CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-1188

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "search form hijacking".

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1161

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to inject arbitrary web script or HTML via the problem_desc parameter, as demonstrated by the ONLOAD attribute of a BODY element.

    Published: 28 Feb 2007
    7.8
    High

    CVE-2007-1162

    Last Modified: 23 Apr 2026

    A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1166

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1167

    Last Modified: 23 Apr 2026

    inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1168

    Last Modified: 23 Apr 2026

    Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1169

    Last Modified: 23 Apr 2026

    The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network.

    Published: 28 Feb 2007
    6.4
    Medium

    CVE-2007-1172

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."

    Published: 28 Feb 2007
    8.5
    High

    CVE-2006-7094

    Last Modified: 23 Apr 2026

    ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1164

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1165

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1163

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1170

    Last Modified: 23 Apr 2026

    SimBin GTR - FIA GT Racing Game 1.5.0.0 and earlier, GT Legends 1.1.0.0 and earlier, GTR 2 1.1 and earlier, and RACE - The WTCC Game 1.0 and earlier allow remote attackers to cause a denial of service (client disconnection) via an empty UDP packet to the server port.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1171

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2006-7092

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/mambo.php in Mambo LaiThai 4.5.4 SP2 and earlier allows remote attackers to execute arbitrary SQL commands via the usercookie[password] cookie parameter.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2006-7088

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2006-7089

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2006-7091

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Feb 2007
    10
    Critical

    CVE-2007-1160

    Last Modified: 23 Apr 2026

    webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.

    Published: 28 Feb 2007
    6.8
    Medium

    CVE-2006-7090

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the php_root_path parameter.

    Published: 28 Feb 2007
    5.8
    Medium

    CVE-2006-7093

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mambo LaiThai 4.5.4 Security Patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2006-7086

    Last Modified: 23 Apr 2026

    The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1158

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1159

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1199

    Last Modified: 23 Apr 2026

    Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2006-7087

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2006-7065

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7070

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7071

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7072

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b) admin/index.php, and (3) c[phone] parameter to register.php.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7073

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opentools Attachment Mod before 2.4.5 allows remote attackers to inject arbitrary web script or HTML in Internet Explorer via unknown vectors related to the uploaded attachments form. NOTE: some details were obtained from third party information.

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2006-7075

    Last Modified: 23 Apr 2026

    Buffer overflow in the meta_read_flac function in meta_decoder.c for Aqualung 0.9beta5 and earlier, and CVS 0.193.2 and earlier, allows user-assisted attackers to execute arbitrary code via a long Vorbis comment in a Free Lossless Audio Codec (FLAC) file.

    Published: 27 Feb 2007
    9.8
    Critical

    CVE-2006-7079

    Last Modified: 23 Apr 2026

    Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7080

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7081

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7082

    Last Modified: 23 Apr 2026

    Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to bypass authentication and upload arbitrary files via direct requests to (1) adm/photos/images.php and (2) adm/down/files.php.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7083

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to read arbitrary files via ".." sequences in the id parameter.

    Published: 27 Feb 2007
    10
    Critical

    CVE-2007-1134

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2007-1135

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1137

    Last Modified: 23 Apr 2026

    putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1141

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1142

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.

    Published: 27 Feb 2007
    7.8
    High

    CVE-2007-1143

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1144

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.

    Published: 27 Feb 2007
    3.6
    Low

    CVE-2007-1150

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1153

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or CVE-2006-4445.

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2007-1154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.

    Published: 27 Feb 2007
    6
    Medium

    CVE-2006-7067

    Last Modified: 23 Apr 2026

    Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third party, but the dispute was retracted. NOTE: this issue was called an "integer overflow" in the original source, but this might be incorrect.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7068

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2007-1136

    Last Modified: 23 Apr 2026

    index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

    Published: 27 Feb 2007