CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-3799

    Last Modified: 23 Apr 2026

    The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.

    Published: 1 Jun 2007
    9.3
    Critical

    CVE-2007-0328

    Last Modified: 23 Apr 2026

    The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.

    Published: 1 Jun 2007
    6.8
    Medium

    CVE-2007-2872

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.

    Published: 1 Jun 2007
    7.5
    High

    CVE-2007-2959

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2960

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Scallywag 2005-04-25 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin_name parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/, a different vector than CVE-2007-2900. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2961

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in FileCloset before 1.1.5 allows remote attackers to upload arbitrary PHP files via unspecified vectors.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2962

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter.

    Published: 31 May 2007
    10
    Critical

    CVE-2007-2967

    Last Modified: 23 Apr 2026

    Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2963

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) module_bbcodeloader.php, (2) module_div.php, (3) module_email.php, (4) module_image.php, (5) module_link.php, or (6) the editorid parameter to module_table.php in jscripts/folder_rte_files/. NOTE: some details were obtained from third party sources.

    Published: 31 May 2007
    7.2
    High

    CVE-2007-2965

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and "access validation of the address space."

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2966

    Last Modified: 23 Apr 2026

    Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.

    Published: 31 May 2007
    5
    Medium

    CVE-2007-2964

    Last Modified: 23 Apr 2026

    The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.

    Published: 31 May 2007
    9.3
    Critical

    CVE-2007-2868

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2870

    Last Modified: 23 Apr 2026

    Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2871

    Last Modified: 23 Apr 2026

    Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2932

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2936

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2937

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.

    Published: 31 May 2007
    6.8
    Medium

    CVE-2007-2939

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.

    Published: 31 May 2007
    6.8
    Medium

    CVE-2007-2940

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2935

    Last Modified: 23 Apr 2026

    core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict parameter.

    Published: 31 May 2007
    5
    Medium

    CVE-2007-2944

    Last Modified: 23 Apr 2026

    WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/wabcmsn.mdb. NOTE: this issue was originally reported for "webCMS," but this was an error by an unreliable researcher.

    Published: 31 May 2007
    5
    Medium

    CVE-2007-2945

    Last Modified: 23 Apr 2026

    RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2947

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2942

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 May 2007
    9.3
    Critical

    CVE-2007-2867

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-2869

    Last Modified: 23 Apr 2026

    The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.

    Published: 31 May 2007
    7.8
    High

    CVE-2007-2934

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter.

    Published: 31 May 2007
    6.8
    Medium

    CVE-2007-2943

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 31 May 2007
    4.3
    Medium

    CVE-2007-1362

    Last Modified: 23 Apr 2026

    Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies."

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.

    Published: 31 May 2007
    10
    Critical

    CVE-2007-2938

    Last Modified: 23 Apr 2026

    Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.

    Published: 31 May 2007
    7.5
    High

    CVE-2007-2941

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.

    Published: 31 May 2007
    10
    Critical

    CVE-2007-2946

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath property value.

    Published: 31 May 2007
    5
    Medium

    CVE-2007-0690

    Last Modified: 23 Apr 2026

    myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-0692

    Last Modified: 23 Apr 2026

    DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages.

    Published: 30 May 2007
    6.8
    Medium

    CVE-2007-0693

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-0694

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2898

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2899

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2904

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2905

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the post_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 May 2007
    3.5
    Low

    CVE-2007-2909

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2910

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a related issue to CVE-2007-2909.

    Published: 30 May 2007
    8.5
    High

    CVE-2007-2911

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2913

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ClonusWiki .5 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2916

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote attackers to inject arbitrary web script or HTML via the st parameter.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2902

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-2903

    Last Modified: 23 Apr 2026

    Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2901

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.

    Published: 30 May 2007