7.5
    High

    CVE-2007-2737

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ajann
    Published:17 May 2007
    10
    Critical

    CVE-2007-2736

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

    Source:Katatafish
    Published:17 May 2007
    7.5
    High

    CVE-2007-2735

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id_reserv parameter.

    Source:ajann
    Published:17 May 2007
    6.8
    Medium

    CVE-2007-2732

    Last Modified: 5 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.

    Source:Mikhail Markin
    Published:16 May 2007
    7.8
    High

    CVE-2007-2726

    Last Modified: 23 Apr 2026

    BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns.

    Source:gbr
    Published:16 May 2007
    7.5
    High

    CVE-2007-2725

    Last Modified: 23 Apr 2026

    The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function.

    Source:shinnai
    Published:16 May 2007
    7.8
    High

    CVE-2007-2722

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence.

    Source:gbr
    Published:16 May 2007
    4.3
    Medium

    CVE-2007-2718

    Last Modified: 4 Dec 2013

    Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.

    Source:Alla Bezroutchko
    Published:16 May 2007
    7.5
    High

    CVE-2007-2717

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.

    Source:gsy
    Published:16 May 2007
    6.8
    Medium

    CVE-2007-2716

    Last Modified: 2 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) listmembers.php and (2) stats.php. NOTE: some of these details are obtained from third party information.

    Source:kefka
    Published:16 May 2007
    10
    Critical

    CVE-2007-2715

    Last Modified: 23 Apr 2026

    Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

    Source:Dj7xpl
    Published:16 May 2007
    10
    Critical

    CVE-2007-2714

    Last Modified: 22 Nov 2017

    Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors.

    Source:David Kierznowski
    Published:16 May 2007
    10
    Critical

    CVE-2007-2711

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.

    Source:Thomas Pollet
    Published:16 May 2007
    7.5
    High

    CVE-2007-2710

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ThE TiGeR
    Published:16 May 2007
    7.5
    High

    CVE-2007-2709

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.

    Source:ThE TiGeR
    Published:16 May 2007
    7.5
    High

    CVE-2007-2708

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

    Source:Mogatil
    Published:16 May 2007
    6.8
    Medium

    CVE-2007-2707

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.

    Source:ThE TiGeR
    Published:16 May 2007
    7.5
    High

    CVE-2007-2706

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter.

    Source:ThE TiGeR
    Published:16 May 2007
    4.3
    Medium

    CVE-2007-2686

    Last Modified: 6 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.

    Source:Jesper Jurcenoks
    Published:22 May 2007
    7.5
    High

    CVE-2007-2685

    Last Modified: 6 Dec 2013

    Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.

    Source:Jesper Jurcenoks
    Published:21 May 2007
    3.5
    Low

    CVE-2007-2683

    Last Modified: 7 Dec 2013

    Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.

    Source:raylai
    Published:11 May 2007
    7.5
    High

    CVE-2007-2678

    Last Modified: 23 Apr 2026

    Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecified vectors.

    Source:Umesh Wanve
    Published:15 May 2007
    7.5
    High

    CVE-2007-2677

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2) layout_admin_cfg.php, (3) layout_cfg.php, or (4) layout_t_top.php in skins/phpchess/. NOTE: vector 1 has been disputed by CVE, since the code is defined within a function that is not called from within includes/language.php.

    Source:GoLd_M
    Published:14 May 2007
    7.5
    High

    CVE-2007-2676

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter.

    Source:GoLd_M
    Published:14 May 2007
    7.5
    High

    CVE-2007-2675

    Last Modified: 17 Mar 2012

    SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:r45c4l
    Published:14 May 2007
    7.5
    High

    CVE-2007-2674

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.

    Source:Mehmet Ince
    Published:14 May 2007
    7.5
    High

    CVE-2007-2673

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.

    Source:Mehmet Ince
    Published:14 May 2007
    7.5
    High

    CVE-2007-2672

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a viewbus page.

