7.5
    High

    CVE-2007-3636

    Last Modified: 14 Dec 2013

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.

    Source:Stefan Esser
    Published:10 Jul 2007
    6.4
    Medium

    CVE-2007-3633

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.

    Source:shinnai
    Published:10 Jul 2007
    6.8
    Medium

    CVE-2007-3632

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.

    Source:Yakir Wizman
    Published:10 Jul 2007
    7.5
    High

    CVE-2007-3631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

    Source:Xenduer77
    Published:10 Jul 2007
    6.4
    Medium

    CVE-2007-3630

    Last Modified: 23 Apr 2026

    changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

    Source:Dj7xpl
    Published:10 Jul 2007
    10
    Critical

    CVE-2007-3629

    Last Modified: 13 Dec 2013

    SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:GeFORC3
    Published:9 Jul 2007
    7.5
    High

    CVE-2007-3627

    Last Modified: 11 Jun 2013

    Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:almaster
    Published:9 Jul 2007
    10
    Critical

    CVE-2007-3624

    Last Modified: 13 Dec 2013

    Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.

    Source:Mark Litchfield
    Published:9 Jul 2007
    7.5
    High

    CVE-2007-3621

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.

    Source:Carl Livitt
    Published:9 Jul 2007
    5
    Medium

    CVE-2007-3619

    Last Modified: 13 Dec 2013

    Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Source:Adriel T. Desautels
    Published:9 Jul 2007
    7.5
    High

    CVE-2007-3614

    Last Modified: 9 Mar 2011

    Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

    Source:Metasploit
    Published:6 Jul 2007
    4.3
    Medium

    CVE-2007-3613

    Last Modified: 13 Dec 2013

    Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.

    Source:Mark Litchfield
    Published:6 Jul 2007
    7.5
    High

    CVE-2007-3612

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command.

    Source:h07
    Published:6 Jul 2007
    9.3
    Critical

    CVE-2007-3611

    Last Modified: 23 Apr 2026

    admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act parameter.

    Source:R4M!
    Published:6 Jul 2007
    7.5
    High

    CVE-2007-3610

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:t0pP8uZz
    Published:6 Jul 2007
    7.5
    High

    CVE-2007-3609

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors.

    Source:t0pP8uZz
    Published:6 Jul 2007
    5
    Medium

    CVE-2007-3608

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.

    Source:Mark Litchfield
    Published:6 Jul 2007
    5
    Medium

    CVE-2007-3607

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

    Source:Mark Litchfield
    Published:6 Jul 2007
    7.6
    High

    CVE-2007-3606

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.

    Source:Mark Litchfield
    Published:6 Jul 2007
    7.6
    High

    CVE-2007-3605

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.

    Source:Mark Litchfield
    Published:6 Jul 2007
    2.6
    Low

    CVE-2007-3594

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.

    Source:Lostmon
    Published:6 Jul 2007
    4.3
    Medium

    CVE-2007-3593

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp. NOTE: it was later reported that vector 3 also affects 7.5 build 7500.

    Source:Lostmon
    Published:6 Jul 2007
    4.3
    Medium

    CVE-2007-3590

    Last Modified: 5 Oct 2016

    Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Source:GoLd_M
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3589

    Last Modified: 5 Oct 2016

    Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.

    Source:GoLd_M
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3587

    Last Modified: 5 Oct 2016

    MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.

    Source:BlackHawk
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3586

    Last Modified: 5 Oct 2016

    Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files.

    Source:BlackHawk
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3585

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Source:BlackHawk
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3584

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Source:Coloss
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3583

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter.

    Source:Cold Zero
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3582

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter.

    Source:t0pP8uZz
    Published:5 Jul 2007
    4.3
    Medium

    CVE-2007-3574

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter.

    Source:Petko Petkov
    Published:5 Jul 2007
    9.3
    Critical

    CVE-2007-3572

    Last Modified: 13 Dec 2013

    Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).

    Source:Cody Brocious
    Published:5 Jul 2007
    4.3
    Medium

    CVE-2007-3569

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) "Basic Search page"; and (8) username parameter when (c) logging on.

    Source:A. R.
    Published:5 Jul 2007
    7.5
    High

    CVE-2007-3566

    Last Modified: 21 Nov 2016

    Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.

    Source:Metasploit
    Published:26 Jul 2007
    7.5
    High

    CVE-2007-3563

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.

    Source:Kw3[R]Ln
    Published:4 Jul 2007
    7.5
    High

    CVE-2007-3562

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Kw3[R]Ln
    Published:4 Jul 2007
    7.5
    High

    CVE-2007-3558

    Last Modified: 21 Sept 2016

    SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.

    Source:DarkFig
    Published:4 Jul 2007
    5
    Medium

    CVE-2007-3556

    Last Modified: 13 Dec 2013

    Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.

    Source:durito
    Published:4 Jul 2007
    4.3
    Medium

    CVE-2007-3555

    Last Modified: 13 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

    Source:MustLive
    Published:4 Jul 2007
    7.6
    High

    CVE-2007-3554

    Last Modified: 5 Oct 2016

    Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.

    Source:shinnai
    Published:4 Jul 2007
    4.3
    Medium

    CVE-2007-3553

    Last Modified: 13 Dec 2013

    Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Kaushal Desai
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3549

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:t0pP8uZz
    Published:3 Jul 2007
    7.1
    High

    CVE-2007-3548

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.

    Source:r0ut3r
    Published:3 Jul 2007
    7.8
    High

    CVE-2007-3547

    Last Modified: 15 Nov 2016

    Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.

    Source:Katatafish
    Published:3 Jul 2007
    4.3
    Medium

    CVE-2007-3542

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:DarkFig
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3539

    Last Modified: 15 Nov 2016

    Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

    Source:croconile
    Published:3 Jul 2007
    7.6
    High

    CVE-2007-3536

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.

    Source:rgod
    Published:3 Jul 2007
    6.4
    Medium

    CVE-2007-3535

    Last Modified: 5 Oct 2016

    Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php.

    Source:Katatafish
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3534

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter.

    Source:r00t
    Published:3 Jul 2007
    7.2
    High

    CVE-2007-3530

    Last Modified: 5 Oct 2016

    PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.

    Source:Kw3[R]Ln
    Published:3 Jul 2007