CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-1102

    Last Modified: 23 Apr 2026

    Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

    Published: 26 Feb 2007
    6.8
    Medium

    CVE-2007-1106

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 26 Feb 2007
    7.5
    High

    CVE-2007-1107

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.

    Published: 26 Feb 2007
    6.8
    Medium

    CVE-2007-1108

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.

    Published: 26 Feb 2007
    4.3
    Medium

    CVE-2007-1109

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) login or (2) mail_address field in Register.php, or the (3) search_author, (4) mode, (5) start_year, (6) end_year, or (7) date_type field in Search.php, a different vulnerability than CVE-2006-1674. NOTE: 1.6.2 and other versions might also be affected.

    Published: 26 Feb 2007
    5
    Medium

    CVE-2007-1110

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 26 Feb 2007
    4.3
    Medium

    CVE-2007-1104

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.

    Published: 26 Feb 2007
    10
    Critical

    CVE-2007-1093

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.

    Published: 26 Feb 2007
    7.8
    High

    CVE-2007-1094

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.

    Published: 26 Feb 2007
    6.8
    Medium

    CVE-2007-1096

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue might overlap CVE-2007-0376.

    Published: 26 Feb 2007
    7.8
    High

    CVE-2007-1100

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 26 Feb 2007
    5
    Medium

    CVE-2007-1105

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 26 Feb 2007
    4.3
    Medium

    CVE-2007-1103

    Last Modified: 23 Apr 2026

    Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.

    Published: 26 Feb 2007
    6.8
    Medium

    CVE-2007-1111

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.

    Published: 26 Feb 2007
    7.1
    High

    CVE-2007-1090

    Last Modified: 23 Apr 2026

    Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.

    Published: 26 Feb 2007
    6.8
    Medium

    CVE-2007-1091

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.

    Published: 26 Feb 2007
    7.5
    High

    CVE-2006-7057

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue might be primary to CVE-2006-2506.2.

    Published: 24 Feb 2007
    4.3
    Medium

    CVE-2006-7058

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML via the catid parameter to (1) templates/standard/search_form.html and (2) templates/dark/search_form.html. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Feb 2007
    7.8
    High

    CVE-2006-7062

    Last Modified: 23 Apr 2026

    calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7063

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter.

    Published: 24 Feb 2007
    9.3
    Critical

    CVE-2006-7064

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.

    Published: 24 Feb 2007
    5
    Medium

    CVE-2006-7060

    Last Modified: 23 Apr 2026

    cindex.php in Scriptsez.net E-Dating System allows remote attackers to obtain the full path via an invalid id parameter in a dologin action, which leaks the path in an error message.

    Published: 24 Feb 2007
    4.3
    Medium

    CVE-2006-7059

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (&#0000039) in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.

    Published: 24 Feb 2007
    9.3
    Critical

    CVE-2006-7061

    Last Modified: 23 Apr 2026

    Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.

    Published: 24 Feb 2007
    4.3
    Medium

    CVE-2007-5034

    Last Modified: 23 Apr 2026

    ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7044

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in comment.core.inc.php in Clan Manager Pro (CMPRO) 1.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.

    Published: 24 Feb 2007
    9.3
    Critical

    CVE-2006-7046

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Feb 2007
    4.9
    Medium

    CVE-2006-7051

    Last Modified: 23 Apr 2026

    The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix timers, which are allocated in kernel memory but are not treated as part of the process' memory.

    Published: 24 Feb 2007
    10
    Critical

    CVE-2006-7052

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.php, (b) showcatpicks.php, and (c) showarticle.php; and the (2) admin_header_file and (3) admin_footer_file parameters to (d) admin/authors.php, (e) admin/index.php, (f) admin/categories.php, (g) admin/editconfig.php, and (h) admin/articles.php.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7053

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."

    Published: 24 Feb 2007
    6.8
    Medium

    CVE-2006-7055

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.

    Published: 24 Feb 2007
    6.8
    Medium

    CVE-2006-7042

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject arbitrary web script or HTML via the start parameter.

    Published: 24 Feb 2007
    3.5
    Low

    CVE-2006-7043

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7045

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Clan Manager Pro (CMPRO) 1.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) rootpath and possibly (2) sitepath parameters to (a) cmpro.ext/comment.core.inc.php and (b) cmpro.intern/comment.core.inc.php. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7048

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter to (a) atutor.inc.php (b) db-generic.inc.php (c) docebo.inc.php (d) dokeos.1.6.inc.php (e) dokeos.inc.php (f) ganesha.inc.php (g) mambo.inc.php (h) moodle.inc.php (i) phpnuke.inc.php (j) postnuke.inc.php and (k) spip.inc.php in claroline/auth/extauth/drivers/; (2) includePath parameter in mambo.inc.php, postnuke.inc.php, and (l) inc/lib/event/init_event_manager.inc.php; and (3) rootSys parameter in (m) inc/lib/export_exe_tracking.class.php, a different set of vectors than CVE-2006-2284.

    Published: 24 Feb 2007
    7.5
    High

    CVE-2006-7049

    Last Modified: 23 Apr 2026

    The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.

    Published: 24 Feb 2007
    6.8
    Medium

    CVE-2006-7056

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DreamCost HostAdmin 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) functions.php and (2) members.php. NOTE: the index.php vector is covered by CVE-2006-0791.

    Published: 24 Feb 2007
    7.8
    High

    CVE-2006-7054

    Last Modified: 23 Apr 2026

    The DNS module in Arkoon FAST360 UTM appliances 3.0 up to 3.0/29, 3.1 through 3.3, and 4.0 allows remote attackers to cause a denial of service (reboot) via a malformed DNS message, as demonstrated by the PROTOS DNS testing suite.

    Published: 24 Feb 2007
    5
    Medium

    CVE-2006-7047

    Last Modified: 23 Apr 2026

    include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate bannedips.php file. NOTE: this issue was originally reported as remote file inclusion, but CVE analysis suggests that this cannot be used for code execution.

    Published: 24 Feb 2007
    6.8
    Medium

    CVE-2006-7050

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.

    Published: 24 Feb 2007
    7.2
    High

    CVE-2007-1086

    Last Modified: 23 Apr 2026

    Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."

    Published: 23 Feb 2007
    7.2
    High

    CVE-2007-1087

    Last Modified: 23 Apr 2026

    IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

    Published: 23 Feb 2007
    7.2
    High

    CVE-2007-1089

    Last Modified: 23 Apr 2026

    IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

    Published: 23 Feb 2007
    7.2
    High

    CVE-2007-1088

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.

    Published: 23 Feb 2007
    7.8
    High

    CVE-2006-5877

    Last Modified: 23 Apr 2026

    The enigmail extension before 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote attackers to cause a denial of service (crash), as demonstrated with Mozilla Thunderbird.

    Published: 23 Feb 2007
    7.5
    High

    CVE-2006-7025

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.

    Published: 23 Feb 2007
    5
    Medium

    CVE-2006-7030

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.

    Published: 23 Feb 2007
    10
    Critical

    CVE-2006-7032

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.

    Published: 23 Feb 2007
    4.4
    Medium

    CVE-2006-7037

    Last Modified: 23 Apr 2026

    Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.

    Published: 23 Feb 2007
    7.8
    High

    CVE-2006-7038

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service.

    Published: 23 Feb 2007