6.8
    Medium

    CVE-2007-5412

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php.

    Source:NoGe
    Published:12 Oct 2007
    4.3
    Medium

    CVE-2007-5411

    Last Modified: 2 Jan 2014

    Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.

    Source:Radu State
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5410

    Last Modified: 2 Jan 2014

    PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Cyber-Crime
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5409

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the nuseo_dir parameter.

    Source:BiNgZa
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5408

    Last Modified: 10 Oct 2017

    SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:ka0x
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5407

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and (4) register.php, in view/; and (5) list.sub.html.php, (6) list.user.sub.html.php, and (7) reports.html.php in views/.

    Source:NoGe
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5390

    Last Modified: 20 Oct 2016

    PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter.

    Source:0in
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5388

    Last Modified: 20 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php.

    Source:S.W.A.T.
    Published:12 Oct 2007
    6.8
    Medium

    CVE-2007-5387

    Last Modified: 20 Oct 2016

    PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter.

    Source:S.W.A.T.
    Published:12 Oct 2007
    4.3
    Medium

    CVE-2007-5386

    Last Modified: 2 Jan 2014

    Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Omer Singer
    Published:12 Oct 2007
    9.3
    Critical

    CVE-2007-5381

    Last Modified: 10 Oct 2017

    Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.

    Source:Andy Davis
    Published:12 Oct 2007
    6.5
    Medium

    CVE-2007-5374

    Last Modified: 23 Apr 2026

    cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.

    Source:BlackHawk
    Published:11 Oct 2007
    4.3
    Medium

    CVE-2007-5370

    Last Modified: 2 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.

    Source:Doz
    Published:11 Oct 2007
    7.2
    High

    CVE-2007-5365

    Last Modified: 14 Jul 2017

    Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

    Source:RoMaNSoFt
    Published:8 Oct 2007
    6.8
    Medium

    CVE-2007-5363

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:NoGe
    Published:11 Oct 2007
    6.8
    Medium

    CVE-2007-5362

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.

    Source:k1n9k0ng
    Published:11 Oct 2007
    9.3
    Critical

    CVE-2007-5348

    Last Modified: 24 Nov 2017

    Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."

    Source:John Smith
    Published:10 Sept 2008
    5
    Medium

    CVE-2007-5333

    Last Modified: 22 Jan 2014

    Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

    Source:John Kew
    Published:11 Feb 2008
    10
    Critical

    CVE-2007-5332

    Last Modified: 5 Dec 2013

    Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption.

    Source:M. Shirk
    Published:13 Oct 2007
    7.5
    High

    CVE-2007-5322

    Last Modified: 12 Oct 2016

    Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.

    Source:shinnai
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5321

    Last Modified: 12 Oct 2016

    Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.

    Source:TEAMELITE
    Published:9 Oct 2007
    4
    Medium

    CVE-2007-5320

    Last Modified: 12 Oct 2016

    Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).

    Source:shinnai
    Published:9 Oct 2007
    5
    Medium

    CVE-2007-5316

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Khashayar Fereidani
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5315

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the livealbum_dir parameter.

    Source:S.W.A.T.
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5314

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter.

    Source:h4ck3r
    Published:9 Oct 2007
    7.5
    High

    CVE-2007-5313

    Last Modified: 6 Oct 2017

    PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:Mogatil
    Published:9 Oct 2007
    4.3
    Medium

    CVE-2007-5312

    Last Modified: 26 Dec 2016

    Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat parameter to browse.php.

    Source:HACKERS PAL
    Published:9 Oct 2007
    7.5
    High

    CVE-2007-5311

    Last Modified: 26 Dec 2016

    Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter.

    Source:HACKERS PAL
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5310

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:NoGe
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5309

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Mehmet Ince
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5308

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Source:[PHCN] Mahjong
    Published:9 Oct 2007
    7.5
    High

    CVE-2007-5307

    Last Modified: 6 Oct 2017

    ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in ELSEIF CMS.

    Source:HACKERS PAL
    Published:9 Oct 2007
    5
    Medium

    CVE-2007-5306

    Last Modified: 6 Oct 2017

    ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utilisateurs/votesresultats.php.

    Source:HACKERS PAL
    Published:9 Oct 2007
    7.5
    High

    CVE-2007-5305

    Last Modified: 6 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and (f) coeurusr.php in utilisateurs/, and (g) articles/fonctions.php and (h) depot/fonctions.php in moduleajouter/; the (3) corpsdesign parameter to (i) articles/usrarticles.php and (j) depot/usrdepot.php in moduleajouter/; and possibly other files.

    Source:HACKERS PAL
    Published:9 Oct 2007
    4.3
    Medium

    CVE-2007-5304

    Last Modified: 6 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3) elseifforumtxtmenugeneraleduforum parameter to moduleajouter/depot/adminforum.php.

    Source:HACKERS PAL
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5301

    Last Modified: 3 Jan 2014

    Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

    Source:Erik
    Published:9 Oct 2007
    5
    Medium

    CVE-2007-5300

    Last Modified: 7 Oct 2017

    Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Source:k1tk4t
    Published:9 Oct 2007
    5
    Medium

    CVE-2007-5299

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. (dot dot) in the view_mode parameter to (1) featured_list.php and (2) online_list.php in member/.

    Source:SnIpEr_SA
    Published:9 Oct 2007
    6.4
    Medium

    CVE-2007-5298

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[document_uri] parameter to (1) _administration/securite.php and (2) _administration/gestion_configurations/save_config.php.

    Source:HACKERS PAL
    Published:9 Oct 2007
    6.8
    Medium

    CVE-2007-5294

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter.

    Source:HACKERS PAL
    Published:9 Oct 2007
    2.6
    Low

    CVE-2007-5293

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php.

    Source:HACKERS PAL
    Published:9 Oct 2007
    4.3
    Medium

    CVE-2007-5290

    Last Modified: 5 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to login.php and the (2) mode2 parameter to default.asp in an advanced_login mode.

    Source:Ivan Sanchez
    Published:9 Oct 2007
    4.3
    Medium

    CVE-2007-5278

    Last Modified: 30 Nov 2016

    Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.

    Source:InATeam
    Published:8 Oct 2007
    7.5
    High

    CVE-2007-5272

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action.

    Source:CyberGhost
    Published:8 Oct 2007
    6.8
    Medium

    CVE-2007-5271

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2) interface/editors/custom.php.

    Source:GoLd_M
    Published:8 Oct 2007
    7.5
    High

    CVE-2007-5265

    Last Modified: 2 Jan 2014

    Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) password fields when accessing certain "restricted zones", which are not properly handled by the (a) processWebHeader and (b) filterWebRequest functions.

    Source:Luigi Auriemma
    Published:8 Oct 2007
    5
    Medium

    CVE-2007-5264

    Last Modified: 3 Jan 2014

    Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information.

    Source:Luigi Auriemma
    Published:8 Oct 2007
    6.4
    Medium

    CVE-2007-5261

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.

    Source:k1tk4t
    Published:6 Oct 2007
    10
    Critical

    CVE-2007-5257

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.

    Source:shinnai
    Published:6 Oct 2007
    7.5
    High

    CVE-2007-5256

    Last Modified: 2 Jan 2014

    Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary code via a long HELP command on TCP port 3010 to the sysuser::exechelp function in sysuser.cc and (2) remote authenticated users to execute arbitrary code via long commands on TCP port 6809 to the servinterface::sendmulticast function in servinterface.cc, as demonstrated by a PIcallsign command.

    Source:Luigi Auriemma
    Published:6 Oct 2007