CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-0365

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably a different vulnerability than CVE-2006-5830.

    Published: 19 Jan 2007
    4.3
    Medium

    CVE-2007-0364

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.

    Published: 19 Jan 2007
    6.8
    Medium

    CVE-2006-6942

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2006-6943

    Last Modified: 23 Apr 2026

    PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2006-6944

    Last Modified: 23 Apr 2026

    phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

    Published: 19 Jan 2007
    7.1
    High

    CVE-2006-5964

    Last Modified: 23 Apr 2026

    choShilA.bpl in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows local users, and user-assisted remote attackers to cause a denial of service (system crash) by right clicking on a file with a long filename.

    Published: 19 Jan 2007
    9.3
    Critical

    CVE-2007-0352

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.

    Published: 19 Jan 2007
    6.8
    Medium

    CVE-2007-0353

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2007-0354

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Jan 2007
    7.2
    High

    CVE-2007-0355

    Last Modified: 23 Apr 2026

    Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2007-0359

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2007-0360

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2007-0356

    Last Modified: 23 Apr 2026

    The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.

    Published: 19 Jan 2007
    6.8
    Medium

    CVE-2007-0363

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 19 Jan 2007
    4.3
    Medium

    CVE-2006-5963

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows user-assisted remote attackers to extract files to arbitrary pathnames via a ../ (dot dot slash) in a filename.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2007-0350

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346.

    Published: 19 Jan 2007
    6.2
    Medium

    CVE-2007-0351

    Last Modified: 23 Apr 2026

    Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2007-0357

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.

    Published: 19 Jan 2007
    7.8
    High

    CVE-2007-0358

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.

    Published: 19 Jan 2007
    7.5
    High

    CVE-2007-0361

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.

    Published: 19 Jan 2007
    6.8
    Medium

    CVE-2007-0362

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2006-6941

    Last Modified: 23 Apr 2026

    index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2007-0349

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.

    Published: 19 Jan 2007
    5
    Medium

    CVE-2007-0329

    Last Modified: 23 Apr 2026

    download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php. NOTE: this issue might be resultant from a directory traversal vulnerability.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0330

    Last Modified: 23 Apr 2026

    Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0331

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.

    Published: 18 Jan 2007
    4.4
    Medium

    CVE-2007-0336

    Last Modified: 23 Apr 2026

    Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0338

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter). NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0344

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0345

    Last Modified: 23 Apr 2026

    The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0346

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0341

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0332

    Last Modified: 23 Apr 2026

    (1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.

    Published: 18 Jan 2007
    7.2
    High

    CVE-2007-0333

    Last Modified: 23 Apr 2026

    Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0334

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0335

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0342

    Last Modified: 23 Apr 2026

    WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.

    Published: 18 Jan 2007
    5
    Medium

    CVE-2007-0343

    Last Modified: 23 Apr 2026

    OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.

    Published: 18 Jan 2007
    5
    Medium

    CVE-2006-6489

    Last Modified: 23 Apr 2026

    The SISCO OSI stack, as used in SISCO MMS-EASE, ICCP Toolkit for MMS-EASE, AX-S4 MMS and AX-S4 ICCP, and possibly other control system applications, allows remote attackers to cause a denial of service (application termination and restart) via malformed packets.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0337

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0340

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.

    Published: 18 Jan 2007
    Unknown

    CVE-2006-6491

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2006. Notes: none

    Published: 18 Jan 2007
    Unknown

    CVE-2006-6492

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2006. Notes: none

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0302

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.

    Published: 18 Jan 2007
    10
    Critical

    CVE-2007-0303

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to "Potential security bugs."

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0304

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0305

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Jan 2007
    7.8
    High

    CVE-2007-0312

    Last Modified: 23 Apr 2026

    wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.

    Published: 18 Jan 2007
    9
    Critical

    CVE-2007-0313

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.

    Published: 18 Jan 2007