CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-0882

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

    Published: 12 Feb 2007
    9.3
    Critical

    CVE-2007-0770

    Last Modified: 23 Apr 2026

    Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.

    Published: 12 Feb 2007
    7.8
    High

    CVE-2007-0880

    Last Modified: 23 Apr 2026

    Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2007-0871

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.

    Published: 12 Feb 2007
    5
    Medium

    CVE-2007-0872

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2007-0876

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Quick Digital Image Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to inject arbitrary web script or HTML via the Qwd parameter to the top-level URI.

    Published: 12 Feb 2007
    5
    Medium

    CVE-2007-0877

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    6.8
    Medium

    CVE-2007-0874

    Last Modified: 23 Apr 2026

    Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.

    Published: 12 Feb 2007
    7.1
    High

    CVE-2006-7001

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in avatar.php in PhpMyChat Plus 1.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the L parameter, a different issue than CVE-2006-5897. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2006-7002

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_comment.php in Wheatblog (wB) 1.1 allows remote attackers to inject arbitrary web script or HTML via the Email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue may overlap CVE-2006-5195.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2007-0873

    Last Modified: 23 Apr 2026

    nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2007-0875

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL database

    Published: 12 Feb 2007
    5
    Medium

    CVE-2006-6998

    Last Modified: 23 Apr 2026

    install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2006-6999

    Last Modified: 23 Apr 2026

    attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.

    Published: 12 Feb 2007
    5
    Medium

    CVE-2006-7000

    Last Modified: 23 Apr 2026

    Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (2) includes/init.php, (3) certain files in includes/cron/, and (4) jpgraph.php, (5) jpgraph_bar.php, (6) jpgraph_pie.php, and (7) jpgraph_pie3d.php in includes/graph/, which leaks the path in error messages.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-6993

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in pages/addcomment2.php in Neuron Blog 1.1 allow remote attackers to inject arbitrary SQL commands via the (1) commentname, (2) commentmail, (3) commentwebsite, and (4) comment parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    6
    Medium

    CVE-2006-6995

    Last Modified: 23 Apr 2026

    mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter.

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2006-6996

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML and web script via the (1) title and (2) newspost parameters to (a) newsadd.php, and the (3) name, title, and (4) comment parameters to (b) news.php, a different set of vectors than CVE-2006-1818. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    10
    Critical

    CVE-2006-6997

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the same as CVE-2006-1792.

    Published: 12 Feb 2007
    6.4
    Medium

    CVE-2006-6994

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks.

    Published: 12 Feb 2007
    4.9
    Medium

    CVE-2007-0771

    Last Modified: 23 Apr 2026

    The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.

    Published: 12 Feb 2007
    7.6
    High

    CVE-2007-0870

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.

    Published: 11 Feb 2007
    4.3
    Medium

    CVE-2007-0869

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field. NOTE: this might be a duplicate of CVE-2007-0830.5. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Feb 2007
    7.5
    High

    CVE-2007-0867

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.

    Published: 9 Feb 2007
    5
    Medium

    CVE-2007-0868

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Feb 2007
    5
    Medium

    CVE-2006-6984

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in GreenBrowser 3.4.0622 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6986

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in PhaseOut 5.4.4 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6990

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Enigma Browser 3.8.8 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6991

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Fast Browser Pro 8.1 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6992

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.5
    High

    CVE-2007-0861

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG['_PKG_PATH_MDLS'] parameter. NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached

    Published: 9 Feb 2007
    6.8
    Medium

    CVE-2007-0862

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter. NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable

    Published: 9 Feb 2007
    7.5
    High

    CVE-2007-0864

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.

    Published: 9 Feb 2007
    5
    Medium

    CVE-2006-6985

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6988

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Slim Browser 4.07 build 100 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.5
    High

    CVE-2007-0860

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in local Calendar System 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) TEMPLATE_DIR parameter to (a) showinvoices.php, (b) showmonth.php, (c) showevents.php, (d) retrieveinvoice.php, (e) modifyitem.php, and (f) lookup_userid.php; or the LIBDIR parameter to (g) editevent.php, (h) resetpassword.php, (i) signup.php, showmonth.php, (j) showday.php, showevents.php, and lookup_userid.php. NOTE: this issue has been disputed by a third party, who states that the associated variables are set in config.php before use

    Published: 9 Feb 2007
    6.8
    Medium

    CVE-2007-0866

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6989

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in NetCaptor 4.5.7 Personal Edition allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    10
    Critical

    CVE-2007-0863

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php

    Published: 9 Feb 2007
    5
    Medium

    CVE-2006-6983

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in MYweb4net Browser 3.8.8.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.8
    High

    CVE-2006-6987

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in FineBrowser Freeware 3.2.2 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.

    Published: 9 Feb 2007
    7.5
    High

    CVE-2007-0865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.

    Published: 9 Feb 2007
    10
    Critical

    CVE-2007-0446

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.

    Published: 8 Feb 2007
    4.6
    Medium

    CVE-2007-0669

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files.

    Published: 8 Feb 2007
    5
    Medium

    CVE-2006-6981

    Last Modified: 23 Apr 2026

    3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blocked account) via unspecified vectors related to NTLM authentication, which causes a password hash to be overwritten.

    Published: 8 Feb 2007
    6.8
    Medium

    CVE-2007-0846

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.

    Published: 8 Feb 2007
    7.5
    High

    CVE-2007-0847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.

    Published: 8 Feb 2007
    7.5
    High

    CVE-2007-0848

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.

    Published: 8 Feb 2007
    7.2
    High

    CVE-2007-0849

    Last Modified: 23 Apr 2026

    scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

    Published: 8 Feb 2007
    7.5
    High

    CVE-2007-0850

    Last Modified: 23 Apr 2026

    scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

    Published: 8 Feb 2007