CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-2328

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in addvip.php in phpMYTGP 1.4b allows remote attackers to execute arbitrary PHP code via a URL in the msetstr[PROGSDIR] parameter.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2329

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in searchbot.php in Searchactivity allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 27 Apr 2007
    4.3
    Medium

    CVE-2007-2309

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the den parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2298

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2299

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2304

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2305

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 26 Apr 2007
    4.3
    Medium

    CVE-2007-2306

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2312

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2313

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Published: 26 Apr 2007
    6.8
    Medium

    CVE-2007-2314

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter to (a) configurer.php, (b) connect.php, (c) delete.php, (d) delete2.php, (e) index.php, (f) infos.php, (g) membres.php, (h) modif-infos.php, (i) modif-message.php, (j) modif.php, (k) uninstall.php, or (l) uninstall_table.php in admin/, different vectors than CVE-2007-2000. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Apr 2007
    10
    Critical

    CVE-2007-2316

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script "in txt mode from a browser."

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2317

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.

    Published: 26 Apr 2007
    6.8
    Medium

    CVE-2007-2319

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.

    Published: 26 Apr 2007
    4.3
    Medium

    CVE-2007-2300

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2301

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2302

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.

    Published: 26 Apr 2007
    6.8
    Medium

    CVE-2007-2303

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2307

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.

    Published: 26 Apr 2007
    4.3
    Medium

    CVE-2007-2308

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.

    Published: 26 Apr 2007
    4.3
    Medium

    CVE-2007-2310

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2311

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use

    Published: 26 Apr 2007
    7.8
    High

    CVE-2007-2315

    Last Modified: 23 Apr 2026

    MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.

    Published: 26 Apr 2007
    9.3
    Critical

    CVE-2007-2318

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2320

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.

    Published: 26 Apr 2007
    7.8
    High

    CVE-2007-2297

    Last Modified: 23 Apr 2026

    The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).

    Published: 26 Apr 2007
    6.8
    Medium

    CVE-2007-1683

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 26 Apr 2007
    7.8
    High

    CVE-2007-2294

    Last Modified: 23 Apr 2026

    The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2291

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.

    Published: 26 Apr 2007
    7.6
    High

    CVE-2007-2293

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.

    Published: 26 Apr 2007
    9.3
    Critical

    CVE-2007-2295

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.

    Published: 26 Apr 2007
    9.3
    Critical

    CVE-2007-2296

    Last Modified: 23 Apr 2026

    Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2287

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2288

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2289

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/includes/spaw/dialogs/insert_link.php in download engine (Download-Engine) 1.4.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the spaw_root parameter, a different vector than CVE-2007-2255. NOTE: this may be an issue in SPAW.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2286

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Built2Go PHP Link Portal 1.79 allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_db parameter.

    Published: 26 Apr 2007
    7.5
    High

    CVE-2007-2290

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.

    Published: 26 Apr 2007
    10
    Critical

    CVE-2007-2282

    Last Modified: 23 Apr 2026

    Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.

    Published: 26 Apr 2007
    9.3
    Critical

    CVE-2007-2283

    Last Modified: 23 Apr 2026

    Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.

    Published: 26 Apr 2007
    9.3
    Critical

    CVE-2007-2284

    Last Modified: 23 Apr 2026

    Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.

    Published: 26 Apr 2007
    7.8
    High

    CVE-2007-2285

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.

    Published: 26 Apr 2007
    7.6
    High

    CVE-2007-2438

    Last Modified: 23 Apr 2026

    The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.

    Published: 26 Apr 2007
    4.3
    Medium

    CVE-2006-7196

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

    Published: 26 Apr 2007
    7.8
    High

    CVE-2007-2270

    Last Modified: 23 Apr 2026

    The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.

    Published: 25 Apr 2007
    9.4
    Critical

    CVE-2007-2271

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.

    Published: 25 Apr 2007
    4.6
    Medium

    CVE-2007-2275

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2278

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the abs_path_editor parameter to library/editor/editor.php, or (3) the cfgfile_to_load parameter to admin/phpMyAdmin/libraries/common.lib.php.

    Published: 25 Apr 2007
    10
    Critical

    CVE-2007-2139

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.

    Published: 25 Apr 2007
    6.8
    Medium

    CVE-2007-2265

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.

    Published: 25 Apr 2007
    10
    Critical

    CVE-2007-2266

    Last Modified: 23 Apr 2026

    Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.

    Published: 25 Apr 2007