4.3
    Medium

    CVE-2007-6545

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php.

    Source:DSecRG
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6544

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.

    Source:sh2kerr
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6543

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:EgiX
    Published:28 Dec 2007
    7.5
    High

    CVE-2007-6542

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.

    Source:KnocKout
    Published:27 Dec 2007
    6.8
    Medium

    CVE-2007-6539

    Last Modified: 14 Jan 2014

    PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file parameter.

    Source:JuMp-Er
    Published:27 Dec 2007
    7.5
    High

    CVE-2007-6538

    Last Modified: 14 Jan 2014

    SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published:27 Dec 2007
    6.8
    Medium

    CVE-2007-6537

    Last Modified: 14 Jan 2014

    Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbitrary code via a long filename in a gzipped archive, such as a (1) gz, (2) adz, (3) roz, or (4) hdz archive in a compressed floppy disk image.

    Source:Luigi Auriemma
    Published:27 Dec 2007
    7.5
    High

    CVE-2007-6533

    Last Modified: 15 Jan 2014

    Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message.

    Source:Luigi Auriemma
    Published:27 Dec 2007
    9.3
    Critical

    CVE-2007-6530

    Last Modified: 10 Mar 2011

    Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.

    Source:Metasploit
    Published:27 Dec 2007
    5
    Medium

    CVE-2007-6528

    Last Modified: 9 Mar 2018

    Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

    Source:Sha0
    Published:27 Dec 2007
    7.5
    High

    CVE-2007-6518

    Last Modified: 22 Dec 2016

    Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters.

    Source:ThE TiGeR
    Published:24 Dec 2007
    6.8
    Medium

    CVE-2007-6516

    Last Modified: 23 Apr 2026

    Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property.

    Source:shinnai
    Published:21 Dec 2007
    7.5
    High

    CVE-2007-6515

    Last Modified: 20 Jan 2011

    support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.

    Source:Spencer McIntyre
    Published:21 Dec 2007
    4.3
    Medium

    CVE-2007-6514

    Last Modified: 14 Jan 2014

    Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.

    Source:Maciej Piotr Falkiewicz
    Published:19 Dec 2007
    4.3
    Medium

    CVE-2007-6513

    Last Modified: 14 Jan 2014

    HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

    Source:Elazar Broad
    Published:21 Dec 2007
    6.8
    Medium

    CVE-2007-6510

    Last Modified: 14 Jan 2014

    Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown impact via a crafted file to the SkytPacker ripper.

    Source:Luigi Auriemma
    Published:21 Dec 2007
    7.8
    High

    CVE-2007-6509

    Last Modified: 14 Jan 2014

    Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp.

    Source:Chris Castaldo
    Published:21 Dec 2007
    7.5
    High

    CVE-2007-6508

    Last Modified: 7 Dec 2016

    Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter.

    Source:p4imi0
    Published:21 Dec 2007
    9.3
    Critical

    CVE-2007-6506

    Last Modified: 23 Apr 2026

    The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

    Source:porkythepig
    Published:20 Dec 2007
    5.5
    Medium

    CVE-2007-6504

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter.

    Source:BugReport.IR
    Published:20 Dec 2007
    5.5
    Medium

    CVE-2007-6503

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to hosting/AutoSignUpPlans.asp with the (a) save, (b) 30, and (c) d_30 parameters.

    Source:BugReport.IR
    Published:20 Dec 2007
    5.5
    Medium

    CVE-2007-6502

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects, which trigger a response with the setup directory pathname in the HTML source; and (3) might allow remote attackers to obtain sensitive information via a request for /admin/forum/, which reveals the path in an error message when a forum is not found.

    Source:BugReport.IR
    Published:20 Dec 2007
    5.5
    Medium

    CVE-2007-6501

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp.

    Source:BugReport.IR
    Published:20 Dec 2007
    4.9
    Medium

    CVE-2007-6500

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp.

