CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-1146

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in function.php in arabhost allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1149

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1156

    Last Modified: 23 Apr 2026

    JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.

    Published: 27 Feb 2007
    7.1
    High

    CVE-2006-7066

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7069

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2006-7074

    Last Modified: 23 Apr 2026

    admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2006-7077

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7078

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Professional Home Page Tools Login Script, as of July 2006, allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) vorname, and (3) nachname parameters in the register script. NOTE: some details have been obtained from third party sources.

    Published: 27 Feb 2007
    10
    Critical

    CVE-2007-1139

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.

    Published: 27 Feb 2007
    9.4
    Critical

    CVE-2007-1140

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1145

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1147

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1148

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1151

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1152

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Feb 2007
    4.6
    Medium

    CVE-2007-1155

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED.

    Published: 27 Feb 2007
    7.6
    High

    CVE-2007-1157

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7076

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.

    Published: 27 Feb 2007
    Unknown

    CVE-2006-7084

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-7083. Reason: This candidate is a duplicate of CVE-2006-7083. Notes: All CVE users should reference CVE-2006-7083 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2006-7085

    Last Modified: 23 Apr 2026

    Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php. NOTE: this issue was originally reported as SQL injection, but this is not likely.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1138

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

    Published: 27 Feb 2007
    10
    Critical

    CVE-2007-1117

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.

    Published: 27 Feb 2007
    6.8
    Medium

    CVE-2007-1118

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.

    Published: 27 Feb 2007
    6.4
    Medium

    CVE-2007-1119

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that were not configured in the "Only allow uploads to the following directories" setting via unspecified vectors.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1123

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php. NOTE: the zpanel.php vector may overlap CVE-2005-0793.2. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1124

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1125

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.

    Published: 27 Feb 2007
    6.4
    Medium

    CVE-2007-1127

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1128

    Last Modified: 23 Apr 2026

    shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1132

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1133

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1131

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

    Published: 27 Feb 2007
    6.4
    Medium

    CVE-2007-1121

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Feb 2007
    6.4
    Medium

    CVE-2007-1122

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01. NOTE: some of these details are obtained from third party information.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2007-1126

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1130

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

    Published: 27 Feb 2007
    9.3
    Critical

    CVE-2007-1120

    Last Modified: 23 Apr 2026

    The (1) Import.LoadFromURL and (2) Export.asText.SaveToFile functions in TeeChart Pro ActiveX control (TeeChart7.ocx) allow remote attackers to download a crafted .tee file to an arbitrary location. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-1129

    Last Modified: 23 Apr 2026

    Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.

    Published: 27 Feb 2007
    7.5
    High

    CVE-2007-0774

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.

    Published: 27 Feb 2007
    4.7
    Medium

    CVE-2008-1072

    Last Modified: 23 Apr 2026

    The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2008-1071

    Last Modified: 23 Apr 2026

    The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

    Published: 27 Feb 2007
    5
    Medium

    CVE-2008-1070

    Last Modified: 23 Apr 2026

    The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

    Published: 27 Feb 2007
    4.3
    Medium

    CVE-2007-1115

    Last Modified: 23 Apr 2026

    The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.

    Published: 26 Feb 2007
    5
    Medium

    CVE-2007-1116

    Last Modified: 23 Apr 2026

    The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.

    Published: 26 Feb 2007
    4.3
    Medium

    CVE-2007-1114

    Last Modified: 23 Apr 2026

    The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.

    Published: 26 Feb 2007
    9.3
    Critical

    CVE-2007-0776

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.

    Published: 26 Feb 2007
    10
    Critical

    CVE-2007-1097

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation. NOTE: some details were obtained from third party information.

    Published: 26 Feb 2007
    7.8
    High

    CVE-2007-1098

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ScryMUD before 2.1.11 have unknown impact and attack vectors, possibly related to denial of service caused by a search that begins with a .* sequence.

    Published: 26 Feb 2007
    7.5
    High

    CVE-2007-1099

    Last Modified: 23 Apr 2026

    dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

    Published: 26 Feb 2007
    4.3
    Medium

    CVE-2007-1101

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.

    Published: 26 Feb 2007