7.5
    High

    CVE-2007-5110

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:26 Sept 2007
    10
    Critical

    CVE-2007-5108

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in IAC Search & Media ask.com toolbar has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. NOTE: this might be the same issue as CVE-2007-5107.

    Source:Joey Mengele
    Published:26 Sept 2007
    9.3
    Critical

    CVE-2007-5107

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. NOTE: some of these details are obtained from third party information. NOTE: the researcher claims that this is the same as CVE-2007-5108, but there is insufficient detail for CVE-2007-5108 to be certain.

    Source:Metasploit
    Published:26 Sept 2007
    4.3
    Medium

    CVE-2007-5105

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.

    Source:Adrian Pastor
    Published:26 Sept 2007
    6.8
    Medium

    CVE-2007-5102

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _path parameter.

    Source:ShockShadow
    Published:26 Sept 2007
    7.5
    High

    CVE-2007-5099

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:GoLd_M
    Published:26 Sept 2007
    6.8
    Medium

    CVE-2007-5098

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the set_depth parameter to (1) app.lib/product.control/core.php/product.control.config.php, or (2) customer.browse.list.php or (3) customer.browse.search.php in app.lib/product.control/core.php/customer.area/.

    Source:BiNgZa
    Published:26 Sept 2007
    7.5
    High

    CVE-2007-5094

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in the header, and a long Content-Transfer-Encoding header line.

    Source:axis
    Published:26 Sept 2007
    6.8
    Medium

    CVE-2007-5092

    Last Modified: 31 Dec 2013

    Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php.

    Source:waraxe
    Published:26 Sept 2007
    7.5
    High

    CVE-2007-5089

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SKIN_URL parameter.

    Source:w0cker
    Published:26 Sept 2007
    10
    Critical

    CVE-2007-5082

    Last Modified: 20 Oct 2016

    Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to missing validation of a length parameter.

    Source:Nice Name Crew
    Published:1 Oct 2007
    10
    Critical

    CVE-2007-5070

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows remote attackers to execute arbitrary code via a long string in the first argument to the SetFont method.

    Source:rgod
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5069

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter.

    Source:h4ck3r
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5068

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL commands via the mod parameter.

    Source:IHTeam
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5067

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe.

    Source:h07
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5065

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:ShockShadow
    Published:24 Sept 2007
    6.8
    Medium

    CVE-2007-5064

    Last Modified: 31 Dec 2013

    Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remote attackers to execute arbitrary code via a long first argument to the DownURL2 method. NOTE: some of these details are obtained from third party information.

    Source:7jdg
    Published:24 Sept 2007
    5
    Medium

    CVE-2007-5063

    Last Modified: 12 Oct 2016

    Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt.

    Source:undefined1_
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5062

    Last Modified: 12 Oct 2016

    account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action.

    Source:undefined1_
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5061

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action.

    Source:IHTeam
    Published:24 Sept 2007
    4.3
    Medium

    CVE-2007-5060

    Last Modified: 31 Dec 2013

    Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.

    Source:x0kster
    Published:24 Sept 2007
    6.8
    Medium

    CVE-2007-5056

    Last Modified: 12 Oct 2016

    Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.

    Source:irk4z
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5055

    Last Modified: 20 Dec 2016

    Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php.

    Source:irk4z
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5054

    Last Modified: 20 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4) links/showlinks.php, or (5) links/submit_links.php in modules/.

    Source:irk4z
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5053

    Last Modified: 20 Dec 2016

    Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php; or a URL in the language_home parameter to (3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, or (7) links/submit_links.php in modules/; related to missing checks in (a) modules/moduleSec.php and (b) include/includeSec.php for inclusion of certain URLs, as demonstrated by an ftps:// URL.

    Source:irk4z
    Published:24 Sept 2007
    4.3
    Medium

    CVE-2007-5052

    Last Modified: 31 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module with (1) the title parameter or (2) a "title=" sequence in the PATH_INFO, or a request to the download module with (3) the cat parameter or (4) a "cat=" sequence in the PATH_INFO.

    Source:x0kster
    Published:24 Sept 2007
    7.5
    High

    CVE-2007-5050

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.

    Source:Dj7xpl
    Published:24 Sept 2007
    5
    Medium

    CVE-2007-5036

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."

    Source:Alex Hernandez
    Published:24 Sept 2007
    4.3
    Medium

    CVE-2007-5027

    Last Modified: 30 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.

    Source:azizov
    Published:21 Sept 2007
    5
    Medium

    CVE-2007-5026

    Last Modified: 23 Apr 2026

    dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.

    Source:AnTi SeCuRe
    Published:21 Sept 2007
    10
    Critical

    CVE-2007-5019

    Last Modified: 19 Oct 2016

    Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.

    Source:YAG KOHHA
    Published:20 Sept 2007
    6
    Medium

    CVE-2007-5018

    Last Modified: 19 Oct 2016

    Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

    Source:void
    Published:20 Sept 2007
    5
    Medium

    CVE-2007-5017

    Last Modified: 19 Oct 2016

    Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.

    Source:shinnai
    Published:20 Sept 2007
    7.5
    High

    CVE-2007-5016

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.

    Source:str0ke
    Published:20 Sept 2007
    6.8
    Medium

    CVE-2007-5015

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support.

    Source:BiNgZa
    Published:20 Sept 2007
    5
    Medium

    CVE-2007-5011

    Last Modified: 30 Dec 2013

    webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.

    Source:Doz
    Published:20 Sept 2007
    4.3
    Medium

    CVE-2007-5010

    Last Modified: 30 Dec 2013

    Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe.

    Source:Doz
    Published:20 Sept 2007
    6.8
    Medium

    CVE-2007-5009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehrad
    Published:20 Sept 2007
    10
    Critical

    CVE-2007-5003

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.

    Source:Metasploit
    Published:1 Oct 2007
    6.9
    Medium

    CVE-2007-4993

    Last Modified: 2 Jan 2014

    pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.

    Source:Joris van Rantwijk
    Published:22 Sept 2007
    7.5
    High

    CVE-2007-4984

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Source:nexen
    Published:19 Sept 2007
    10
    Critical

    CVE-2007-4983

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.

    Source:h07
    Published:19 Sept 2007
    10
    Critical

    CVE-2007-4982

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:19 Sept 2007
    4.3
    Medium

    CVE-2007-4980

    Last Modified: 25 Oct 2016

    The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.

    Source:ikki
    Published:19 Sept 2007
    7.5
    High

    CVE-2007-4979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.

    Source:Houssamix
    Published:19 Sept 2007
    7.5
    High

    CVE-2007-4978

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/.

    Source:S.W.A.T.
    Published:19 Sept 2007
    3.5
    Low

    CVE-2007-4977

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.

    Source:L4teral
    Published:19 Sept 2007
    6.5
    Medium

    CVE-2007-4976

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.

    Source:L4teral
    Published:19 Sept 2007
    4.3
    Medium

    CVE-2007-4975

    Last Modified: 30 Dec 2013

    Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.

    Source:malibu.r
    Published:19 Sept 2007
    6.8
    Medium

    CVE-2007-4966

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.

    Source:Sumit Siddharth
    Published:18 Sept 2007