CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2007-1743

    Last Modified: 23 Apr 2026

    suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.

    Published: 13 Apr 2007
    3.7
    Low

    CVE-2007-1742

    Last Modified: 23 Apr 2026

    suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."

    Published: 13 Apr 2007
    6.2
    Medium

    CVE-2007-1741

    Last Modified: 23 Apr 2026

    Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."

    Published: 13 Apr 2007
    7.5
    High

    CVE-2007-2021

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2019

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.

    Published: 12 Apr 2007
    6.5
    Medium

    CVE-2007-2018

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2017

    Last Modified: 23 Apr 2026

    siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-2016

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2006-7193

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the SMARTY_DIR parameter. NOTE: this issue is disputed by CVE and a third party because SMARTY_DIR is a constant

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-2013

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2004

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2014

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1998

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2005

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2015

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Published: 12 Apr 2007
    9.8
    Critical

    CVE-2007-2020

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1999

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2000

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.

    Published: 12 Apr 2007
    6.5
    Medium

    CVE-2007-2001

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2002

    Last Modified: 23 Apr 2026

    InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2003

    Last Modified: 23 Apr 2026

    InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2006

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2007

    Last Modified: 23 Apr 2026

    admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-2008

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-2010

    Last Modified: 23 Apr 2026

    Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-2011

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 12 Apr 2007
    5.8
    Medium

    CVE-2007-2012

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MimarSinan CompreXX 4.1 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .rar, (2) .jar or (3) .zip archive.

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-1989

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1990

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-1991

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1992

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.

    Published: 12 Apr 2007
    9.3
    Critical

    CVE-2007-1993

    Last Modified: 23 Apr 2026

    Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."

    Published: 12 Apr 2007
    4.9
    Medium

    CVE-2007-1994

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.

    Published: 12 Apr 2007
    6.8
    Medium

    CVE-2007-1996

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.

    Published: 12 Apr 2007
    7.8
    High

    CVE-2007-1981

    Last Modified: 23 Apr 2026

    The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1982

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1980

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1983

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1984

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in lite-cms 0.2.1 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1985

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpexplorator.php in phpexplorator 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd or (2) lang_path parameter.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1986

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1987

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPEcho CMS 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _plugin_file parameter to smarty/internals/core.load_pulgins.php or the (2) root_path parameter to index.php. NOTE: CVE disputes (1) because the inclusion occurs within a function that is not called during a direct request. CVE disputes (2) because root_path is defined in config.php before use

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-1988

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 12 Apr 2007
    5
    Medium

    CVE-2007-2028

    Last Modified: 23 Apr 2026

    Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1974

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1975

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SLAED CMS 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path parameter to admin/admin.php or the (2) modpath parameter to index.php.

    Published: 12 Apr 2007
    7.5
    High

    CVE-2007-1976

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application's checkSuperglobals function defends against the attack

    Published: 12 Apr 2007
    4.3
    Medium

    CVE-2007-1977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.

    Published: 12 Apr 2007