6.8
    Medium

    CVE-2007-6202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.

    Source:InATeam
    Published:1 Dec 2007
    5
    Medium

    CVE-2007-6198

    Last Modified: 10 Jan 2014

    portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.

    Source:Adrian Pastor
    Published:1 Dec 2007
    6.8
    Medium

    CVE-2007-6191

    Last Modified: 10 Jan 2014

    Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incphp/globals.php or (2) plugins/export/mc_table.php. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in p.mapper.

    Source:ShAy6oOoN
    Published:30 Nov 2007
    9.3
    Critical

    CVE-2007-6189

    Last Modified: 23 Apr 2026

    A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.

    Source:Nphinity
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6188

    Last Modified: 20 Oct 2016

    Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php.

    Source:GoLd_M
    Published:30 Nov 2007
    5
    Medium

    CVE-2007-6187

    Last Modified: 20 Oct 2016

    Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filepath parameter to (1) css_file.php, (2) js_file.php, or (3) xml_file.php in noah/modules/nosystem/templates/.

    Source:GoLd_M
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6185

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a download action, as demonstrated by a certain PHP file containing database credentials.

    Source:KiNgOfThEwOrLd
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6184

    Last Modified: 20 Oct 2016

    Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter.

    Source:tomplixsee
    Published:30 Nov 2007
    7.2
    High

    CVE-2007-6182

    Last Modified: 7 Jan 2014

    The responder program in ISPsystem ISPmanager (aka ISPmgr) 4.2.15.1 allows local users to gain privileges via shell metacharacters in command line arguments.

    Source:Andrew Christensen
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6179

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_library_path parameter to (1) markdown.php and (2) gallery.php in decoder/.

    Source:MhZ91
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6178

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.

    Source:MhZ91
    Published:30 Nov 2007
    7.5
    High

    CVE-2007-6177

    Last Modified: 25 Oct 2016

    PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the webappcfg[APPPATH] parameter.

    Source:GoLd_M
    Published:30 Nov 2007
    10
    Critical

    CVE-2007-6176

    Last Modified: 23 Apr 2026

    kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action.

    Source:Zero X
    Published:30 Nov 2007
    4.3
    Medium

    CVE-2007-6173

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress parameter in a Send New Password action, a different vector than CVE-2007-6055. NOTE: some of these details are obtained from third party information.

    Source:Joshua Morin
    Published:30 Nov 2007
    10
    Critical

    CVE-2007-6172

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.

    Source:Kacper
    Published:30 Nov 2007
    9.3
    Critical

    CVE-2007-6166

    Last Modified: 25 Oct 2016

    Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.

    Source:h07
    Published:29 Nov 2007
    9.3
    Critical

    CVE-2007-6165

    Last Modified: 27 Oct 2016

    Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.

    Source:Metasploit
    Published:29 Nov 2007
    7.5
    High

    CVE-2007-6164

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) reviews.php, (2) links.php and (3) articles.php.

    Source:KiNgOfThEwOrLd
    Published:29 Nov 2007
    7.5
    High

    CVE-2007-6163

    Last Modified: 10 Jan 2014

    SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information.

    Source:Aria-Security Team
    Published:29 Nov 2007
    4.3
    Medium

    CVE-2007-6162

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.

    Source:JosS
    Published:29 Nov 2007
    4.3
    Medium

    CVE-2007-6160

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a yeardetail action.

    Source:KiNgOfThEwOrLd
    Published:29 Nov 2007
    7.5
    High

    CVE-2007-6159

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.

    Source:KiNgOfThEwOrLd
    Published:29 Nov 2007
    7.5
    High

    CVE-2007-6158

    Last Modified: 24 Nov 2016

    Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname (aka Username) and (2) loginpass (aka Password) parameters to caladmin.php.

    Source:JosS
    Published:29 Nov 2007
    4.3
    Medium

    CVE-2007-6157

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Source:JosS
    Published:29 Nov 2007
    6.8
    Medium

    CVE-2007-6147

    Last Modified: 25 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/.

