CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2007-1291

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1292

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1295

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1297

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1298

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1299

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2007-1307

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.

    Published: 7 Mar 2007
    4.3
    Medium

    CVE-2007-1287

    Last Modified: 23 Apr 2026

    A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2007-1264

    Last Modified: 23 Apr 2026

    Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2007-1269

    Last Modified: 23 Apr 2026

    GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2007-1268

    Last Modified: 23 Apr 2026

    Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2007-1267

    Last Modified: 23 Apr 2026

    Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2007-1266

    Last Modified: 23 Apr 2026

    Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    7.8
    High

    CVE-2007-1265

    Last Modified: 23 Apr 2026

    KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

    Published: 6 Mar 2007
    10
    Critical

    CVE-2006-7134

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7113

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7115

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.php when the path parameter is set to faq/faq.php, and other unspecified vectors involving guestbook/print.php.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php.

    Published: 6 Mar 2007
    7.8
    High

    CVE-2006-7121

    Last Modified: 23 Apr 2026

    The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authentication.

    Published: 6 Mar 2007
    6.8
    Medium

    CVE-2006-7122

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7123

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters when importing the (a) ip-to-country.csv file; and the (2) HTTP Referer, (3) HTTP User Agent, and (4) HTTP Accept Language headers to (b) bsqtemplateinc.php.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7124

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute arbitrary PHP code via the baseDir parameter.

    Published: 6 Mar 2007
    6.8
    Medium

    CVE-2006-7125

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7130

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770.

    Published: 6 Mar 2007
    10
    Critical

    CVE-2006-7131

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root parameter.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2006-7133

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.

    Published: 6 Mar 2007
    7.8
    High

    CVE-2007-1281

    Last Modified: 23 Apr 2026

    Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7119

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows remote attackers to execute arbitrary PHP code via a URL in the CFG_PHPGIGGLE_ROOT parameter.

    Published: 6 Mar 2007
    6.8
    Medium

    CVE-2006-7127

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/main.php and (2) forum/headlines.php.

    Published: 6 Mar 2007
    10
    Critical

    CVE-2006-7132

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang parameter to viewticket.php.

    Published: 6 Mar 2007
    6
    Medium

    CVE-2006-7112

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.

    Published: 6 Mar 2007
    6.8
    Medium

    CVE-2006-7117

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and (2) read arbitrary files via ".." sequences in the file parameter in an add_dl action to adm_index.php, as demonstrated by reading connect.php.

    Published: 6 Mar 2007
    10
    Critical

    CVE-2006-7120

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. NOTE: this issue might be in phpHtmlLib. NOTE: CVE disputes this issue for proper installations of maintain, since $phphtmllib is set in includes.inc before being used in example6.php

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7128

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter.

    Published: 6 Mar 2007
    2.1
    Low

    CVE-2006-7129

    Last Modified: 23 Apr 2026

    ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.

    Published: 6 Mar 2007
    5
    Medium

    CVE-2006-7114

    Last Modified: 23 Apr 2026

    P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. NOTE: this might be the same issue as CVE-2006-6888.

    Published: 6 Mar 2007
    7.5
    High

    CVE-2006-7118

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 6 Mar 2007
    6.8
    Medium

    CVE-2006-7126

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

    Published: 6 Mar 2007
    7.2
    High

    CVE-2007-1000

    Last Modified: 23 Apr 2026

    The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.

    Published: 6 Mar 2007
    6.9
    Medium

    CVE-2007-0005

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.

    Published: 6 Mar 2007
    5.8
    Medium

    CVE-2007-0715

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.

    Published: 5 Mar 2007
    9.3
    Critical

    CVE-2007-0712

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.

    Published: 5 Mar 2007
    9.3
    Critical

    CVE-2007-0714

    Last Modified: 23 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.

    Published: 5 Mar 2007
    5.8
    Medium

    CVE-2007-0718

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.

    Published: 5 Mar 2007
    9.3
    Critical

    CVE-2007-0711

    Last Modified: 23 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.

    Published: 5 Mar 2007
    5.8
    Medium

    CVE-2007-0713

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.

    Published: 5 Mar 2007
    5.8
    Medium

    CVE-2007-0716

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.

    Published: 5 Mar 2007
    5.8
    Medium

    CVE-2007-0717

    Last Modified: 23 Apr 2026

    Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.

    Published: 5 Mar 2007
    4.3
    Medium

    CVE-2007-1276

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.

    Published: 5 Mar 2007
    5.5
    Medium

    CVE-2006-7110

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.

    Published: 5 Mar 2007