    Source:BugReport.IR
    Published:20 Dec 2007
    5.5
    Medium

    CVE-2007-6499

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "host id (IIS) value."

    Source:BugReport.IR
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6498

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter to OpenApi/GatewayVariables.asp, and possibly (5) unspecified vectors to IIS/iibind.asp.

    Source:BugReport.IR
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6497

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219.

    Source:BugReport.IR
    Published:20 Dec 2007
    6.8
    Medium

    CVE-2007-6496

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654.

    Source:BugReport.IR
    Published:20 Dec 2007
    6.5
    Medium

    CVE-2007-6495

    Last Modified: 23 Apr 2026

    inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action to accounts/AccountActions.asp. NOTE: this can be leveraged for remote code execution by changing the permissions of \Forum\db, which is configured for execution of ASP scripts with administrative privileges, and then uploading a script to \Forum\db.

    Source:BugReport.IR
    Published:20 Dec 2007
    10
    Critical

    CVE-2007-6494

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.

    Source:BugReport.IR
    Published:20 Dec 2007
    10
    Critical

    CVE-2007-6493

    Last Modified: 14 Jan 2014

    The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to execute arbitrary code via a certain argument to the SetHandler method.

    Source:rgod
    Published:20 Dec 2007
    4.3
    Medium

    CVE-2007-6490

    Last Modified: 20 Oct 2016

    Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.

    Source:MhZ91
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6489

    Last Modified: 20 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.

    Source:MhZ91
    Published:20 Dec 2007
    6.8
    Medium

    CVE-2007-6488

    Last Modified: 20 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.

    Source:MhZ91
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6485

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.

    Source:Michael Brooks
    Published:20 Dec 2007
    5
    Medium

    CVE-2007-6483

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.

    Source:Corey Lebleu
    Published:20 Dec 2007
    4.9
    Medium

    CVE-2007-6479

    Last Modified: 25 Oct 2016

    Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

    Source:RoMaNcYxHaCkEr
    Published:20 Dec 2007
    6.8
    Medium

    CVE-2007-6478

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. NOTE: some of these details are obtained from third party information.

    Source:devcode
    Published:20 Dec 2007
    5
    Medium

    CVE-2007-6476

    Last Modified: 20 Oct 2016

    GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.

    Source:MhZ91
    Published:20 Dec 2007
    6.4
    Medium

    CVE-2007-6475

    Last Modified: 20 Oct 2016

    Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_sel parameter to (1) updater.php and (2) thumber.php.

    Source:MhZ91
    Published:20 Dec 2007
    4.3
    Medium

    CVE-2007-6474

    Last Modified: 20 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.

    Source:MhZ91
    Published:20 Dec 2007
    5.8
    Medium

    CVE-2007-6473

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command.

    Source:r4x
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6472

    Last Modified: 15 Dec 2016

    Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.

    Source:Koller
    Published:20 Dec 2007
    5.8
    Medium

    CVE-2007-6471

    Last Modified: 13 Jan 2014

    Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.

    Source:Michael Brooks
    Published:20 Dec 2007
    6.4
    Medium

    CVE-2007-6470

    Last Modified: 13 Jan 2014

    phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via PHPSESSID cookies.

    Source:Michael Brooks
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6467

    Last Modified: 13 Jan 2014

    SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.

    Source:Sw33t h4cK3r
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6466

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action. NOTE: it was later reported that MOG - Web Shop (MOG-WebShop), a product based on the same code, is also affected.

    Source:k1tk4t
    Published:20 Dec 2007
    6.8
    Medium

    CVE-2007-6464

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) client_page_open.php in global/templates/.

    Source:RoMaNcYxHaCkEr
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6462

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:20 Dec 2007
    6.8
    Medium

    CVE-2007-6459

    Last Modified: 20 Oct 2016

    Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460.

    Source:Michael Brooks
    Published:20 Dec 2007