CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-0565

    Last Modified: 23 Apr 2026

    CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.

    Published: 30 Jan 2007
    4.3
    Medium

    CVE-2007-0562

    Last Modified: 23 Apr 2026

    Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.

    Published: 30 Jan 2007
    4.3
    Medium

    CVE-2007-0563

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0560

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0561

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.

    Published: 30 Jan 2007
    7.2
    High

    CVE-2007-0557

    Last Modified: 23 Apr 2026

    rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2007-0347

    Last Modified: 23 Apr 2026

    The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

    Published: 29 Jan 2007
    5
    Medium

    CVE-2007-0538

    Last Modified: 23 Apr 2026

    Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

    Published: 29 Jan 2007
    7.8
    High

    CVE-2007-0539

    Last Modified: 23 Apr 2026

    The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

    Published: 29 Jan 2007
    5
    Medium

    CVE-2007-0540

    Last Modified: 23 Apr 2026

    WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

    Published: 29 Jan 2007
    5
    Medium

    CVE-2007-0541

    Last Modified: 23 Apr 2026

    WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2007-0542

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 29 Jan 2007
    7.8
    High

    CVE-2007-0546

    Last Modified: 23 Apr 2026

    Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2007-0547

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Jan 2007
    5
    Medium

    CVE-2007-0548

    Last Modified: 23 Apr 2026

    KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2007-0549

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2007-0550

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter.

    Published: 29 Jan 2007
    7.5
    High

    CVE-2007-0551

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.

    Published: 29 Jan 2007
    7.8
    High

    CVE-2007-0545

    Last Modified: 23 Apr 2026

    Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb.

    Published: 29 Jan 2007
    6
    Medium

    CVE-2007-0544

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2007-0553

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604. NOTE: some of these details are obtained from third party information.

    Published: 29 Jan 2007
    7.5
    High

    CVE-2007-0554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2006-6965

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.

    Published: 29 Jan 2007
    9.4
    Critical

    CVE-2007-0543

    Last Modified: 23 Apr 2026

    ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb. NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2007-0552

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2006-6955

    Last Modified: 23 Apr 2026

    Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2006-6956

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

    Published: 29 Jan 2007
    4.3
    Medium

    CVE-2006-6954

    Last Modified: 23 Apr 2026

    Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2006-6960

    Last Modified: 23 Apr 2026

    The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2006-6961

    Last Modified: 23 Apr 2026

    WebRoot Spy Sweeper 4.5.9 and earlier does not detect malware based on file contents, which allows remote attackers to bypass malware detection by changing a file's name.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2006-6962

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047.

    Published: 29 Jan 2007
    7.5
    High

    CVE-2006-6963

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_lms] parameter to (1) class.module/class.definition.php and (2) modules/scorm/scorm_utils.php. NOTE: this issue may overlap CVE-2006-2577.

    Published: 29 Jan 2007
    4
    Medium

    CVE-2006-6964

    Last Modified: 23 Apr 2026

    MailEnable Professional before 1.78 provides a cleartext user password when an administrator edits the user's settings, which allows remote authenticated administrators to obtain sensitive information by viewing the HTML source.

    Published: 29 Jan 2007
    7.5
    High

    CVE-2006-6958

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter to (1) team_admin.php, (2) rss_admin.php, (3) manual_admin.php, and (4) forum_admin.php in includes/root_modules/, a different set of vectors than CVE-2006-3076.

    Published: 29 Jan 2007
    2.1
    Low

    CVE-2006-6953

    Last Modified: 23 Apr 2026

    The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.

    Published: 29 Jan 2007
    6.8
    Medium

    CVE-2006-6957

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.

    Published: 29 Jan 2007
    4.6
    Medium

    CVE-2006-6959

    Last Modified: 23 Apr 2026

    WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.

    Published: 29 Jan 2007
    5
    Medium

    CVE-2007-0463

    Last Modified: 23 Apr 2026

    Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.

    Published: 29 Jan 2007
    7.2
    High

    CVE-2007-0536

    Last Modified: 23 Apr 2026

    The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.

    Published: 27 Jan 2007
    10
    Critical

    CVE-2007-0462

    Last Modified: 23 Apr 2026

    The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0517

    Last Modified: 23 Apr 2026

    Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt.

    Published: 26 Jan 2007
    3.5
    Low

    CVE-2007-0519

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0520

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0518

    Last Modified: 23 Apr 2026

    Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.

    Published: 26 Jan 2007
    3.3
    Low

    CVE-2007-0523

    Last Modified: 23 Apr 2026

    The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

    Published: 26 Jan 2007
    2.9
    Low

    CVE-2007-0524

    Last Modified: 23 Apr 2026

    The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0525

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.

    Published: 26 Jan 2007
    4.3
    Medium

    CVE-2007-0526

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php.

    Published: 26 Jan 2007
    3.3
    Low

    CVE-2007-0522

    Last Modified: 23 Apr 2026

    The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0531

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.

    Published: 26 Jan 2007