5.8
    Medium

    CVE-2007-4965

    Last Modified: 30 Dec 2013

    Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

    Source:Slythers Bro
    Published:16 Sept 2007
    5
    Medium

    CVE-2007-4964

    Last Modified: 2 Jan 2014

    WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.

    Source:j00ru//vx
    Published:18 Sept 2007
    9.3
    Critical

    CVE-2007-4962

    Last Modified: 30 Dec 2013

    Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Source:j00ru//vx
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4957

    Last Modified: 12 Oct 2016

    Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter.

    Source:GoLd_M
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4956

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.

    Source:s4mi
    Published:18 Sept 2007
    6.8
    Medium

    CVE-2007-4955

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Morgan
    Published:18 Sept 2007
    6.8
    Medium

    CVE-2007-4954

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Morgan
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4953

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.

    Source:Cold Zero
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.

    Source:Cold Zero
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4942

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806. NOTE: the provenance of this information is unknown.

    Source:ThE TiGeR
    Published:18 Sept 2007
    7.1
    High

    CVE-2007-4941

    Last Modified: 30 Dec 2013

    KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.

    Source:Code Audit Labs
    Published:18 Sept 2007
    9.3
    Critical

    CVE-2007-4939

    Last Modified: 29 Dec 2013

    Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with an "indx truck size" of 0xffffffff, and certain wLongsPerEntry and nEntriesInuse values.

    Source:Code Audit Labs
    Published:18 Sept 2007
    7.6
    High

    CVE-2007-4938

    Last Modified: 24 Nov 2016

    Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.

    Source:Code Audit Labs
    Published:18 Sept 2007
    5
    Medium

    CVE-2007-4937

    Last Modified: 30 Dec 2013

    CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.

    Source:Cr@zy_King
    Published:18 Sept 2007
    4.6
    Medium

    CVE-2007-4934

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php.

    Source:Dj7xpl
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4933

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters.

    Source:InATeam
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4932

    Last Modified: 23 Apr 2026

    admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel.

    Source:InATeam
    Published:18 Sept 2007
    4.3
    Medium

    CVE-2007-4930

    Last Modified: 30 Dec 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.

    Source:Seth Fogie
    Published:18 Sept 2007
    7.5
    High

    CVE-2007-4925

    Last Modified: 30 Dec 2013

    The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.

    Source:anonymous
    Published:18 Sept 2007
    5
    Medium

    CVE-2007-4924

    Last Modified: 23 Apr 2026

    The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."

    Source:Jose Miguel Esparza
    Published:17 Sept 2007
    6.8
    Medium

    CVE-2007-4923

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Morgan
    Published:17 Sept 2007
    6.5
    Medium

    CVE-2007-4922

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information.

    Source:Houssamix
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4921

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.

    Source:arfis project
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4920

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.

    Source:D4real_TeaM
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4919

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.

    Source:s4mi
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.

    Source:s0cratex
    Published:17 Sept 2007
    4.3
    Medium

    CVE-2007-4917

    Last Modified: 30 Dec 2013

    Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334.

    Published:17 Sept 2007
    10
    Critical

    CVE-2007-4916

    Last Modified: 12 Oct 2016

    Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

    Source:GOODFELLAS
    Published:17 Sept 2007
    10
    Critical

    CVE-2007-4915

    Last Modified: 30 Dec 2013

    The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.

    Source:Luca Carettoni
    Published:17 Sept 2007
    5
    Medium

    CVE-2007-4911

    Last Modified: 23 Apr 2026

    JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000. NOTE: some of these details are obtained from third party information.

    Source:vCore
    Published:17 Sept 2007
    9.3
    Critical

    CVE-2007-4909

    Last Modified: 30 Dec 2013

    Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.

    Source:Kender.Security
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4908

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.

    Source:k1tk4t
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4907

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and (6) admin/auth.php.

    Source:aLiiF
    Published:17 Sept 2007
    6.8
    Medium

    CVE-2007-4906

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:Rootshell Security
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4905

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.

    Source:k1tk4t
    Published:17 Sept 2007
    4.3
    Medium

    CVE-2007-4904

    Last Modified: 25 Oct 2016

    RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

    Source:NtWaK0
    Published:17 Sept 2007
    7.5
    High

    CVE-2007-4903

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.

    Source:shinnai
    Published:17 Sept 2007
    6.4
    Medium

    CVE-2007-4902

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.

    Source:shinnai
    Published:17 Sept 2007
    4.3
    Medium

    CVE-2007-4899

    Last Modified: 29 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search.

    Source:Doz
    Published:14 Sept 2007
    5
    Medium

    CVE-2007-4897

    Last Modified: 23 Apr 2026

    pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).

    Source:Jose Miguel Esparza
    Published:12 Sept 2007
    4.3
    Medium

    CVE-2007-4896

    Last Modified: 29 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.

    Source:hd1979
    Published:14 Sept 2007
    5
    Medium

    CVE-2007-4895

    Last Modified: 3 Nov 2016

    Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter.

    Source:k-one
    Published:14 Sept 2007
    7.5
    High

    CVE-2007-4892

    Last Modified: 5 Sept 2016

    Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers to execute arbitrary SQL commands via a PLESKSESSID cookie to (1) login.php3 or (2) auth.php3.

    Source:Nick I Merritt
    Published:14 Sept 2007
    6.8
    Medium

    CVE-2007-4891

    Last Modified: 23 Apr 2026

    A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

    Source:shinnai
    Published:14 Sept 2007
    5.8
    Medium

    CVE-2007-4890

    Last Modified: 23 Apr 2026

    Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.

    Source:shinnai
    Published:14 Sept 2007
    6.8
    Medium

    CVE-2007-4886

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.

    Source:k1tk4t
    Published:14 Sept 2007
    10
    Critical

    CVE-2007-4880

    Last Modified: 20 Oct 2016

    Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.

    Source:muts
    Published:28 Sept 2007
    4.3
    Medium

    CVE-2007-4874

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.

    Source:Jesper Jurcenoks
    Published:26 Sept 2007
    6.8
    Medium

    CVE-2007-4863

    Last Modified: 6 Jan 2014

    SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.

    Source:netVigilance
    Published:30 Oct 2007
    4.3
    Medium

    CVE-2007-4862

    Last Modified: 6 Jan 2014

    Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter.

    Source:netVigilance
    Published:30 Oct 2007