CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2007-2128

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unknown impact and remote authenticated attack vectors, aka APPS08.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2131

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.22.14, 8.47.12, and 8.48.08 has unknown impact and attack vectors, aka PSE01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2126

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2113

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vectors, aka DB07. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB07 is actually for multiple issues.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2107

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-1960. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2105

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/index.php in Monkey CMS 0.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the admin_skin parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2102

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vector than CVE-2006-6087.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2101

    Last Modified: 23 Apr 2026

    FAC Guestbook 3.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/gbdb.mdb. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2100

    Last Modified: 23 Apr 2026

    FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2099

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2098

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2094

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2093

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2091

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2090

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2006-7194

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2089

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2092

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2095

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in chat.php in MySpeach 1.9 allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter, a different vector than CVE-2007-0498.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2103

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2086

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2087

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2088

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Sitebar 3.3.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) writerFile parameter to index.php and the (2) file parameter to Integrator.php.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2096

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote attackers to execute arbitrary PHP code via a URL in the phphd_real_path parameter. NOTE: this issue may be present in versions from 2006.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2097

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7) articlesections.php, (8) createArticlesPage.php, (9) guestbook.php, (10) helpguide.php, (11) helpguideeditor.php, (12) links.php, (13) upload.php, (14) sitestatistics.php, (15) nav.php, (16) tpl_upload.php, (17) linksections, or (18) pophelp.php in htdocs/site-admin/; different vectors than CVE-2006-5076. NOTE: this issue is disputed by a third party, who states that $includes_path is defined before use

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2104

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in iXon CMS 0.30 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme_url parameter to (1) index.php, (2) page.php, (3) search.php, (4) single.php, and (5) archives.php.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2106

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2085

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in oe2edit.cgi in oe2edit CMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2084

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/. NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use

    Published: 18 Apr 2007
    6.9
    Medium

    CVE-2007-2083

    Last Modified: 23 Apr 2026

    vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.

    Published: 18 Apr 2007
    6.5
    Medium

    CVE-2007-2082

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2081

    Last Modified: 23 Apr 2026

    MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2080

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2076

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this problem existed only briefly in v1.0."

    Published: 18 Apr 2007
    6.9
    Medium

    CVE-2007-2075

    Last Modified: 23 Apr 2026

    ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container.

    Published: 18 Apr 2007
    4.6
    Medium

    CVE-2007-2074

    Last Modified: 23 Apr 2026

    Certain programs in containers in ScramDisk 4 Linux before 1.0-1 execute with SUID permissions, which allows local users to gain privileges via mounted containers.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2073

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the gallery parameter in a new session.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2072

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue has been disputed by third party researchers for 0.3, stating that the dir variable is properly initialized before use

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2068

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2067

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.

    Published: 18 Apr 2007
    5
    Medium

    CVE-2007-2066

    Last Modified: 23 Apr 2026

    UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2064

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.

    Published: 18 Apr 2007
    4.3
    Medium

    CVE-2007-2061

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2069

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dsn[phptype] parameter.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2077

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this issue was fixed last year and [no] is longer a problem."

    Published: 18 Apr 2007
    9.3
    Critical

    CVE-2007-1891

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote attackers to execute arbitrary code, related to misinterpretation of the nSize parameter as a byte count instead of a wide character count.

    Published: 18 Apr 2007
    9.3
    Critical

    CVE-2007-2062

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.

    Published: 18 Apr 2007
    4.4
    Medium

    CVE-2007-2063

    Last Modified: 23 Apr 2026

    SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2065

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2070

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

    Published: 18 Apr 2007