CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2006-7109

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.

    Published: 5 Mar 2007
    7.5
    High

    CVE-2006-7111

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Futomi's CGI Cafe KMail CGI 1.0.3 and earlier allows remote attackers to bypass authentication and obtain unauthorized email access via unspecified vectors.

    Published: 5 Mar 2007
    7.5
    High

    CVE-2007-1277

    Last Modified: 23 Apr 2026

    WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

    Published: 5 Mar 2007
    5
    Medium

    CVE-2007-3390

    Last Modified: 23 Apr 2026

    Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP.

    Published: 5 Mar 2007
    6.8
    Medium

    CVE-2007-0994

    Last Modified: 23 Apr 2026

    A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.

    Published: 5 Mar 2007
    5
    Medium

    CVE-2007-1263

    Last Modified: 23 Apr 2026

    GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.

    Published: 5 Mar 2007
    9.3
    Critical

    CVE-2007-1282

    Last Modified: 23 Apr 2026

    Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.

    Published: 5 Mar 2007
    4.3
    Medium

    CVE-2007-1308

    Last Modified: 23 Apr 2026

    ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

    Published: 4 Mar 2007
    7.5
    High

    CVE-2006-7101

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the AdminUser cookie.

    Published: 3 Mar 2007
    6.8
    Medium

    CVE-2006-7100

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Insert User 0.1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2006-7104

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2006-7106

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2006-7107

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.

    Published: 3 Mar 2007
    6.4
    Medium

    CVE-2006-7103

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1260

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1261

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2006-7102

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter to (1) quest_delete.php, (2) quest_edit.php, or (3) quest_news.php.

    Published: 3 Mar 2007
    9.8
    Critical

    CVE-2006-7105

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect

    Published: 3 Mar 2007
    6
    Medium

    CVE-2007-1255

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/. NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.

    Published: 3 Mar 2007
    9.3
    Critical

    CVE-2007-1251

    Last Modified: 23 Apr 2026

    Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1248

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1259

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.

    Published: 3 Mar 2007
    10
    Critical

    CVE-2007-1257

    Last Modified: 23 Apr 2026

    The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

    Published: 3 Mar 2007
    6.1
    Medium

    CVE-2007-1258

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.

    Published: 3 Mar 2007
    6.8
    Medium

    CVE-2007-1256

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.

    Published: 3 Mar 2007
    9.3
    Critical

    CVE-2007-1252

    Last Modified: 23 Apr 2026

    Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message. NOTE: some information was obtained from third party sources.

    Published: 3 Mar 2007
    9.3
    Critical

    CVE-2007-1253

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.

    Published: 3 Mar 2007
    6.5
    Medium

    CVE-2007-1254

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1250

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Mar 2007
    6.8
    Medium

    CVE-2007-1249

    Last Modified: 23 Apr 2026

    MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.

    Published: 3 Mar 2007
    6.8
    Medium

    CVE-2007-1247

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.

    Published: 3 Mar 2007
    5.8
    Medium

    CVE-2007-1241

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1239

    Last Modified: 23 Apr 2026

    Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1233

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1243

    Last Modified: 23 Apr 2026

    Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1242

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1240

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2007
    7.5
    High

    CVE-2007-1235

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1234

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php.

    Published: 3 Mar 2007
    6.6
    Medium

    CVE-2006-7098

    Last Modified: 23 Apr 2026

    The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.

    Published: 3 Mar 2007
    5
    Medium

    CVE-2006-7099

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot dot) in the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1231

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files.

    Published: 3 Mar 2007
    5.1
    Medium

    CVE-2007-1232

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.

    Published: 3 Mar 2007
    6.4
    Medium

    CVE-2007-1236

    Last Modified: 23 Apr 2026

    sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.

    Published: 3 Mar 2007
    5
    Medium

    CVE-2007-1237

    Last Modified: 23 Apr 2026

    sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1238

    Last Modified: 23 Apr 2026

    Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.

    Published: 3 Mar 2007
    6.8
    Medium

    CVE-2007-1244

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

    Published: 3 Mar 2007
    7.6
    High

    CVE-2007-1246

    Last Modified: 23 Apr 2026

    The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.

    Published: 3 Mar 2007
    4.3
    Medium

    CVE-2007-1245

    Last Modified: 23 Apr 2026

    IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.

    Published: 3 Mar 2007
    3.4
    Low

    CVE-2007-1716

    Last Modified: 23 Apr 2026

    pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.

    Published: 3 Mar 2007