7.2
    High

    CVE-2007-2839

    Last Modified: 13 Dec 2013

    gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

    Source:Steve Kemp
    Published:5 Jul 2007
    4.3
    Medium

    CVE-2007-2832

    Last Modified: 6 Dec 2013

    Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.

    Source:Marc Ruef
    Published:24 May 2007
    9.3
    Critical

    CVE-2007-2827

    Last Modified: 24 Jan 2017

    Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.

    Source:shinnai
    Published:22 May 2007
    7.5
    High

    CVE-2007-2826

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter.

    Source:BoZKuRTSeRDaR
    Published:22 May 2007
    10
    Critical

    CVE-2007-2824

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php.

    Source:BlackHawk
    Published:22 May 2007
    9.3
    Critical

    CVE-2007-2822

    Last Modified: 23 Apr 2026

    TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.

    Source:Silentz
    Published:22 May 2007
    7.5
    High

    CVE-2007-2821

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

    Source:waraxe
    Published:22 May 2007
    7.5
    High

    CVE-2007-2820

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary code via long arguments to the (1) SWAT_Init, (2) SWAT_InitEx, (3) SWAT_InitEx2, (4) SWAT_InitEx3, and (5) SWAT_Login functions.

    Source:KIM Kee-hong
    Published:22 May 2007
    7.5
    High

    CVE-2007-2817

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ThE TiGeR
    Published:22 May 2007
    7.5
    High

    CVE-2007-2816

    Last Modified: 22 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11) test6.php, (12) frames1_left.php, and (13) frames1_center.php in themes/.

    Source:ThE TiGeR
    Published:22 May 2007
    10
    Critical

    CVE-2007-2815

    Last Modified: 23 Apr 2026

    The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.

    Source:Sha0
    Published:22 May 2007
    7.5
    High

    CVE-2007-2814

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7) CopyBufToClipExA, (8) LoadEx, (9) LoadFox, and other functions.

    Source:rgod
    Published:22 May 2007
    10
    Critical

    CVE-2007-2810

    Last Modified: 30 Nov 2013

    SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ertuqrul
    Published:22 May 2007
    6.8
    Medium

    CVE-2007-2807

    Last Modified: 12 Oct 2016

    Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.

    Source:bangus/magnum
    Published:22 May 2007
    5.8
    Medium

    CVE-2007-2806

    Last Modified: 6 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters.

    Source:John Martinelli
    Published:22 May 2007
    4.3
    Medium

    CVE-2007-2805

    Last Modified: 5 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.

    Source:r0t
    Published:22 May 2007
    7.5
    High

    CVE-2007-2803

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a haberdetay action.

    Source:BAHADIR
    Published:22 May 2007
    4.3
    Medium

    CVE-2007-2801

    Last Modified: 13 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."

    Source:Jesper Jurcenoks
    Published:30 Jun 2007
    9
    Critical

    CVE-2007-2795

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.

    Source:dmc
    Published:27 Jan 2009
    7.5
    High

    CVE-2007-2793

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.

    Source:diesl0w
    Published:22 May 2007
    7.5
    High

    CVE-2007-2792

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:snakespc
    Published:22 May 2007
    10
    Critical

    CVE-2007-2791

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout.

    Source:bunker
    Published:22 May 2007
    6.8
    Medium

    CVE-2007-2788

    Last Modified: 7 Dec 2013

    Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.

    Source:Chris Evans
    Published:21 May 2007
    7.5
    High

    CVE-2007-2787

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument.

    Source:shinnai
    Published:21 May 2007
    10
    Critical

    CVE-2007-2783

    Last Modified: 5 Oct 2016

    Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. NOTE: this issue has no actionable information, and perhaps should not be included in CVE.

    Source:Ahmed Siddiqui
    Published:21 May 2007
    5
    Medium

    CVE-2007-2780

    Last Modified: 1 Dec 2016

    PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.

    Source:kefka
    Published:21 May 2007
    7.5
    High

    CVE-2007-2779

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.

    Source:Mehmet Ince
    Published:21 May 2007
    7.8
    High

    CVE-2007-2778

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts.

    Source:MurderSkillz
    Published:21 May 2007
    7.5
    High

    CVE-2007-2777

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.

    Source:BlackHawk
    Published:21 May 2007
    10
    Critical

    CVE-2007-2776

    Last Modified: 23 Apr 2026

    AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.

    Source:BlackHawk
    Published:21 May 2007
    10
    Critical

    CVE-2007-2775

    Last Modified: 23 Apr 2026

    AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.

    Source:BlackHawk
    Published:21 May 2007
    7.5
    High

    CVE-2007-2774

    Last Modified: 6 Feb 2026

    Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.

    Source:Mehmet Ince
    Published:21 May 2007
    7.5
    High

    CVE-2007-2773

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter.

    Source:NeoMorphS
    Published:21 May 2007
    7.8
    High

    CVE-2007-2772

    Last Modified: 23 Apr 2026

    (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.

    Source:Shirkdog
    Published:21 May 2007
    9.3
    Critical

    CVE-2007-2771

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property.

    Source:shinnai
    Published:21 May 2007
    9.3
    Critical

    CVE-2007-2770

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue.

    Source:h07
    Published:21 May 2007
    10
    Critical

    CVE-2007-2763

    Last Modified: 5 Dec 2013

    Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (DMM) 2.6.0.4 allows remote attackers to execute arbitrary code via a long string in the second argument, a different issue than CVE-2007-2564.

    Source:shinnai
    Published:18 May 2007
    7.5
    High

    CVE-2007-2762

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.

    Source:Alkomandoz Hacker
    Published:18 May 2007
    7.5
    High

    CVE-2007-2761

    Last Modified: 28 Apr 2011

    Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file.

    Source:n00b
    Published:18 May 2007
    6.8
    Medium

    CVE-2007-2757

    Last Modified: 26 Sept 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) wp-content/themes/redoable/searchloop.php or (2) wp-content/themes/redoable/header.php.

    Source:John Martinelli
    Published:18 May 2007
    10
    Critical

    CVE-2007-2755

    Last Modified: 23 Apr 2026

    The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744.

    Source:shinnai
    Published:17 May 2007
    5
    Medium

    CVE-2007-2753

    Last Modified: 5 Oct 2016

    RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb.

    Source:kerem125
    Published:17 May 2007
    6.4
    Medium

    CVE-2007-2752

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:kerem125
    Published:17 May 2007
    7.5
    High

    CVE-2007-2751

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php.

    Source:kezzap66345
    Published:17 May 2007
    7.5
    High

    CVE-2007-2750

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQL commands via the newsnr parameter.

    Source:Silentz
    Published:17 May 2007
    5
    Medium

    CVE-2007-2749

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.

    Source:Silentz
    Published:17 May 2007
    5
    Medium

    CVE-2007-2747

    Last Modified: 6 Dec 2013

    Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.

    Source:Jesus Roncero
    Published:17 May 2007
    7.5
    High

    CVE-2007-2744

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote attackers to cause a denial of service (Internet Explorer 6 crash), and possibly execute arbitrary code, via a long argument to the SaveBarCode method. NOTE: this issue might overlap CVE-2007-2657.

    Source:shinnai
    Published:17 May 2007
    7.5
    High

    CVE-2007-2743

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter.

    Source:BeyazKurt
    Published:17 May 2007
    7.5
    High

    CVE-2007-2738

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.

    Source:ajann
    Published:17 May 2007