5
    Medium

    CVE-2007-4850

    Last Modified: 20 Jan 2014

    curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

    Source:Maksymilian Arciemowicz
    Published:22 Jan 2008
    7.5
    High

    CVE-2007-4846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik go action.

    Source:k1tk4t
    Published:12 Sept 2007
    7.5
    High

    CVE-2007-4845

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.

    Source:k1tk4t
    Published:12 Sept 2007
    5.8
    Medium

    CVE-2007-4843

    Last Modified: 29 Dec 2013

    Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Source:Gynvael Coldwind
    Published:12 Sept 2007
    7.5
    High

    CVE-2007-4838

    Last Modified: 2 Jan 2014

    Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.

    Source:Luigi Auriemma
    Published:12 Sept 2007
    7.5
    High

    CVE-2007-4834

    Last Modified: 22 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.

    Source:QTRinux
    Published:12 Sept 2007
    9.3
    Critical

    CVE-2007-4821

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169.

    Source:shinnai
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4820

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.

    Source:QTRinux
    Published:11 Sept 2007
    4.3
    Medium

    CVE-2007-4819

    Last Modified: 12 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Nice Name Crew
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4818

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in modules/.

    Source:Nice Name Crew
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4817

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.

    Source:Cold Zero
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4816

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.

    Source:ZhenHan.Liu
    Published:11 Sept 2007
    6.8
    Medium

    CVE-2007-4815

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php, (2) post.php, (3) view.php, or (4) viewitem.php in source/mod/rss/.

    Source:MhZ91
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4814

    Last Modified: 16 Sept 2016

    Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.

    Source:rgod
    Published:11 Sept 2007
    5
    Medium

    CVE-2007-4812

    Last Modified: 7 Jan 2014

    Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. NOTE: the crash might actually occur in the alert method.

    Source:Azizov E
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4809

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code via a URL in the DOC_ROOT parameter to (1) lib/functions.php or (2) lib/header.php.

    Source:MhZ91
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4808

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.

    Source:k1tk4t
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4807

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakdownTime.php or (2) modules/Discipline/StudentFieldBreakdown.php.

    Source:ThE TiGeR
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4806

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter.

    Source:ThE TiGeR
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4805

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter.

    Source:not sec group
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4804

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances.

    Source:k1tk4t
    Published:11 Sept 2007
    6.8
    Medium

    CVE-2007-4803

    Last Modified: 23 Apr 2026

    Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls file, as demonstrated by the (1) File1 and (2) Title1 fields, different vectors than CVE-2006-6287 and CVE-2007-2487.

    Source:0x58
    Published:11 Sept 2007
    6.8
    Medium

    CVE-2007-4802

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.

    Source:void
    Published:11 Sept 2007
    7.5
    High

    CVE-2007-4790

    Last Modified: 12 Oct 2016

    Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.

    Source:shinnai
    Published:10 Sept 2007
    6.6
    Medium

    CVE-2007-4781

    Last Modified: 12 Oct 2016

    administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter.

    Source:Silentz
    Published:10 Sept 2007
    9.3
    Critical

    CVE-2007-4776

    Last Modified: 10 Mar 2011

    Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a vulnerability.

    Source:Metasploit
    Published:10 Sept 2007
    7.5
    High

    CVE-2007-4763

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPOF_INCLUDE_PATH parameter.

    Source:ThE TiGeR
    Published:8 Sept 2007
    7.5
    High

    CVE-2007-4762

    Last Modified: 4 Oct 2016

    Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092.

    Source:SmOk3
    Published:8 Sept 2007
    7.5
    High

    CVE-2007-4757

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter.

    Source:S.W.A.T.
    Published:8 Sept 2007
    7.5
    High

    CVE-2007-4754

    Last Modified: 2 Jan 2014

    Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname.

    Source:Luigi Auriemma
    Published:8 Sept 2007
    6.8
    Medium

    CVE-2007-4748

    Last Modified: 23 Apr 2026

    Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter.

    Source:dummy
    Published:6 Sept 2007
    6.8
    Medium

    CVE-2007-4744

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter.

    Source:ThE TiGeR
    Published:6 Sept 2007
    9.3
    Critical

    CVE-2007-4740

    Last Modified: 12 Oct 2016

    The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method.

    Source:rgod
    Published:6 Sept 2007
    7.5
    High

    CVE-2007-4738

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php, a different set of vectors than CVE-2007-4737. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:leetsecurity
    Published:6 Sept 2007
    7.5
    High

    CVE-2007-4737

    Last Modified: 12 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.

    Source:leetsecurity
    Published:6 Sept 2007
    7.5
    High

    CVE-2007-4736

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:k1tk4t
    Published:6 Sept 2007
    9.3
    Critical

    CVE-2007-4735

    Last Modified: 23 Apr 2026

    Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file.

    Source:0x58
    Published:6 Sept 2007
    4.3
    Medium

    CVE-2007-4734

    Last Modified: 23 Apr 2026

    Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file.

    Source:0x58
    Published:6 Sept 2007
    5
    Medium

    CVE-2007-4726

    Last Modified: 12 Oct 2016

    Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:Katatafish
    Published:5 Sept 2007
    6.8
    Medium

    CVE-2007-4725

    Last Modified: 29 Dec 2013

    Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.

    Source:miyy3t
    Published:5 Sept 2007
    6.8
    Medium

    CVE-2007-4722

    Last Modified: 3 Nov 2017

    Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.

    Source:anonymous
    Published:5 Sept 2007
    7.5
    High

    CVE-2007-4719

    Last Modified: 28 Dec 2013

    SQL injection vulnerability in read.php in 212cafeBoard 6.30 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Lopez Bran Digrap
    Published:5 Sept 2007
    5.1
    Medium

    CVE-2007-4718

    Last Modified: 28 Dec 2013

    Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:Fernando Munoz
    Published:5 Sept 2007
    3.5
    Low

    CVE-2007-4717

    Last Modified: 28 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.

    Source:Fernando Munoz
    Published:5 Sept 2007
    7.5
    High

    CVE-2007-4715

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code via a URL in the files_dir parameter in (1) es_desp.php, (2) es_custom_menu.php, and (3) es_offer.php.

    Source:bius
    Published:5 Sept 2007
    7.5
    High

    CVE-2007-4714

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:k1tk4t
    Published:5 Sept 2007
    7.5
    High

    CVE-2007-4712

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:JaheeM
    Published:5 Sept 2007
    4.3
    Medium

    CVE-2007-4711

    Last Modified: 28 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage, (2) mail, and (3) name parameters in a show action to (a) form.php; the (4) language and (5) anzeigebreite parameters to (b) admin/header.php; and the (6) msg parameter to (c) install.php, different vectors than CVE-2006-0706.

    Source:cod3in
    Published:5 Sept 2007
    6.9
    Medium

    CVE-2007-4684

    Last Modified: 20 Oct 2016

    Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to the i386_set_ldt system call.

    Source:RISE Security
    Published:15 Nov 2007
    7.5
    High

    CVE-2007-4653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.

    Source:Don
    Published:4 Sept 2007