7.5
    High

    CVE-2007-6084

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:22 Nov 2007
    7.5
    High

    CVE-2007-6083

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Source:Gu1ll4um3r0m41n
    Published:22 Nov 2007
    9.3
    Critical

    CVE-2007-6082

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

    Source:Liz0ziM
    Published:22 Nov 2007
    7.5
    High

    CVE-2007-6080

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

    Source:BugReport.IR
    Published:21 Nov 2007
    6.8
    Medium

    CVE-2007-6079

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file.

    Source:BugReport.IR
    Published:21 Nov 2007
    7.5
    High

    CVE-2007-6078

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.asp, possibly involving a parameter passed from cp_main.asp; (3) inc_profile_functions.asp; or (4) inc_SUBSCRIPTIONS.asp; or the (5) Avatar_URL, (6) LINK1, or (7) LINK2 parameter to cp_main.asp in an EditIt action.

    Source:BugReport.IR
    Published:21 Nov 2007
    7.5
    High

    CVE-2007-6058

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.

    Source:K-159
    Published:20 Nov 2007
    6.8
    Medium

    CVE-2007-6057

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.

    Source:VerY-SecReT
    Published:20 Nov 2007
    5
    Medium

    CVE-2007-6056

    Last Modified: 7 Jan 2014

    frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task details via modified values to the (1) Mehr and (2) SUPER parameters.

    Source:MC Iglo
    Published:20 Nov 2007
    4.3
    Medium

    CVE-2007-6055

    Last Modified: 7 Jan 2014

    Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.

    Source:Adrian Pastor
    Published:20 Nov 2007
    4.3
    Medium

    CVE-2007-6054

    Last Modified: 7 Jan 2014

    Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI, related to the url variable.

    Source:Jan Fry
    Published:20 Nov 2007
    7.5
    High

    CVE-2007-6041

    Last Modified: 14 Jan 2014

    Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code by sending a nickname, then a vehicle name in a MSG2_USE_VEHICLE message, in which the combined length triggers the overflow.

    Source:Luigi Auriemma
    Published:20 Nov 2007
    2.1
    Low

    CVE-2007-6039

    Last Modified: 6 Jan 2014

    PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

    Source:laurent gaffie
    Published:20 Nov 2007
    6.8
    Medium

    CVE-2007-6038

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:NoGe
    Published:20 Nov 2007
    4.3
    Medium

    CVE-2007-6037

    Last Modified: 7 Jan 2014

    Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters.

    Source:nnposter
    Published:20 Nov 2007
    7.1
    High

    CVE-2007-6036

    Last Modified: 14 Jan 2014

    The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, which causes a negative number to be used during memory allocation.

    Source:Luigi Auriemma
    Published:20 Nov 2007
    7.5
    High

    CVE-2007-6032

    Last Modified: 5 Jan 2014

    SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

    Source:joseph.giron13
    Published:20 Nov 2007
    6.8
    Medium

    CVE-2007-6028

    Last Modified: 7 Jan 2014

    Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values.

    Source:Elazar Broad
    Published:20 Nov 2007
    6.8
    Medium

    CVE-2007-6027

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Crackers_Child
    Published:20 Nov 2007
    9.3
    Critical

    CVE-2007-6026

    Last Modified: 14 Jul 2017

    Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

    Source:cocoruder
    Published:20 Nov 2007
    9.3
    Critical

    CVE-2007-6019

    Last Modified: 17 Feb 2014

    Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

    Source:Javier Vicente Vallejo
    Published:8 Apr 2008
    9.3
    Critical

    CVE-2007-6016

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.

    Source:Elazar
    Published:29 Feb 2008
    9.3
    Critical

    CVE-2007-6015

    Last Modified: 1 Dec 2016

    Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.

    Source:x86
    Published:10 Dec 2007
    4.3
    Medium

    CVE-2007-6005

    Last Modified: 6 Jan 2014

    Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method.

    Source:Elazar Broad
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-6004

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an artikel action or (2) the katid parameter in a produk action.

    Source:k1tk4t
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-6003

    Last Modified: 13 Jan 2014

    Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Remco Verhoef
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-6001

    Last Modified: 9 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910.

    Source:Tim Brown
    Published:15 Nov 2007
    5
    Medium

    CVE-2007-6000

    Last Modified: 7 Jan 2014

    KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.

    Source:laurent gaffie
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5999

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:15 Nov 2007
    6.5
    Medium

    CVE-2007-5998

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

    Source:Khashayar Fereidani
    Published:15 Nov 2007
    6.5
    Medium

    CVE-2007-5997

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5996

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.

    Source:Khashayar Fereidani
    Published:15 Nov 2007
    6.8
    Medium

    CVE-2007-5995

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the example parameter.

    Source:p4sswd
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-5993

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.

    Source:Jesus Olmos Gonzalez
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5992

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.

    Source:t0pP8uZz
    Published:15 Nov 2007
    7.8
    High

    CVE-2007-5984

    Last Modified: 6 Jan 2014

    classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation."

    Source:L4teral
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-5983

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Source:L4teral
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-5982

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to help/index.php, or the (3) INSTALL_X7CHATVERSION parameter to upgradev1.php.

    Source:ShAy6oOoN
    Published:15 Nov 2007
    4.3
    Medium

    CVE-2007-5979

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.

    Source:Jan Fry
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5978

    Last Modified: 6 Jan 2014

    SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5974

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.

    Source:Kacper
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-5973

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Source:Alexsize
    Published:15 Nov 2007
    7.1
    High

    CVE-2007-5962

    Last Modified: 7 Dec 2016

    Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.

    Source:Praveen Darshanam
    Published:21 May 2008
    5
    Medium

    CVE-2007-5958

    Last Modified: 23 Apr 2026

    X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.

    Source:vl4dZ
    Published:17 Jan 2008
    6.1
    Medium

    CVE-2007-5954

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Jose Luis Gongora Fernandez
    Published:14 Nov 2007
    4.3
    Medium

    CVE-2007-5952

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in admin/index.php in Helios Calendar 1.2.1 Beta allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Sanchez
    Published:14 Nov 2007
    7.5
    High

    CVE-2007-5951

    Last Modified: 6 Jan 2014

    SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r00t
    Published:14 Nov 2007
    4.3
    Medium

    CVE-2007-5944

    Last Modified: 7 Jan 2014

    Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.

    Source:anonymous
    Published:14 Nov 2007
    10
    Critical

    CVE-2007-5941

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method.

    Source:Elazar
    Published:14 Nov 2007
    9
    Critical

    CVE-2007-5926

    Last Modified: 6 Jan 2014

    OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures.

    Source:Kevin Finisterre
    Published:10 Nov 2007