CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-0227

    Last Modified: 23 Apr 2026

    slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files. NOTE: another researcher reports that the issue is not present in slocate 2.7.

    Published: 13 Jan 2007
    7.2
    High

    CVE-2007-0229

    Last Modified: 23 Apr 2026

    Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.

    Published: 13 Jan 2007
    7.5
    High

    CVE-2007-0232

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.

    Published: 13 Jan 2007
    7.5
    High

    CVE-2006-6927

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Rialto 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the uname (username) and (2) pword (passwd) fields in (a) admin/default.asp; the (3) ID parameter to (b) listfull.asp or (c) printmain.asp; the (4) cat parameter to (d) listmain.asp, (e) searchoption.asp, or (f) searchmain.asp; the (5) Keyword parameter to (g) searchkey.asp; the (6) area parameter to searchmain.asp or searchoption.asp; the (7) searchin parameter to searchkey.asp; or the (8) cost1, (9) cost2, (10) acreage1, or (11) squarefeet1 parameters to searchoption.asp. NOTE: some of these details are obtained from third party information.

    Published: 13 Jan 2007
    6.8
    Medium

    CVE-2006-6929

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Rapid Classified 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) reply.asp or (b) view_print.asp, the (2) SH1 parameter to (c) search.asp, the (3) name parameter to reply.asp, or the (4) dosearch parameter to (d) advsearch.asp.

    Published: 13 Jan 2007
    5
    Medium

    CVE-2007-0228

    Last Modified: 23 Apr 2026

    The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP port 10618, which triggers a NULL pointer dereference.

    Published: 13 Jan 2007
    7.5
    High

    CVE-2007-0230

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter. NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use

    Published: 13 Jan 2007
    5
    Medium

    CVE-2007-0247

    Last Modified: 23 Apr 2026

    squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

    Published: 13 Jan 2007
    5
    Medium

    CVE-2007-0206

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 12 Jan 2007
    10
    Critical

    CVE-2006-6918

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Admin login for Georgian discussion board (GeoBB) before 1.0 has unknown impact and attack vectors.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2006-6919

    Last Modified: 23 Apr 2026

    Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2006-6920

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0168

    Last Modified: 23 Apr 2026

    The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0169

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.

    Published: 11 Jan 2007
    6.6
    Medium

    CVE-2007-0166

    Last Modified: 23 Apr 2026

    The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.

    Published: 11 Jan 2007
    5
    Medium

    CVE-2007-0199

    Last Modified: 23 Apr 2026

    The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."

    Published: 11 Jan 2007
    10
    Critical

    CVE-2007-0201

    Last Modified: 23 Apr 2026

    Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0197

    Last Modified: 23 Apr 2026

    Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0196

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information.

    Published: 11 Jan 2007
    10
    Critical

    CVE-2007-0203

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.

    Published: 11 Jan 2007
    5
    Medium

    CVE-2007-0198

    Last Modified: 23 Apr 2026

    The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0204

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0200

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.

    Published: 11 Jan 2007
    5
    Medium

    CVE-2007-0195

    Last Modified: 23 Apr 2026

    my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0192

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0184

    Last Modified: 23 Apr 2026

    Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.

    Published: 11 Jan 2007
    5
    Medium

    CVE-2007-0185

    Last Modified: 23 Apr 2026

    Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0190

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0193

    Last Modified: 23 Apr 2026

    FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.

    Published: 11 Jan 2007
    7.8
    High

    CVE-2007-0194

    Last Modified: 23 Apr 2026

    admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0191

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0181

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0182

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/. NOTE: the include/common_function.php vector is already covered by another candidate from the same date.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0183

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0186

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an <FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php. NOTE: it is possible that this candidate overlaps CVE-2006-3550.

    Published: 11 Jan 2007
    6.5
    Medium

    CVE-2007-0188

    Last Modified: 23 Apr 2026

    F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0189

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0187

    Last Modified: 23 Apr 2026

    F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0172

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0173

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0178

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0179

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.

    Published: 11 Jan 2007
    4.3
    Medium

    CVE-2007-0175

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0170

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0171

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.

    Published: 11 Jan 2007
    7.5
    High

    CVE-2007-0174

    Last Modified: 23 Apr 2026

    Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.

    Published: 11 Jan 2007
    6.8
    Medium

    CVE-2007-0176

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

    Published: 11 Jan 2007
    5.1
    Medium

    CVE-2007-0177

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Jan 2007