6.8
    Medium

    CVE-2007-3130

    Last Modified: 10 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:DarkbiteX
    Published:8 Jun 2007
    5
    Medium

    CVE-2007-3127

    Last Modified: 11 Dec 2013

    content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.

    Source:Jesper Jurcenoks
    Published:19 Jun 2007
    7.5
    High

    CVE-2007-3119

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:kerem125
    Published:7 Jun 2007
    7.5
    High

    CVE-2007-3118

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php.

    Source:Mehmet Ince
    Published:7 Jun 2007
    10
    Critical

    CVE-2007-3111

    Last Modified: 5 Oct 2016

    Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.

    Source:rgod
    Published:7 Jun 2007
    6.2
    Medium

    CVE-2007-3103

    Last Modified: 23 Apr 2026

    The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.

    Source:vl4dZ
    Published:11 Jul 2007
    4.3
    Medium

    CVE-2007-3101

    Last Modified: 10 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.

    Source:Rajat Swarup
    Published:18 Jun 2007
    5
    Medium

    CVE-2007-3098

    Last Modified: 23 Apr 2026

    The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.

    Source:En Douli
    Published:6 Jun 2007
    6.8
    Medium

    CVE-2007-3096

    Last Modified: 5 Oct 2016

    Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:Silentz
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter.

    Source:s0cratex
    Published:6 Jun 2007
    4.9
    Medium

    CVE-2007-3086

    Last Modified: 8 Dec 2013

    Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex.

    Source:Matousec Transparent security
    Published:6 Jun 2007
    7.8
    High

    CVE-2007-3082

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter.

    Source:Silentz
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3080

    Last Modified: 8 Dec 2013

    SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ertuqrul
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3077

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter.

    Source:Silentz
    Published:6 Jun 2007
    7.8
    High

    CVE-2007-3076

    Last Modified: 23 Apr 2026

    A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the DownloadFile function.

    Source:shinnai
    Published:6 Jun 2007
    9.3
    Critical

    CVE-2007-3071

    Last Modified: 8 Dec 2013

    Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.

    Source:shinnai
    Published:6 Jun 2007
    4.3
    Medium

    CVE-2007-3070

    Last Modified: 8 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.

    Source:Glafkos Charalambous
    Published:6 Jun 2007
    6.8
    Medium

    CVE-2007-3068

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.

    Source:n00b
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3065

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.

    Source:Silentz
    Published:6 Jun 2007
    4.3
    Medium

    CVE-2007-3064

    Last Modified: 9 Dec 2013

    Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.

    Source:Serapis.net
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3063

    Last Modified: 9 Dec 2013

    SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.

    Source:Serapis.net
    Published:6 Jun 2007
    7.8
    High

    CVE-2007-3061

    Last Modified: 23 Apr 2026

    Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.

    Source:LionTurk
    Published:6 Jun 2007
    4.3
    Medium

    CVE-2007-3060

    Last Modified: 8 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3) PHPLIVE_VERSION parameters to (b) help.php, the (4) admin[name] parameter to (c) admin/header.php, and the (5) BASE_URL parameter to (d) super/info.php, and in some cases, the LANG[DEFAULT_BRANDING], PHPLIVE_VERSION, and (6) nav_line parameters to setup/footer.php, different vectors than CVE-2006-6769.

    Source:ReZEN
    Published:6 Jun 2007
    6.8
    Medium

    CVE-2007-3057

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Source:GoLd_M
    Published:6 Jun 2007
    4.3
    Medium

    CVE-2007-3055

    Last Modified: 8 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:vagrant
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3052

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:Kacper
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-3051

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie.

    Source:BlackHawk
    Published:6 Jun 2007
    4.3
    Medium

    CVE-2007-3049

    Last Modified: 8 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Buttercup web file manager (BWFM) May 2007 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Source:John Martinelli
    Published:6 Jun 2007
    7.2
    High

    CVE-2007-3048

    Last Modified: 23 Apr 2026

    GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue

    Source:Rembrandt
    Published:5 Jun 2007
    9.3
    Critical

    CVE-2007-3040

    Last Modified: 29 Dec 2013

    Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.

