7.5
    High

    CVE-2007-3394

    Last Modified: 12 Dec 2013

    Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.

    Source:laurent gaffie
    Published:26 Jun 2007
    4.3
    Medium

    CVE-2007-3386

    Last Modified: 25 Dec 2013

    Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.

    Source:NTT OSS CENTER
    Published:14 Aug 2007
    4.3
    Medium

    CVE-2007-3382

    Last Modified: 25 Dec 2013

    Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.

    Source:Tomasz Kuczynski
    Published:14 Aug 2007
    7.5
    High

    CVE-2007-3371

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.

    Source:Kw3[R]Ln
    Published:22 Jun 2007
    7.5
    High

    CVE-2007-3370

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.

    Source:GoLd_M
    Published:22 Jun 2007
    7.5
    High

    CVE-2007-3365

    Last Modified: 12 Dec 2013

    MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.

    Source:Shay Priel
    Published:22 Jun 2007
    4.3
    Medium

    CVE-2007-3364

    Last Modified: 12 Dec 2013

    Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content.

    Source:Prili
    Published:22 Jun 2007
    9.3
    Critical

    CVE-2007-3360

    Last Modified: 5 Oct 2016

    hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.

    Source:clarity_
    Published:22 Jun 2007
    6.8
    Medium

    CVE-2007-3358

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.

    Source:Kw3[R]Ln
    Published:22 Jun 2007
    7.5
    High

    CVE-2007-3354

    Last Modified: 12 Dec 2013

    Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.

    Source:laurent gaffie
    Published:22 Jun 2007
    7.8
    High

    CVE-2007-3346

    Last Modified: 12 Dec 2013

    Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.

    Source:r0t
    Published:22 Jun 2007
    7.8
    High

    CVE-2007-3340

    Last Modified: 27 Sept 2016

    BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages.

    Source:Prili
    Published:21 Jun 2007
    4.3
    Medium

    CVE-2007-3339

    Last Modified: 11 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.

    Source:Ivan Almuina
    Published:21 Jun 2007
    10
    Critical

    CVE-2007-3336

    Last Modified: 14 Aug 2010

    Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.

    Source:fdiskyou
    Published:22 Jun 2007
    10
    Critical

    CVE-2007-3334

    Last Modified: 12 Dec 2013

    Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.

    Source:anonymous
    Published:21 Jun 2007
    6.9
    Medium

    CVE-2007-3333

    Last Modified: 17 Dec 2013

    Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.

    Source:qaaz
    Published:26 Jul 2007
    5
    Medium

    CVE-2007-3332

    Last Modified: 22 Nov 2013

    Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the name parameter in a modload action.

    Source:rUnViRuS
    Published:21 Jun 2007
    5
    Medium

    CVE-2007-3327

    Last Modified: 11 Dec 2013

    httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).

    Source:Prili
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3325

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

    Source:Kw3[R]Ln
    Published:21 Jun 2007
    4.3
    Medium

    CVE-2007-3324

    Last Modified: 11 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681.

    Source:Doz
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3323

    Last Modified: 11 Dec 2013

    SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.

    Source:Doz
    Published:21 Jun 2007
    6.8
    Medium

    CVE-2007-3315

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2) templates/Classic Guestbook/, (3) templates/DarkNights/, and (4) templates/Simplistic/, different vectors than CVE-2007-3271. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Crackers_Child
    Published:21 Jun 2007
    6.8
    Medium

    CVE-2007-3314

    Last Modified: 25 Apr 2011

    Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.

    Source:Metasploit
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3313

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.

    Source:Silentz
    Published:21 Jun 2007
    9
    Critical

    CVE-2007-3312

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arbitrary local files a .. (dot dot) in the u parameter. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

    Source:Silentz
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3311

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:WiLdBoY
    Published:21 Jun 2007
    4.3
    Medium

    CVE-2007-3310

    Last Modified: 11 Dec 2013

    Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:GeFORC3
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3307

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

    Source:BlackHawk
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3306

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.

    Source:Abo0od
    Published:21 Jun 2007
    7.5
    High

    CVE-2007-3301

    Last Modified: 11 Dec 2013

    SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.

    Source:Ivan Almuina
    Published:20 Jun 2007
    7.5
    High

    CVE-2007-3297

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3) modules/SoundImporter.php.

    Source:GoLd_M
    Published:20 Jun 2007
    7.5
    High

    CVE-2007-3294

    Last Modified: 11 Oct 2016

    Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the tidy_repair_string function. NOTE: this might only be an issue in environments where vsnprintf is implemented as a wrapper for vsprintf.

    Source:rgod
    Published:19 Jun 2007
    7.5
    High

    CVE-2007-3293

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:g00ns
    Published:20 Jun 2007
    7.5
    High

    CVE-2007-3292

    Last Modified: 5 Oct 2016

    Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article.

    Source:g00ns
    Published:20 Jun 2007
    4.3
    Medium

    CVE-2007-3291

    Last Modified: 5 Oct 2016

    Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.

    Source:g00ns
    Published:20 Jun 2007
    9.3
    Critical

    CVE-2007-3290

    Last Modified: 5 Oct 2016

    categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.

    Source:g00ns
    Published:20 Jun 2007
    7.5
    High

    CVE-2007-3289

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Source:GoLd_M
    Published:20 Jun 2007
    7.8
    High

    CVE-2007-3284

    Last Modified: 10 Dec 2013

    corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.

    Source:Lostmon
    Published:19 Jun 2007
    7.8
    High

    CVE-2007-3282

    Last Modified: 23 Apr 2026

    Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.

    Source:YAG KOHHA
    Published:19 Jun 2007
    4.3
    Medium

    CVE-2007-3281

    Last Modified: 11 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Serapis.net
    Published:19 Jun 2007
    9
    Critical

    CVE-2007-3280

    Last Modified: 23 Apr 2026

    The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

    Published:19 Jun 2007
    7.8
    High

    CVE-2007-3272

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action.

    Source:Dj7xpl
    Published:19 Jun 2007
    7.5
    High

    CVE-2007-3271

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.

    Source:Crackers_Child
    Published:19 Jun 2007
    10
    Critical

    CVE-2007-3270

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.

    Source:o0xxdark0o
    Published:19 Jun 2007
    4.3
    Medium

    CVE-2007-3267

    Last Modified: 11 Dec 2013

    Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.

    Source:RMx
    Published:19 Jun 2007
    9
    Critical

    CVE-2007-3266

    Last Modified: 11 Dec 2013

    Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.

    Source:maiosyet
    Published:19 Jun 2007
    7.8
    High

    CVE-2007-3251

    Last Modified: 5 Oct 2016

    Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the adminlang cookie to admin/functions.php or (2) read arbitrary local files via the img parameter to admin/show_img.php.

    Source:Silentz
    Published:18 Jun 2007
    4.3
    Medium

    CVE-2007-3249

    Last Modified: 10 Dec 2013

    Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.

    Source:Edi Strosar
    Published:18 Jun 2007
    4.3
    Medium

    CVE-2007-3243

    Last Modified: 10 Dec 2013

    Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.

    Source:Ory Segal
    Published:15 Jun 2007
    6.8
    Medium

    CVE-2007-3237

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Source:Sp[L]o1T
    Published:15 Jun 2007