7.5
    High

    CVE-2007-6458

    Last Modified: 20 Oct 2016

    SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php.

    Source:Michael Brooks
    Published:20 Dec 2007
    5
    Medium

    CVE-2007-6457

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host header.

    Source:rgod
    Published:20 Dec 2007
    4.3
    Medium

    CVE-2007-6455

    Last Modified: 14 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.

    Source:Beenu Arora
    Published:20 Dec 2007
    10
    Critical

    CVE-2007-6454

    Last Modified: 20 Jan 2014

    Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request.

    Source:Luigi Auriemma
    Published:20 Dec 2007
    10
    Critical

    CVE-2007-6453

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter.

    Source:rgod
    Published:20 Dec 2007
    7.5
    High

    CVE-2007-6414

    Last Modified: 23 Apr 2026

    admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. NOTE: this can be leveraged for arbitrary code execution through a request to admin/videolinks_view.php.

    Source:Liz0ziM
    Published:17 Dec 2007
    6.4
    Medium

    CVE-2007-6405

    Last Modified: 20 Oct 2016

    Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407.

    Source:Luigi Auriemma
    Published:17 Dec 2007
    5
    Medium

    CVE-2007-6404

    Last Modified: 20 Oct 2016

    Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI.

    Source:Luigi Auriemma
    Published:17 Dec 2007
    6.8
    Medium

    CVE-2007-6403

    Last Modified: 25 Oct 2016

    Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the time of the attack.

    Source:SYS 49152
    Published:17 Dec 2007
    9.3
    Critical

    CVE-2007-6402

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6401.

    Source:SYS 49152
    Published:17 Dec 2007
    9.3
    Critical

    CVE-2007-6401

    Last Modified: 20 Oct 2016

    Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402.

    Source:SYS 49152
    Published:17 Dec 2007
    5
    Medium

    CVE-2007-6400

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.

    Source:GoLd_M
    Published:17 Dec 2007
    6.5
    Medium

    CVE-2007-6399

    Last Modified: 23 Apr 2026

    index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.

    Source:KiNgOfThEwOrLd
    Published:17 Dec 2007
    5
    Medium

    CVE-2007-6398

    Last Modified: 23 Apr 2026

    Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie.

    Source:KiNgOfThEwOrLd
    Published:17 Dec 2007
    5
    Medium

    CVE-2007-6397

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action or (b) the username parameter in a viewprofile action.

    Source:KiNgOfThEwOrLd
    Published:17 Dec 2007
    7.5
    High

    CVE-2007-6396

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE: similar code injection might be possible in a user profile.

    Source:KiNgOfThEwOrLd
    Published:17 Dec 2007
    5
    Medium

    CVE-2007-6395

    Last Modified: 23 Apr 2026

    Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.

    Source:KiNgOfThEwOrLd
    Published:17 Dec 2007
    7.5
    High

    CVE-2007-6394

    Last Modified: 20 Oct 2016

    SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action.

    Source:S.W.A.T.
    Published:17 Dec 2007
    6.5
    Medium

    CVE-2007-6393

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode.

    Source:t0pP8uZz
    Published:17 Dec 2007
    7.5
    High

    CVE-2007-6392

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI.

    Source:t0pP8uZz
    Published:17 Dec 2007
    7.5
    High

    CVE-2007-6391

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:hadihadi
    Published:17 Dec 2007
    9.3
    Critical

    CVE-2007-6387

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6380

    Last Modified: 10 Jan 2014

    Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.php, (b) adresses/ratefile.php, (c) mydownloads/ratefile.php, (d) mysections/ratefile.php, and (e) myalbum/ratephoto.php in modules/; the (2) bid parameter to (f) modules/banners/click.php; and the (3) gid parameter to (g) modules/arcade/index.php in a show_stats and play_game action, related issues to CVE-2007-5104 and CVE-2007-6266.

