CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-1597

    Last Modified: 23 Apr 2026

    Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.

    Published: 22 Mar 2007
    6.8
    Medium

    CVE-2007-1598

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by filecopa.tar by Immunity. NOTE: some of these details are obtained from third party information. NOTE: As of 20070322, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 22 Mar 2007
    4.3
    Medium

    CVE-2007-1606

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.

    Published: 22 Mar 2007
    6.5
    Medium

    CVE-2007-1599

    Last Modified: 23 Apr 2026

    wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.

    Published: 22 Mar 2007
    5
    Medium

    CVE-2007-1605

    Last Modified: 23 Apr 2026

    w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies. NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.

    Published: 22 Mar 2007
    7.8
    High

    CVE-2007-1594

    Last Modified: 23 Apr 2026

    The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Response code 0 in a SIP packet.

    Published: 22 Mar 2007
    7.5
    High

    CVE-2007-1595

    Last Modified: 23 Apr 2026

    The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.

    Published: 22 Mar 2007
    9.3
    Critical

    CVE-2007-1596

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.

    Published: 22 Mar 2007
    9.3
    Critical

    CVE-2007-1600

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.

    Published: 22 Mar 2007
    5
    Medium

    CVE-2007-1601

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files

    Published: 22 Mar 2007
    7.5
    High

    CVE-2007-1602

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 22 Mar 2007
    7.5
    High

    CVE-2007-1603

    Last Modified: 23 Apr 2026

    admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.

    Published: 22 Mar 2007
    7.5
    High

    CVE-2007-1604

    Last Modified: 23 Apr 2026

    Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.

    Published: 22 Mar 2007
    5
    Medium

    CVE-2007-1607

    Last Modified: 23 Apr 2026

    search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL sequences in the (1) search_forum or (2) search_user parameter, which force a SQL error.

    Published: 22 Mar 2007
    7.5
    High

    CVE-2007-1608

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.

    Published: 22 Mar 2007
    4.3
    Medium

    CVE-2007-1609

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.

    Published: 22 Mar 2007
    4.3
    Medium

    CVE-2007-1610

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via a feed.

    Published: 22 Mar 2007
    4.3
    Medium

    CVE-2007-1611

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.0 and 1.0.1, allows remote attackers to inject arbitrary web script or HTML via the title of an article in a feed.

    Published: 22 Mar 2007
    7.8
    High

    CVE-2007-1591

    Last Modified: 23 Apr 2026

    VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to cause a denial of service (kernel fault and system crash) via a crafted UPX file with a certain field that triggers a divide-by-zero error.

    Published: 22 Mar 2007
    5
    Medium

    CVE-2007-1349

    Last Modified: 23 Apr 2026

    PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.

    Published: 22 Mar 2007
    5
    Medium

    CVE-2007-1585

    Last Modified: 23 Apr 2026

    The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to obtain sensitive information (passwords and configuration data) via a packet to UDP port 916. NOTE: some of these details are obtained from third party information.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1584

    Last Modified: 23 Apr 2026

    Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.

    Published: 21 Mar 2007
    5
    Medium

    CVE-2007-1577

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1578

    Last Modified: 23 Apr 2026

    Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1579

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.

    Published: 21 Mar 2007
    6.3
    Medium

    CVE-2007-1580

    Last Modified: 23 Apr 2026

    FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:". NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument.

    Published: 21 Mar 2007
    9.3
    Critical

    CVE-2007-1581

    Last Modified: 23 Apr 2026

    The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1582

    Last Modified: 23 Apr 2026

    The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.

    Published: 21 Mar 2007
    7.8
    High

    CVE-2007-1586

    Last Modified: 23 Apr 2026

    ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1587

    Last Modified: 23 Apr 2026

    templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by specifying the program name in the qshapeLocation parameter.

    Published: 21 Mar 2007
    7.5
    High

    CVE-2007-1588

    Last Modified: 23 Apr 2026

    server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI programs with unintended privileges.

    Published: 21 Mar 2007
    2.1
    Low

    CVE-2007-1589

    Last Modified: 23 Apr 2026

    TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user.

    Published: 21 Mar 2007
    7.8
    High

    CVE-2007-1590

    Last Modified: 23 Apr 2026

    The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1002

    Last Modified: 23 Apr 2026

    Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.

    Published: 21 Mar 2007
    Unknown

    CVE-2007-1570

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1438. Reason: This candidate is a duplicate of CVE-2007-1438. Notes: All CVE users should reference CVE-2007-1438 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Mar 2007
    7.5
    High

    CVE-2007-1575

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) unspecified vectors to the (a) calendar and (2) search modules, and an (2) unspecified cookie when the user logs out.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1567

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

    Published: 21 Mar 2007
    4.3
    Medium

    CVE-2007-1576

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2006-7174

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this may be the same issue as CVE-2006-5235.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1568

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.

    Published: 21 Mar 2007
    10
    Critical

    CVE-2007-1569

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file. NOTE: some of these details are obtained from third party information.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1571

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1572

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Mar 2007
    6
    Medium

    CVE-2007-1573

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field.

    Published: 21 Mar 2007
    5
    Medium

    CVE-2007-1574

    Last Modified: 23 Apr 2026

    CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Mar 2007
    5
    Medium

    CVE-2007-0606

    Last Modified: 23 Apr 2026

    w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.

    Published: 21 Mar 2007
    7.5
    High

    CVE-2007-1313

    Last Modified: 23 Apr 2026

    NETxAutomation NETxEIB OPC Server before 3.0.1300 does not properly validate OLE for Process Control (OPC) server handles, which allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors involving the (1) IOPCSyncIO::Read, (2) IOPCSyncIO::Write, (3) IOPCServer::AddGroup, (4) IOPCServer::RemoveGroup, (5) IOPCCommon::SetClientName, and (6) IOPCGroupStateMgt::CloneGroup functions, which allow access to arbitrary memory. NOTE: the vectors might be limited to attackers with physical access.

    Published: 21 Mar 2007
    7.5
    High

    CVE-2007-1566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.

    Published: 21 Mar 2007
    6.8
    Medium

    CVE-2007-1463

    Last Modified: 23 Apr 2026

    Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.

    Published: 21 Mar 2007
    9.3
    Critical

    CVE-2007-0348

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.

    Published: 21 Mar 2007