7.8
    High

    CVE-2007-3529

    Last Modified: 5 Oct 2016

    videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.

    Source:Kw3[R]Ln
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3526

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.

    Source:t0pP8uZz
    Published:3 Jul 2007
    6.8
    Medium

    CVE-2007-3524

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php.

    Source:BlackNDoor
    Published:3 Jul 2007
    6.4
    Medium

    CVE-2007-3523

    Last Modified: 5 Oct 2016

    Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.

    Source:BlackNDoor
    Published:3 Jul 2007
    6.8
    Medium

    CVE-2007-3522

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.

    Source:Mehmet Ince
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3521

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie.

    Source:t0pP8uZz
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3520

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

    Source:t0pP8uZz
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3519

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Iron
    Published:3 Jul 2007
    7.5
    High

    CVE-2007-3518

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:3 Jul 2007
    4.3
    Medium

    CVE-2007-3517

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.

    Source:munozferna
    Published:3 Jul 2007
    10
    Critical

    CVE-2007-3515

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:3 Jul 2007
    6.4
    Medium

    CVE-2007-3505

    Last Modified: 15 Nov 2016

    Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.

    Source:Katatafish
    Published:2 Jul 2007
    7.5
    High

    CVE-2007-3493

    Last Modified: 23 Apr 2026

    A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

    Source:shinnai
    Published:29 Jun 2007
    6.8
    Medium

    CVE-2007-3492

    Last Modified: 13 Dec 2013

    Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string containing "//A:" in the argument to the LIST command.

    Source:35c666
    Published:29 Jun 2007
    7.5
    High

    CVE-2007-3490

    Last Modified: 14 Aug 2017

    Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.

    Source:ZhenHan.Liu
    Published:29 Jun 2007
    10
    Critical

    CVE-2007-3488

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method.

    Source:str0ke
    Published:29 Jun 2007
    6.4
    Medium

    CVE-2007-3487

    Last Modified: 23 Apr 2026

    Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.

    Source:callAX
    Published:29 Jun 2007
    6.8
    Medium

    CVE-2007-3479

    Last Modified: 16 Dec 2013

    Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the "used DLL" field in a WDP project file.

    Source:Jerome Athias
    Published:28 Jun 2007
    4.3
    Medium

    CVE-2007-3473

    Last Modified: 13 Dec 2013

    The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.

    Source:anonymous
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3461

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:t0pP8uZz
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3460

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.

    Source:g00ns
    Published:27 Jun 2007
    6.4
    Medium

    CVE-2007-3459

    Last Modified: 23 Apr 2026

    A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method.

    Source:callAX
    Published:27 Jun 2007
    9.3
    Critical

    CVE-2007-3456

    Last Modified: 16 Dec 2013

    Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.

    Source:Stefano DiPaola
    Published:10 Jul 2007
    7.5
    High

    CVE-2007-3452

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

    Source:t0pP8uZz
    Published:27 Jun 2007
    6.5
    Medium

    CVE-2007-3451

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.

    Source:Crackers_Child
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2007-3450

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Crackers_Child
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2007-3449

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:Crackers_Child
    Published:27 Jun 2007
    4.3
    Medium

    CVE-2007-3448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.

    Source:t0pP8uZz
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2007-3447

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.

    Source:t0pP8uZz
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3446

    Last Modified: 23 Apr 2026

    BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.

    Source:t0pP8uZz
    Published:27 Jun 2007
    9.3
    Critical

    CVE-2007-3435

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.

    Source:callAX
    Published:27 Jun 2007
    5
    Medium

    CVE-2007-3434

    Last Modified: 23 Apr 2026

    index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.

    Source:t0pP8uZz
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3433

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.

    Source:t0pP8uZz
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3432

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.

    Source:DarkFig
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2007-3431

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.

    Source:Katatafish
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.

    Source:Kacper
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2007-3429

    Last Modified: 5 Oct 2016

    Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.

    Source:g00ns
    Published:27 Jun 2007
    7.5
    High

    CVE-2007-3427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.

    Source:laurent gaffié
    Published:27 Jun 2007
    4.3
    Medium

    CVE-2007-3426

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Source:laurent gaffié
    Published:27 Jun 2007
    5
    Medium

    CVE-2007-3425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.

    Source:laurent gaffié
    Published:27 Jun 2007
    9.3
    Critical

    CVE-2007-3410

    Last Modified: 5 Oct 2016

    Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.

    Source:axis
    Published:26 Jun 2007
    5
    Medium

    CVE-2007-3407

    Last Modified: 12 Dec 2013

    Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).

    Source:Shay Priel
    Published:26 Jun 2007
    4.3
    Medium

    CVE-2007-3406

    Last Modified: 16 Nov 2013

    Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.

    Source:Rajesh Sethumadhavan
    Published:26 Jun 2007
    5
    Medium

    CVE-2007-3404

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Source:H4 / XPK
    Published:26 Jun 2007
    7.5
    High

    CVE-2007-3403

    Last Modified: 5 Oct 2016

    Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.

    Source:Dj7xpl
    Published:26 Jun 2007
    7.5
    High

    CVE-2007-3402

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.

    Source:Katatafish
    Published:26 Jun 2007
    7.5
    High

    CVE-2007-3401

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.

    Source:Rf7awy
    Published:26 Jun 2007
    9.3
    Critical

    CVE-2007-3400

    Last Modified: 15 Nov 2017

    The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.

    Source:shinnai
    Published:26 Jun 2007
    5
    Medium

    CVE-2007-3398

    Last Modified: 12 Dec 2013

    LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages.

    Source:Prili
    Published:26 Jun 2007
    4.3
    Medium

    CVE-2007-3396

    Last Modified: 12 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.

    Source:Shay Priel
    Published:26 Jun 2007