6.8
    Medium

    CVE-2007-6624

    Last Modified: 12 Jan 2017

    Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.

    Source:irk4z
    Published:4 Jan 2008
    5
    Medium

    CVE-2007-6623

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter.

    Source:EgiX
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6622

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

    Source:EgiX
    Published:4 Jan 2008
    6.4
    Medium

    CVE-2007-6621

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter.

    Source:EcHoLL
    Published:4 Jan 2008
    6.4
    Medium

    CVE-2007-6620

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter.

    Source:EcHoLL
    Published:4 Jan 2008
    6.8
    Medium

    CVE-2007-6615

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the selected_provider parameter.

    Source:MhZ91
    Published:3 Jan 2008
    6.8
    Medium

    CVE-2007-6614

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter, a related issue to CVE-2007-6542.

    Source:MhZ91
    Published:3 Jan 2008
    5
    Medium

    CVE-2007-6613

    Last Modified: 17 Jan 2014

    Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a long joilet file name.

    Source:Devon Miller
    Published:30 Dec 2007
    5
    Medium

    CVE-2007-6609

    Last Modified: 6 Jan 2017

    Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

    Source:Luigi Auriemma
    Published:31 Dec 2007
    4.3
    Medium

    CVE-2007-6608

    Last Modified: 15 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIRST parameters to admin/staff_del_confirm.php, (3) the name parameter to admin/theme_del_confirm.php, or (4) the themeName parameter to admin/theme_preview.php.

    Source:Juan Galiana Lara
    Published:31 Dec 2007
    5.8
    Medium

    CVE-2007-6605

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four arguments to the Start method.

    Source:shinnai
    Published:31 Dec 2007
    5
    Medium

    CVE-2007-6604

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or by executing embedded PHP code in images under uploads/avatar/.

    Source:nexen
    Published:31 Dec 2007
    5
    Medium

    CVE-2007-6603

    Last Modified: 23 Apr 2026

    Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

    Source:RoMaNcYxHaCkEr
    Published:31 Dec 2007
    7.5
    High

    CVE-2007-6602

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.

    Source:Felix Groebert
    Published:31 Dec 2007
    4.3
    Medium

    CVE-2007-6597

    Last Modified: 15 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and (3) the Date parameter to blogs.asp.

    Source:Doz
    Published:31 Dec 2007
    8.8
    High

    CVE-2007-6593

    Last Modified: 10 Jan 2014

    Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.

    Source:Sebastian
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6587

    Last Modified: 19 Jun 2015

    SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Eyup CELIK
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6586

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.

    Source:x0kster
    Published:28 Dec 2007
    6.8
    Medium

    CVE-2007-6585

    Last Modified: 8 Nov 2016

    PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.

    Source:CraCkEr
    Published:28 Dec 2007
    6.4
    Medium

    CVE-2007-6584

    Last Modified: 21 Nov 2016

    Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.

    Source:irk4z
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6583

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip parameter.

    Source:irk4z
    Published:28 Dec 2007
    6.4
    Medium

    CVE-2007-6582

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.

    Source:irk4z
    Published:28 Dec 2007
    6.4
    Medium

    CVE-2007-6581

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/.

    Source:MhZ91
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6580

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.

    Source:Koller
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6579

    Last Modified: 29 Dec 2016

    Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4.

    Source:MhZ91
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6578

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DNX
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6577

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.

    Source:Houssamix
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6576

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Adult Script 1.6.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) videolink_count.php or (2) links.php.

    Source:MhZ91
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6575

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.

    Source:x0kster
    Published:28 Dec 2007
    4.3
    Medium

    CVE-2007-6574

    Last Modified: 14 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.

    Source:Doz
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6568

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

    Source:Kw3[R]Ln
    Published:28 Dec 2007
    6.4
    Medium

    CVE-2007-6567

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.

    Source:Kw3[R]Ln
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

    Source:Kw3[R]Ln
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6565

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component.

    Source:JosS
    Published:28 Dec 2007
    4.3
    Medium

    CVE-2007-6564

    Last Modified: 15 Jan 2014

    Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter.

    Source:Omer Singer
    Published:28 Dec 2007
    5.7
    Medium

    CVE-2007-6561

    Last Modified: 15 Jan 2014

    Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF_load_image function that results in an overflow in the pdc_fsearch_fopen function, and possibly other vectors.

    Source:poplix
    Published:28 Dec 2007
    4.3
    Medium

    CVE-2007-6560

    Last Modified: 15 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.

    Source:malibu.r
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6559

    Last Modified: 15 Jan 2014

    Multiple SQL injection vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to execute arbitrary SQL commands via (1) the from parameter to index.php or (2) the page parameter to update.php.

    Source:malibu.r
    Published:28 Dec 2007
    4.3
    Medium

    CVE-2007-6558

    Last Modified: 20 Jan 2014

    TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288.

    Source:David G.M.
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6557

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.

    Source:MhZ91
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6556

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to default.asp in a news page action or (2) the pageid parameter to default.asp.

    Source:bypass
    Published:28 Dec 2007
    9.3
    Critical

    CVE-2007-6555

    Last Modified: 8 Nov 2016

    PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

    Source:ShockShadow
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6554

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) register.php, (3) login.php, or (4) statistics.php.

    Source:GoLd_M
    Published:28 Dec 2007
    6.8
    Medium

    CVE-2007-6553

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845.

    Source:GoLd_M
    Published:28 Dec 2007
    6
    Medium

    CVE-2007-6552

    Last Modified: 26 Oct 2016

    Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

    Source:k1tk4t
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6551

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:MhZ91
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6550

    Last Modified: 23 Apr 2026

    form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.

    Source:EgiX
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6548

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (3) the disclaimer parameter to modules/system/admin.php in a disclaimer action, (4) the disclaimer parameter to modules/mydownloads/admin/index.php in a mydownloadsConfigAdmin action, (5) the disclaimer parameter to modules/newbb_plus/admin/forum_config.php, (6) the disclaimer parameter to modules/mylinks/admin/index.php in a myLinksConfigAdmin action, or (7) the intro parameter to modules/sections/admin/index.php in a secconfig action, which inject PHP sequences into (a) sections/cache/intro.php, (b) mylinks/cache/disclaimer.php, (c) mydownloads/cache/disclaimer.php, (d) newbb_plus/cache/disclaimer.php, (e) system/cache/disclaimer.php, (f) system/cache/footer.php, (g) system/cache/header.php, or (h) system/cache/maintenance.php in modules/.

    Source:DSecRG
    Published:28 Dec 2007
    6.8
    Medium

    CVE-2007-6547

    Last Modified: 23 Apr 2026

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

    Source:DSecRG
    Published:28 Dec 2007
    6.4
    Medium

    CVE-2007-6546

    Last Modified: 23 Apr 2026

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

    Source:DSecRG
    Published:28 Dec 2007