CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-2267

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corruption or send_mondo panic) via unspecified vectors, as demonstrated by EMC Symcli backup software 6.2.1.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2268

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2269

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2272

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2273

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.

    Published: 25 Apr 2007
    7.8
    High

    CVE-2007-2274

    Last Modified: 23 Apr 2026

    The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.

    Published: 25 Apr 2007
    7.8
    High

    CVE-2007-2276

    Last Modified: 23 Apr 2026

    3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a "badly written loop." NOTE: the vendor disputes this issue, stating that the product has "performed as expected with no DoS emerging.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2277

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2254

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2257

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2260

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) source.php, (3) log.php, (4) latex.php, (5) indexinfo.php, (6) index.php, (7) importinfo.php, (8) import.php, (9) examplefile.php, (10) clearinfo.php, (11) clear.php, (12) aboutinfo.php, (13) about.php, and other unspecified files.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2252

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2253

    Last Modified: 23 Apr 2026

    Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2255

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459. NOTE: vector 3 might be an issue in SPAW.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2262

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as "File117".

    Published: 25 Apr 2007
    4.3
    Medium

    CVE-2007-2256

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2258

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2259

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2261

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-1721.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2243

    Last Modified: 23 Apr 2026

    OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

    Published: 25 Apr 2007
    5
    Medium

    CVE-2007-2250

    Last Modified: 23 Apr 2026

    admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2251

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd.

    Published: 25 Apr 2007
    9.3
    Critical

    CVE-2007-2244

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.

    Published: 25 Apr 2007
    6.8
    Medium

    CVE-2007-2245

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

    Published: 25 Apr 2007
    7.8
    High

    CVE-2007-2246

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2247

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Published: 25 Apr 2007
    4.3
    Medium

    CVE-2007-2248

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.

    Published: 25 Apr 2007
    6.5
    Medium

    CVE-2007-2249

    Last Modified: 23 Apr 2026

    include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2234

    Last Modified: 23 Apr 2026

    include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.

    Published: 25 Apr 2007
    4.3
    Medium

    CVE-2007-2235

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.

    Published: 25 Apr 2007
    6.8
    Medium

    CVE-2007-2236

    Last Modified: 23 Apr 2026

    footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or via the pun_include tag, as demonstrated by use of admin_options.php to execute PHP code from an uploaded avatar file.

    Published: 25 Apr 2007
    6.5
    Medium

    CVE-2007-2230

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CA Clever Path Portal allows remote authenticated users to execute limited SQL commands and retrieve arbitrary database contents via (1) the ofinterest parameter in a light search query, (2) description parameter in the advanced search query, and possibly other vectors.

    Published: 25 Apr 2007
    7.5
    High

    CVE-2007-2232

    Last Modified: 23 Apr 2026

    The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.

    Published: 25 Apr 2007
    6.5
    Medium

    CVE-2007-2233

    Last Modified: 23 Apr 2026

    cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.

    Published: 25 Apr 2007
    4.3
    Medium

    CVE-2007-2292

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

    Published: 25 Apr 2007
    4.9
    Medium

    CVE-2007-1861

    Last Modified: 23 Apr 2026

    The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.

    Published: 25 Apr 2007
    7.8
    High

    CVE-2009-1385

    Last Modified: 23 Apr 2026

    Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.

    Published: 25 Apr 2007
    7.8
    High

    CVE-2007-2135

    Last Modified: 23 Apr 2026

    The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2199

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2202

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.

    Published: 24 Apr 2007
    7.8
    High

    CVE-2007-2210

    Last Modified: 23 Apr 2026

    A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to "improper memory handling," possibly a buffer overflow.

    Published: 24 Apr 2007
    4.3
    Medium

    CVE-2007-2203

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form.

    Published: 24 Apr 2007
    7.5
    High

    CVE-2007-2204

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.

    Published: 24 Apr 2007
    4.3
    Medium

    CVE-2007-2206

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" in the ripeformpost parameter.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2209

    Last Modified: 23 Apr 2026

    Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources.

    Published: 24 Apr 2007
    7.5
    High

    CVE-2007-2212

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Apr 2007
    9.4
    Critical

    CVE-2007-2170

    Last Modified: 23 Apr 2026

    The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2171

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2200

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.

    Published: 24 Apr 2007
    7.5
    High

    CVE-2007-2201

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.

    Published: 24 Apr 2007