    Source:ShAy6oOoN
    Published:27 Nov 2007
    4.3
    Medium

    CVE-2007-6141

    Last Modified: 9 Jan 2014

    Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Crackers_Child
    Published:27 Nov 2007
    6.8
    Medium

    CVE-2007-6139

    Last Modified: 20 Oct 2016

    PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter.

    Source:Crackers_Child
    Published:27 Nov 2007
    7.5
    High

    CVE-2007-6138

    Last Modified: 9 Jan 2014

    SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.

    Source:Aria-Security Team
    Published:27 Nov 2007
    7.5
    High

    CVE-2007-6137

    Last Modified: 20 Oct 2016

    SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:S.W.A.T.
    Published:27 Nov 2007
    4.3
    Medium

    CVE-2007-6136

    Last Modified: 9 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details are obtained from third party information.

    Source:Doz
    Published:27 Nov 2007
    4.3
    Medium

    CVE-2007-6135

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file.

    Source:Jose Luis Gongora Fernandez
    Published:27 Nov 2007
    7.5
    High

    CVE-2007-6134

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a different vector than CVE-2006-1773.

    Source:Shadowleet
    Published:27 Nov 2007
    5.8
    Medium

    CVE-2007-6133

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the kfm_base_path parameter.

    Source:S.W.A.T.
    Published:27 Nov 2007
    5.8
    Medium

    CVE-2007-6129

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:Crackers_Child
    Published:26 Nov 2007
    7.5
    High

    CVE-2007-6128

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL commands via the idevent parameter.

    Source:ka0x
    Published:26 Nov 2007
    7.5
    High

    CVE-2007-6127

    Last Modified: 20 Oct 2016

    Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.

    Source:tomplixsee
    Published:26 Nov 2007
    4.3
    Medium

    CVE-2007-6126

    Last Modified: 20 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.

    Source:tomplixsee
    Published:26 Nov 2007
    7.5
    High

    CVE-2007-6125

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.

    Source:Khashayar Fereidani
    Published:26 Nov 2007
    4.3
    Medium

    CVE-2007-6124

    Last Modified: 6 Apr 2026

    Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

    Source:Khashayar Fereidani
    Published:26 Nov 2007
    4.3
    Medium

    CVE-2007-6113

    Last Modified: 19 Oct 2016

    Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.

    Source:Beyond Security
    Published:22 Nov 2007
    4.3
    Medium

    CVE-2007-6110

    Last Modified: 10 Jan 2014

    Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.

    Source:Michael Skibbe
    Published:25 Sept 2007
    7.5
    High

    CVE-2007-6106

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action.

    Source:K-159
    Published:23 Nov 2007
    6.8
    Medium

    CVE-2007-6105

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php.

    Source:NoGe
    Published:23 Nov 2007
    5
    Medium

    CVE-2007-6103

    Last Modified: 14 Jan 2014

    I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size field in its header, which is improperly handled by the Receiver::processPacket function; and (2) a denial of service (daemon crash) via an (a) IHU_INFO_INIT or a (b) IHU_INFO_RING packet that does not specify the mode, which is improperly handled by the Player::ring function in Player.cpp.

    Source:Luigi Auriemma
    Published:23 Nov 2007
    7.5
    High

    CVE-2007-6091

    Last Modified: 7 Jan 2014

    Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.

    Source:Aria-Security Team
    Published:22 Nov 2007
    9.3
    Critical

    CVE-2007-6089

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

    Source:ShAy6oOoN
    Published:22 Nov 2007
    9.3
    Critical

    CVE-2007-6088

    Last Modified: 20 Oct 2016

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:22 Nov 2007
    6.8
    Medium

    CVE-2007-6087

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module.

    Source:DevilAuron
    Published:22 Nov 2007
    9.3
    Critical

    CVE-2007-6086

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter.

    Source:DevilAuron
    Published:22 Nov 2007
    4.3
    Medium

    CVE-2007-6085

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module.

    Source:DevilAuron
    Published:22 Nov 2007