CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2007-2436

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1861. Reason: This candidate is a duplicate of CVE-2007-1861. Notes: All CVE users should reference CVE-2007-1861 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 May 2007
    6.8
    Medium

    CVE-2007-2433

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Ariadne 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the ARLogin parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    10
    Critical

    CVE-2007-2434

    Last Modified: 23 Apr 2026

    Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query.

    Published: 2 May 2007
    6.8
    Medium

    CVE-2007-2432

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in utilities/search.asp in nukedit 4.9.7b allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    4.6
    Medium

    CVE-2008-4210

    Last Modified: 23 Apr 2026

    fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2421

    Last Modified: 23 Apr 2026

    Buffer overflow in Hitachi Groupmax Mobile Option for Mobile-Phone 07-00 through 07-30, 5 for i-mode 05-11 through 05-23, and 6 for EZweb 06-00 through 06-04 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2428

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2430

    Last Modified: 23 Apr 2026

    shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.

    Published: 2 May 2007
    6.8
    Medium

    CVE-2007-2431

    Last Modified: 23 Apr 2026

    Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.

    Published: 2 May 2007
    5
    Medium

    CVE-2007-2425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter.

    Published: 2 May 2007
    10
    Critical

    CVE-2007-2429

    Last Modified: 23 Apr 2026

    ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2420

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 May 2007
    9.8
    Critical

    CVE-2007-2422

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string

    Published: 2 May 2007
    5.8
    Medium

    CVE-2007-2423

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    5
    Medium

    CVE-2007-1863

    Last Modified: 23 Apr 2026

    cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2424

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2426

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2414

    Last Modified: 23 Apr 2026

    MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 May 2007
    Unknown

    CVE-2007-2413

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2459. Reason: This candidate is a duplicate of CVE-2007-2459. Notes: All CVE users should reference CVE-2007-2459 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 May 2007
    5
    Medium

    CVE-2007-2415

    Last Modified: 23 Apr 2026

    Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a "clean" exit in which "the server I/O loop finishes and the process exits normally."

    Published: 1 May 2007
    7.5
    High

    CVE-2007-2411

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. NOTE: a third party disputes this vulnerability, stating that "the application is not vulnerable to this issue.

    Published: 1 May 2007
    7.8
    High

    CVE-2007-2412

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter. NOTE: a third party has disputed this issue because the a array is populated by a database query before use

    Published: 1 May 2007
    7.5
    High

    CVE-2007-2416

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter.

    Published: 1 May 2007
    2.1
    Low

    CVE-2007-3379

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.

    Published: 1 May 2007
    9
    Critical

    CVE-2006-7200

    Last Modified: 23 Apr 2026

    EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier for attackers to bypass one stage of authentication by stealing and replaying a token.

    Published: 30 Apr 2007
    9.3
    Critical

    CVE-2006-7201

    Last Modified: 23 Apr 2026

    EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared object), which might allow remote attackers to obtain the token via HTTP.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2370

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.

    Published: 30 Apr 2007
    8.5
    High

    CVE-2006-7199

    Last Modified: 23 Apr 2026

    EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server. NOTE: the vendor disputes the severity of the issue, stating that it is easier to monitor this attack than "attacks against static web pages."

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2373

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 30 Apr 2007
    9.3
    Critical

    CVE-2007-2374

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2375

    Last Modified: 23 Apr 2026

    The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2376

    Last Modified: 23 Apr 2026

    The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2378

    Last Modified: 23 Apr 2026

    The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2381

    Last Modified: 23 Apr 2026

    The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2367

    Last Modified: 23 Apr 2026

    Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2368

    Last Modified: 23 Apr 2026

    picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2369

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2371

    Last Modified: 23 Apr 2026

    admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2372

    Last Modified: 23 Apr 2026

    admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2377

    Last Modified: 23 Apr 2026

    The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2379

    Last Modified: 23 Apr 2026

    The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2380

    Last Modified: 23 Apr 2026

    The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2382

    Last Modified: 23 Apr 2026

    The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2383

    Last Modified: 23 Apr 2026

    The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    7.8
    High

    CVE-2007-2384

    Last Modified: 23 Apr 2026

    The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2385

    Last Modified: 23 Apr 2026

    The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

    Published: 30 Apr 2007
    7.8
    High

    CVE-2006-4520

    Last Modified: 23 Apr 2026

    ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2006-7198

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.

    Published: 30 Apr 2007
    6.8
    Medium

    CVE-2007-2357

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mods/Core/result.php in SineCms 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the stringa parameter.

    Published: 30 Apr 2007