    Source:Yamata Li
    Published:12 Sept 2007
    9
    Critical

    CVE-2007-3039

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

    Source:Metasploit
    Published:12 Dec 2007
    9.3
    Critical

    CVE-2007-3034

    Last Modified: 23 Apr 2026

    Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.

    Source:Gil-Dong / Woo-Chi
    Published:14 Aug 2007
    4
    Medium

    CVE-2007-3017

    Last Modified: 19 Dec 2016

    The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.

    Source:RedTeam Pentesting
    Published:17 Jul 2007
    4.3
    Medium

    CVE-2007-3014

    Last Modified: 15 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).

    Source:RedTeam Pentesting
    Published:15 Jul 2007
    6.5
    Medium

    CVE-2007-3013

    Last Modified: 15 Dec 2013

    SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.

    Source:RedTeam Pentesting
    Published:15 Jul 2007
    7.5
    High

    CVE-2007-3011

    Last Modified: 13 Dec 2013

    The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.

    Source:RedTeam Pentesting GmbH
    Published:5 Jul 2007
    9.8
    Critical

    CVE-2007-3010

    Last Modified: 6 Mar 2011

    masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

    Source:Metasploit
    Published:18 Sept 2007
    4.3
    Medium

    CVE-2007-3009

    Last Modified: 10 Dec 2013

    Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.

    Source:Nir Rachmel
    Published:4 Jun 2007
    6.8
    Medium

    CVE-2007-3006

    Last Modified: 23 Apr 2026

    Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. NOTE: it was later claimed that 4.51 Build 147 is also affected.

    Source:n00b
    Published:4 Jun 2007
    7.5
    High

    CVE-2007-3003

    Last Modified: 8 Dec 2013

    Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225.

    Published:4 Jun 2007
    4.3
    Medium

    CVE-2007-3001

    Last Modified: 8 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the sUName parameter to UserArea/Authenticate.php, (2) the sAccountUnq parameter to UserArea/NewAccounts/index.php, or the (3) iCategoryUnq, (4) iDBLoc, (5) iTtlNumItems, (6) iNumPerPage, or (7) sSort parameter to G_Display.php, different vectors than CVE-2005-4239.

    Source:laurent gaffie
    Published:4 Jun 2007
    7.5
    High

    CVE-2007-3000

    Last Modified: 8 Dec 2013

    Multiple SQL injection vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to execute arbitrary SQL commands via (1) the iCategoryUnq parameter to G_Display.php or (2) the iSearchID parameter to Search/DisplayResults.php.

    Source:laurent gaffie
    Published:4 Jun 2007
    4.3
    Medium

    CVE-2007-2991

    Last Modified: 8 Dec 2013

    Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Glafkos Charalambous
    Published:4 Jun 2007
    7.5
    High

    CVE-2007-2988

    Last Modified: 23 Apr 2026

    A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.

    Source:BlackHawk
    Published:1 Jun 2007
    9.3
    Critical

    CVE-2007-2987

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods.

    Source:shinnai
    Published:1 Jun 2007
    7.5
    High

    CVE-2007-2986

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter.

    Source:ThE TiGeR
    Published:1 Jun 2007
    10
    Critical

    CVE-2007-2985

    Last Modified: 23 Apr 2026

    Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

    Source:Silentz
    Published:1 Jun 2007
    9.3
    Critical

    CVE-2007-2983

    Last Modified: 7 Dec 2013

    Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.

    Source:Will Dormann
    Published:25 Oct 2007
    9.3
    Critical

    CVE-2007-2981

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.

    Source:shinnai
    Published:1 Jun 2007
    6.8
    Medium

    CVE-2007-2980

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827.

    Source:shinnai
    Published:1 Jun 2007