5
    Medium

    CVE-2007-4369

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:dun
    Published:15 Aug 2007
    7.5
    High

    CVE-2007-4368

    Last Modified: 1 Nov 2017

    SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.

    Source:s4squatch
    Published:15 Aug 2007
    5
    Medium

    CVE-2007-4366

    Last Modified: 23 Apr 2026

    WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header.

    Source:ZwelL
    Published:15 Aug 2007
    6.8
    Medium

    CVE-2007-4362

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:t0pP8uZz
    Published:15 Aug 2007
    6.8
    Medium

    CVE-2007-4359

    Last Modified: 25 Dec 2013

    Multiple SQL injection vulnerabilities in SkilMatch Staffing Systems JobLister3 allow remote attackers to execute arbitrary SQL commands via (1) the search form or (2) the jobid parameter to index.php in a showbyID action.

    Source:joseph.giron13
    Published:15 Aug 2007
    4.3
    Medium

    CVE-2007-4358

    Last Modified: 25 Dec 2013

    Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containing 0x69 in the ninth byte, which triggers a "double-delete" of trace data, a different vulnerability than CVE-2005-1643.

    Source:Luigi Auriemma
    Published:15 Aug 2007
    7.5
    High

    CVE-2007-4341

    Last Modified: 25 Dec 2013

    PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

    Source:ilker Kandemir
    Published:14 Aug 2007
    10
    Critical

    CVE-2007-4338

    Last Modified: 25 Dec 2013

    index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.

    Source:ilker Kandemir
    Published:14 Aug 2007
    4.3
    Medium

    CVE-2007-4336

    Last Modified: 23 Apr 2026

    Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long SourceUrl property value.

    Source:h07
    Published:14 Aug 2007
    4.3
    Medium

    CVE-2007-4334

    Last Modified: 25 Dec 2013

    Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP parameter.

    Source:vasodipandora
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4330

    Last Modified: 25 Dec 2013

    PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:Rizgar
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4329

    Last Modified: 25 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) news.php, or (3) feed.php.

    Source:Rizgar
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4328

    Last Modified: 25 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. NOTE: A later report states that 1.1 is also affected, but that the filename for vector 3 is anzeigen.php.

    Source:Rizgar
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4327

    Last Modified: 24 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php.

    Source:Rizgar
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4325

    Last Modified: 24 Dec 2013

    PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.

    Source:Rizgar
    Published:14 Aug 2007
    6.8
    Medium

    CVE-2007-4321

    Last Modified: 23 Dec 2013

    fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a client protocol version identification containing an IP address string, a different vector than CVE-2006-6302.

    Source:Daniel B. Cid
    Published:14 Aug 2007
    7.5
    High

    CVE-2007-4320

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.

    Source:k1n9k0ng
    Published:14 Aug 2007
    4.3
    Medium

    CVE-2007-4318

    Last Modified: 25 Dec 2013

    Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.

    Source:Henri Lindberg
    Published:13 Aug 2007
    6.8
    Medium

    CVE-2007-4314

    Last Modified: 23 Apr 2026

    pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. NOTE: this can be leveraged for traffic amplification or other denial of service.

    Source:Rizgar
    Published:13 Aug 2007
    6.8
    Medium

    CVE-2007-4313

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter, a different vector than CVE-2006-2392, CVE-2006-3076, and CVE-2006-6958.

    Source:Kacper
    Published:13 Aug 2007
    7.5
    High

    CVE-2007-4312

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action.

    Source:Kacper
    Published:13 Aug 2007
    6.2
    Medium

    CVE-2007-4305

    Last Modified: 15 Nov 2017

    Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.

    Source:Robert N. M. Watson
    Published:13 Aug 2007
    6.2
    Medium

    CVE-2007-4302

    Last Modified: 15 Nov 2017

    Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing.

    Source:Robert N. M. Watson
    Published:13 Aug 2007
    4.3
    Medium

    CVE-2007-4288

    Last Modified: 27 Dec 2013

    Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au.

    Source:A.Sawan & nophie
    Published:9 Aug 2007
    7.5
    High

    CVE-2007-4287

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the docroot parameter.

    Source:k1n9k0ng
    Published:9 Aug 2007
    9.3
    Critical

    CVE-2007-4286

    Last Modified: 23 Apr 2026

    Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.

