CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-3589

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.

    Published: 5 Jul 2007
    7.2
    High

    CVE-2007-2839

    Last Modified: 23 Apr 2026

    gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

    Published: 5 Jul 2007
    4
    Medium

    CVE-2006-7216

    Last Modified: 23 Apr 2026

    Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables.

    Published: 5 Jul 2007
    4
    Medium

    CVE-2006-7217

    Last Modified: 23 Apr 2026

    Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.

    Published: 5 Jul 2007
    6.8
    Medium

    CVE-2007-3573

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in akocomment allow remote attackers to execute arbitrary SQL commands via the (1) acparentid or (2) acitemid parameter to an unspecified component, different vectors than CVE-2006-1421.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3574

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3575

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/functions in FreeDomain.co.nr Clone allows remote attackers to execute arbitrary SQL commands via the logindomain parameter to members.php.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3577

    Last Modified: 23 Apr 2026

    PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressions; (6) certain '=' expressions, as demonstrated by a 'whatever="something"' sequence; and (7) certain "with" expressions, which allows remote attackers to inject arbitrary web script.

    Published: 5 Jul 2007
    5
    Medium

    CVE-2007-3581

    Last Modified: 23 Apr 2026

    The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert View.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3583

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3584

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3585

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3579

    Last Modified: 23 Apr 2026

    PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3588

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in reply.php in VBZooM 1.12 allows remote attackers to execute arbitrary SQL commands via the UserID parameter to sub-join.php. NOTE: this may be the same as CVE-2006-3691.4.

    Published: 5 Jul 2007
    9.3
    Critical

    CVE-2007-3572

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3580

    Last Modified: 23 Apr 2026

    PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, which allows user-assisted remote attackers to inject arbitrary web script.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3576

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes. NOTE: other researchers dispute the significance of this issue, stating "this only works when typed in the address bar.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3578

    Last Modified: 23 Apr 2026

    PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remote attackers to inject arbitrary web script.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3586

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3587

    Last Modified: 23 Apr 2026

    MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3011

    Last Modified: 23 Apr 2026

    The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3567

    Last Modified: 23 Apr 2026

    MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3569

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) "Basic Search page"; and (8) username parameter when (c) logging on.

    Published: 5 Jul 2007
    7.5
    High

    CVE-2007-3570

    Last Modified: 23 Apr 2026

    The Linux Access Gateway in Novell Access Manager before 3.0 SP1 Release Candidate 1 (RC1) allows remote attackers to bypass unspecified security controls via Fullwidth/Halfwidth Unicode encoded data in a HTTP POST request.

    Published: 5 Jul 2007
    5
    Medium

    CVE-2007-3012

    Last Modified: 23 Apr 2026

    The web interface in Fujitsu-Siemens Computers PRIMERGY BX300 Switch Blade allows remote attackers to obtain sensitive information by canceling the authentication dialog when accessing a sub-page, which still displays the form field contents of the sub-page, as demonstrated using (1) config/ip_management.htm and (2) config/snmp_config.htm.

    Published: 5 Jul 2007
    4.3
    Medium

    CVE-2007-3571

    Last Modified: 23 Apr 2026

    The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.

    Published: 5 Jul 2007
    6.8
    Medium

    CVE-2007-3557

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter.

    Published: 4 Jul 2007
    7.5
    High

    CVE-2007-3558

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.

    Published: 4 Jul 2007
    7.5
    High

    CVE-2007-3560

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Esqlanelapse before 2.6 have unknown impact and attack vectors.

    Published: 4 Jul 2007
    4.3
    Medium

    CVE-2007-3561

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Jul 2007
    3.5
    Low

    CVE-2007-3559

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant.

    Published: 4 Jul 2007
    7.5
    High

    CVE-2007-3563

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.

    Published: 4 Jul 2007
    7.5
    High

    CVE-2007-3562

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Jul 2007
    5
    Medium

    CVE-2007-3556

    Last Modified: 23 Apr 2026

    Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.

    Published: 4 Jul 2007
    7.6
    High

    CVE-2007-3554

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.

    Published: 4 Jul 2007
    4.3
    Medium

    CVE-2007-3555

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

    Published: 4 Jul 2007
    3.5
    Low

    CVE-2007-3782

    Last Modified: 23 Apr 2026

    MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.

    Published: 4 Jul 2007
    4
    Medium

    CVE-2007-3781

    Last Modified: 23 Apr 2026

    MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.

    Published: 4 Jul 2007
    5
    Medium

    CVE-2007-3780

    Last Modified: 23 Apr 2026

    MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.

    Published: 4 Jul 2007
    7.5
    High

    CVE-2007-3549

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 3 Jul 2007
    7.8
    High

    CVE-2007-3550

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated

    Published: 3 Jul 2007
    6.1
    Medium

    CVE-2007-3551

    Last Modified: 23 Apr 2026

    Buffer overflow in bbs100 before 3.2 allows remote attackers to cause a denial of service (crash) by attempting to login as the Guest user when another Guest user is already logged in, possibly related to the state_login_prompt function in state_login.c.

    Published: 3 Jul 2007
    7.8
    High

    CVE-2007-3552

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in bbs100 before 3.2 allow remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving certain v*printf and shift_StringIO functions. NOTE: some details were obtained from third party information.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3553

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Jul 2007
    2.1
    Low

    CVE-2006-7215

    Last Modified: 23 Apr 2026

    The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems other than OpenBSD, aka AI90.

    Published: 3 Jul 2007
    7.1
    High

    CVE-2007-3548

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3534

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.

    Published: 3 Jul 2007
    6.4
    Medium

    CVE-2007-3535

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php.

    Published: 3 Jul 2007
    7.6
    High

    CVE-2007-3536

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.

    Published: 3 Jul 2007