4.3
    Medium

    CVE-2007-4024

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:GeFORC3
    Published:26 Jul 2007
    4.3
    Medium

    CVE-2007-4022

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

    Source:Aria-Security Team
    Published:26 Jul 2007
    6.8
    Medium

    CVE-2007-4010

    Last Modified: 14 Feb 2020

    The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.

    Source:shinnai
    Published:26 Jul 2007
    9.3
    Critical

    CVE-2007-4009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter.

    Source:H4 / XPK
    Published:26 Jul 2007
    7.5
    High

    CVE-2007-4008

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter.

    Source:Kw3[R]Ln
    Published:26 Jul 2007
    9.3
    Critical

    CVE-2007-4007

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:mozi
    Published:26 Jul 2007
    6.8
    Medium

    CVE-2007-4006

    Last Modified: 10 Mar 2011

    Buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 has unknown impact and remote attack vectors, aka ZD-00000034. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Source:Metasploit
    Published:26 Jul 2007
    5
    Medium

    CVE-2007-4005

    Last Modified: 5 Oct 2016

    Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the shell port (514/tcp). NOTE: this might overlap CVE-2007-4006.

    Source:Joey Mengele
    Published:26 Jul 2007
    6.9
    Medium

    CVE-2007-4004

    Last Modified: 30 Jan 2017

    Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.

    Source:qaaz
    Published:26 Jul 2007
    6.9
    Medium

    CVE-2007-4003

    Last Modified: 12 Oct 2016

    pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.

    Source:qaaz
    Published:26 Jul 2007
    7.5
    High

    CVE-2007-3997

    Last Modified: 12 Oct 2016

    The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

    Source:Mattias Bengtsson
    Published:4 Sept 2007
    4.3
    Medium

    CVE-2007-3991

    Last Modified: 16 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters; and possibly other unspecified vectors.

    Source:GeFORC3
    Published:25 Jul 2007
    4.3
    Medium

    CVE-2007-3989

    Last Modified: 16 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and possibly other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:GeFORC3
    Published:25 Jul 2007
    7.5
    High

    CVE-2007-3987

    Last Modified: 16 Dec 2013

    SQL injection vulnerability in SearchResults.asp in ImageRacer 1.0, when WordSearchCrit is enabled, allows remote attackers to execute arbitrary SQL commands via the SearchWord parameter.

    Source:Aria-Security Team
    Published:25 Jul 2007
    7.5
    High

    CVE-2007-3984

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to execute arbitrary code via a long argument to the Scan method. NOTE: this is probably a different issue than CVE-2007-2987.

    Source:shinnai
    Published:25 Jul 2007
    5
    Medium

    CVE-2007-3983

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) allows remote attackers to create or overwrite arbitrary files via a full pathname in an argument to the SaveLayout method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:shinnai
    Published:25 Jul 2007
    5
    Medium

    CVE-2007-3982

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method.

    Source:shinnai
    Published:25 Jul 2007
    7.5
    High

    CVE-2007-3981

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL commands via the catid parameter in a displaycat action.

    Source:t0pP8uZz
    Published:25 Jul 2007
    10
    Critical

    CVE-2007-3980

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Source:Warpboy
    Published:25 Jul 2007
    6.8
    Medium

    CVE-2007-3979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:t0pP8uZz
    Published:25 Jul 2007
    4.3
    Medium

    CVE-2007-3978

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Source:g00ns
    Published:25 Jul 2007
    4.3
    Medium

    CVE-2007-3977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:g00ns
    Published:25 Jul 2007
    7.5
    High

    CVE-2007-3976

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the newsID parameter.

    Source:g00ns
    Published:25 Jul 2007
    7.5
    High

    CVE-2007-3974

    Last Modified: 23 Apr 2026

    admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters.

    Source:s4mi
    Published:25 Jul 2007
    6.8
    Medium

    CVE-2007-3973

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.

    Source:s4mi
    Published:25 Jul 2007
    9.3
    Critical

    CVE-2007-3963

    Last Modified: 16 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.

    Source:s4mi
    Published:25 Jul 2007
    7.1
    High

    CVE-2007-3958

    Last Modified: 23 Apr 2026

    Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.

    Source:DeltahackingTEAM
    Published:24 Jul 2007
    5
    Medium

    CVE-2007-3957

    Last Modified: 5 Oct 2016

    Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI.

    Source:deusconstruct
    Published:24 Jul 2007
    7.8
    High

    CVE-2007-3956

    Last Modified: 23 Apr 2026

    TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.

    Source:YAG KOHHA
    Published:24 Jul 2007
    6.8
    Medium

    CVE-2007-3955

    Last Modified: 23 Apr 2026

    Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.

    Source:Jared DeMott
    Published:24 Jul 2007
    5.8
    Medium

    CVE-2007-3947

    Last Modified: 16 Dec 2013

    request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.

    Source:Abhisek Datta
    Published:24 Jul 2007
    6.8
    Medium

    CVE-2007-3939

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:ajann
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3938

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.

    Source:anonymous
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3937

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Source:Timq
    Published:21 Jul 2007
    6.4
    Medium

    CVE-2007-3936

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filename references in the delfiles parameter.

    Source:Timq
    Published:21 Jul 2007
    9.3
    Critical

    CVE-2007-3935

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3934

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL in the p_mode parameter.

    Source:mozi
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053.

    Source:meoconx
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3932

    Last Modified: 23 Apr 2026

    uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

    Source:Cold Zero
    Published:21 Jul 2007
    10
    Critical

    CVE-2007-3927

    Last Modified: 5 Oct 2016

    Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe."

    Source:ZhenHan.Liu
    Published:21 Jul 2007
    6.5
    Medium

    CVE-2007-3925

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.

    Source:Metasploit
    Published:21 Jul 2007
    7.5
    High

    CVE-2007-3913

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Source:Sumit Siddharth
    Published:6 Sept 2007
    7.5
    High

    CVE-2007-3909

    Last Modified: 17 Dec 2013

    Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.

    Source:Tim Brown
    Published:19 Jul 2007
    8.5
    High

    CVE-2007-3901

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

    Source:Metasploit
    Published:12 Dec 2007
    6.4
    Medium

    CVE-2007-3898

    Last Modified: 2 Jan 2014

    The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.

    Source:Alla Berzroutchko
    Published:14 Nov 2007
    9.3
    Critical

    CVE-2007-3896

    Last Modified: 2 Jan 2014

    The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.

    Source:Billy Rios
    Published:11 Oct 2007
    7.5
    High

    CVE-2007-3889

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors.

    Source:joseph.giron13
    Published:18 Jul 2007
    4.3
    Medium

    CVE-2007-3888

    Last Modified: 7 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a) posted_by, (b) subject, and (c) content parameters to index.php; as demonstrated by the onmouseover attribute of certain elements. NOTE: some of these details are obtained from third party information.

    Source:joseph.giron13
    Published:18 Jul 2007
    7.5
    High

    CVE-2007-3884

    Last Modified: 16 Dec 2013

    SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.

    Source:GeFORC3
    Published:18 Jul 2007
    5.1
    Medium

    CVE-2007-3883

    Last Modified: 23 Apr 2026

    The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method.

    Source:shinnai
    Published:18 Jul 2007