    Source:Lostmon
    Published:15 Dec 2007
    5
    Medium

    CVE-2007-6379

    Last Modified: 27 Oct 2016

    BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.

    Source:Luigi Auriemma
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6378

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Luigi Auriemma
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6377

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string.

    Source:Jacopo Cervini
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6376

    Last Modified: 13 Jan 2014

    Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:d3v1l
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6375

    Last Modified: 13 Jan 2014

    Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.

    Source:Doz
    Published:15 Dec 2007
    4.3
    Medium

    CVE-2007-6374

    Last Modified: 13 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3) wiki/index.php or (4) forums/index.php. NOTE: the error parameter to users/login.php is covered by CVE-2006-3103.

    Source:Doz
    Published:15 Dec 2007
    5
    Medium

    CVE-2007-6369

    Last Modified: 20 Oct 2016

    Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) size or (2) path parameter.

    Source:GoLd_M
    Published:15 Dec 2007
    5
    Medium

    CVE-2007-6368

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.

    Source:p4imi0
    Published:15 Dec 2007
    4.3
    Medium

    CVE-2007-6367

    Last Modified: 8 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comment (commento) field, different vectors than CVE-2007-2357.

    Source:KiNgOfThEwOrLd
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6366

    Last Modified: 8 Nov 2016

    Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.

    Source:KiNgOfThEwOrLd
    Published:15 Dec 2007
    7.5
    High

    CVE-2007-6362

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

    Source:K-159
    Published:15 Dec 2007
    4.9
    Medium

    CVE-2007-6359

    Last Modified: 23 Apr 2026

    The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.

    Source:mu-b
    Published:15 Dec 2007
    6.8
    Medium

    CVE-2007-6347

    Last Modified: 25 Oct 2016

    PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third party information.

    Source:RoMaNcYxHaCkEr
    Published:13 Dec 2007
    6.8
    Medium

    CVE-2007-6344

    Last Modified: 20 Oct 2016

    Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

    Source:MhZ91
    Published:13 Dec 2007
    5
    Medium

    CVE-2007-6341

    Last Modified: 14 Jan 2014

    Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response.

    Source:beSTORM
    Published:28 Oct 2007
    7.5
    High

    CVE-2007-6335

    Last Modified: 8 Nov 2016

    Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.

    Source:Thomas Pollet
    Published:18 Dec 2007
    5.8
    Medium

    CVE-2007-6333

    Last Modified: 23 Apr 2026

    The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method.

    Source:porkythepig
    Published:13 Dec 2007
    9.3
    Critical

    CVE-2007-6332

    Last Modified: 23 Apr 2026

    The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method.

    Source:porkythepig
    Published:13 Dec 2007
    9.3
    Critical

    CVE-2007-6331

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

    Source:porkythepig
    Published:13 Dec 2007
    7.5
    High

    CVE-2007-6327

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method.

    Source:shinnai
    Published:13 Dec 2007
    5
    Medium

    CVE-2007-6326

    Last Modified: 20 Oct 2016

    Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI.

    Source:shinnai
    Published:13 Dec 2007
    6.8
    Medium

    CVE-2007-6325

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fsBase] parameter, a different vector than CVE-2006-2726.

    Source:RoMaNcYxHaCkEr
    Published:13 Dec 2007
    6.8
    Medium

    CVE-2007-6324

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:RoMaNcYxHaCkEr
    Published:13 Dec 2007
    5
    Medium

    CVE-2007-6323

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) get_image.php or (2) get_file.php in mms_template/.

    Source:GoLd_M
    Published:13 Dec 2007
    5
    Medium

    CVE-2007-6322

    Last Modified: 20 Oct 2016

    Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:GoLd_M
    Published:13 Dec 2007
    4.3
    Medium

    CVE-2007-6321

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.

    Source:Tomas Kuliavas
    Published:9 Dec 2007
    6.8
    Medium

    CVE-2007-6318

    Last Modified: 20 Oct 2016

    SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.

    Source:Abel Cheung
    Published:10 Dec 2007