jul 2007
    4.3
    Medium

    CVE-2007-4089

    Last Modified: 23 Apr 2026

    Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components.

    Published: 30 Jul 2007
    7.8
    High

    CVE-2007-4062

    Last Modified: 23 Apr 2026

    The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.

    Published: 30 Jul 2007