    Source:Martin Kluge
    Published:9 Aug 2007
    7.5
    High

    CVE-2007-4283

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter.

    Source:Ma$tEr-0F-De$a$t0r
    Published:9 Aug 2007
    7.5
    High

    CVE-2007-4279

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter.

    Source:kezzap66345
    Published:9 Aug 2007
    4.3
    Medium

    CVE-2007-4264

    Last Modified: 24 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) path and (2) download parameters.

    Source:r0t
    Published:9 Aug 2007
    7.5
    High

    CVE-2007-4258

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:t0pP8uZz
    Published:8 Aug 2007
    6.8
    Medium

    CVE-2007-4257

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate string, different vectors than CVE-2007-4140.

    Source:n00b
    Published:8 Aug 2007
    5
    Medium

    CVE-2007-4256

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.

    Source:GoLd_M
    Published:8 Aug 2007
    7.5
    High

    CVE-2007-4255

    Last Modified: 12 Oct 2016

    Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.

    Source:NetJackal
    Published:8 Aug 2007
    6.8
    Medium

    CVE-2007-4254

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method. NOTE: this may overlap CVE-2007-2885 or CVE-2005-2127.

    Source:DeltahackingTEAM
    Published:8 Aug 2007
    7.5
    High

    CVE-2007-4253

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2005-4263.

    Source:k1tk4t
    Published:8 Aug 2007
    4.3
    Medium

    CVE-2007-4252

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a different vulnerability than CVE-2007-3633.

    Source:shinnai
    Published:8 Aug 2007
    7.5
    High

    CVE-2007-4244

    Last Modified: 24 Dec 2013

    PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP code via a URL in the comPath parameter.

    Source:Yollubunlar.Org
    Published:8 Aug 2007
    9.3
    Critical

    CVE-2007-4235

    Last Modified: 24 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in VietPHP allow remote attackers to execute arbitrary PHP code via a URL in (1) the dirpath parameter to (a) _functions.php, or (2) the language parameter to (b) admin/index.php or (c) index.php.

    Source:master-of-desastor
    Published:8 Aug 2007
    6.8
    Medium

    CVE-2007-4232

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter.

    Source:kezzap66345
    Published:8 Aug 2007
    6.8
    Medium

    CVE-2007-4231

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776.

    Source:K-159
    Published:8 Aug 2007
    4.3
    Medium

    CVE-2007-4229

    Last Modified: 24 Dec 2013

    Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Thomas Waldegger
    Published:8 Aug 2007
    7.1
    High

    CVE-2007-4226

    Last Modified: 24 Dec 2013

    Directory traversal vulnerability in the BlueCat Networks Proteus IPAM appliance 2.0.2.0 (Adonis DNS/DHCP appliance 5.0.2.8) allows remote authenticated administrators, with certain TFTP privileges, to create and overwrite arbitrary files via a .. (dot dot) in a pathname. NOTE: this can be leveraged for administrative access by overwriting /etc/shadow.

    Source:defaultroute
    Published:8 Aug 2007
    7.8
    High

    CVE-2007-4220

    Last Modified: 27 Dec 2013

    Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send request, probably related to the (1) Send and (2) Exchange services.

    Source:titon
    Published:29 Aug 2007
    7.5
    High

    CVE-2007-4210

    Last Modified: 12 Oct 2016

    Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.

    Source:k1tk4t
    Published:8 Aug 2007
    7.5
    High

    CVE-2007-4208

    Last Modified: 24 Dec 2013

    SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action.

    Source:Aria-Security Team
    Published:8 Aug 2007
    6.9
    Medium

    CVE-2007-4191

    Last Modified: 12 Oct 2016

    Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657.

    Source:tarkus
    Published:8 Aug 2007
    6.8
    Medium

    CVE-2007-4186

    Last Modified: 24 Dec 2013

    PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Yollubunlar.Org
    Published:8 Aug 2007
    7.5
    High

    CVE-2007-4183

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

    Source:uimp
    Published:8 Aug 2007
    4.3
    Medium

    CVE-2007-4178

    Last Modified: 23 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in WebDirector 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the deslocal parameter.

    Source:r0t
    Published:8 Aug 2007
    5.8
    Medium

    CVE-2007-4174

    Last Modified: 24 Dec 2013

    Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

    Source:anonymous
    Published:7 Aug 2007