    Source:Mehmet Ince
    Published:14 May 2007
    7.1
    High

    CVE-2007-2671

    Last Modified: 1 Dec 2013

    Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.

    Source:Carl Hardwick
    Published:14 May 2007
    6.8
    Medium

    CVE-2007-2668

    Last Modified: 5 Dec 2016

    Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c.

    Source:Xpl017Elz
    Published:14 May 2007
    9.3
    Critical

    CVE-2007-2667

    Last Modified: 23 Apr 2026

    Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter.

    Source:rgod
    Published:14 May 2007
    7.6
    High

    CVE-2007-2666

    Last Modified: 31 Jan 2017

    Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.

    Source:vade79
    Published:14 May 2007
    7.5
    High

    CVE-2007-2665

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.

    Source:Dj7xpl
    Published:14 May 2007
    7.5
    High

    CVE-2007-2664

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, possibly related to the __autoload function.

    Source:3l3ctric-Cracker
    Published:14 May 2007
    7.5
    High

    CVE-2007-2663

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter.

    Source:ThE TiGeR
    Published:14 May 2007
    7.5
    High

    CVE-2007-2662

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI.

    Source:CyberGhost
    Published:14 May 2007
    7.5
    High

    CVE-2007-2661

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via the var parameter, a different vector than CVE-2006-5976.

    Source:gsy
    Published:14 May 2007
    6.8
    Medium

    CVE-2007-2660

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this issue since there is no include statement in pcltrace.lib.php. NOTE: the pcltar.lib.php vector is already covered by CVE-2007-2199

    Source:Mogatil
    Published:14 May 2007
    5
    Medium

    CVE-2007-2659

    Last Modified: 5 Oct 2016

    Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter in a downloadfile action.

    Source:Ali.Mohajem
    Published:14 May 2007
    7.8
    High

    CVE-2007-2658

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a denial of service via a long argument to the SaveEnhWMF method.

    Source:shinnai
    Published:14 May 2007
    7.8
    High

    CVE-2007-2657

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of service via a long argument to the SaveBarCode method.

    Source:shinnai
    Published:14 May 2007
    7.8
    High

    CVE-2007-2656

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile method.

    Source:callAX
    Published:14 May 2007
    9.3
    Critical

    CVE-2007-2648

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function.

    Source:shinnai
    Published:14 May 2007
    6.5
    Medium

    CVE-2007-2647

    Last Modified: 5 Oct 2016

    Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code into the conf/config.inc.php file via the (1) gadm_pass, (2) gadm_user, (3) gcfgHote, (4) gcfgPass, (5) gcfgUser, (6) gclassement_rep, (7) gcontour, (8) gfond, (9) ggd_version, (10) ghome, (11) ghor, (12) gimg_copyright, (13) glangage, (14) gmenu_visible, (15) gmini_hasard, (16) gordre_rep, (17) gpage, (18) gracine, (19) grech_inactive, (20) grep_mini, (21) grepertoire, (22) gsite, (23) gslide, (24) gtitre, (25) guse_copyright, (26) gversion, (27) gvert, or (28) gcfgBase parameter.

    Source:Dj7xpl
    Published:14 May 2007
    9.3
    Critical

    CVE-2007-2645

    Last Modified: 7 Dec 2013

    Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.

    Source:Victor Stinner
    Published:14 May 2007
    9.4
    Critical

    CVE-2007-2644

    Last Modified: 28 Apr 2011

    A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.

    Source:shinnai
    Published:13 May 2007
    5
    Medium

    CVE-2007-2643

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.

    Source:Dj7xpl
    Published:13 May 2007
    7.8
    High

    CVE-2007-2642

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter.

    Source:Dj7xpl
    Published:13 May 2007
    7.5
    High

    CVE-2007-2641

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter, a different vector than CVE-2007-0920.

    Source:gsy
    Published:13 May 2007
    10
    Critical

    CVE-2007-2639

    Last Modified: 4 Dec 2013

    Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.

    Source:Digital Defense
    Published:13 May 2007