6.8
    Medium

    CVE-2007-2634

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ThE TiGeR
    Published:13 May 2007
    6.8
    Medium

    CVE-2007-2632

    Last Modified: 4 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[].

    Source:the_Edit0r
    Published:13 May 2007
    7.5
    High

    CVE-2007-2628

    Last Modified: 1 Dec 2013

    PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityAdmin, PSA) 4.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter.

    Source:ilker Kandemir
    Published:11 May 2007
    7.8
    High

    CVE-2007-2623

    Last Modified: 28 Apr 2011

    Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via (1) a long first argument to the connect function or (2) a long InternalServer property value, possibly involving ntdll.dll.

    Source:shinnai
    Published:11 May 2007
    7.5
    High

    CVE-2007-2622

    Last Modified: 1 Nov 2017

    Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login.php or (2) the taskid parameter to notes.php.

    Source:Silentz
    Published:11 May 2007
    7.5
    High

    CVE-2007-2621

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter.

    Source:warlord
    Published:11 May 2007
    7.5
    High

    CVE-2007-2620

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the x[1] parameter.

    Source:GoLd_M
    Published:11 May 2007
    2.1
    Low

    CVE-2007-2617

    Last Modified: 4 Dec 2013

    srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.

    Source:anonymous
    Published:11 May 2007
    7.5
    High

    CVE-2007-2615

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_local parameter to (1) ftp.php, (2) libs/db.php, and (3) libs/ftp.php.

    Source:GoLd_M
    Published:11 May 2007
    6.8
    Medium

    CVE-2007-2611

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX parameter to (1) mtdialogo.php, (2) ltdialogo.php, (3) login.php, and (4) logingecon.php in inc/; and multiple unspecified files in frm/, sql/, and cns/.

    Source:GoLd_M
    Published:11 May 2007
    7.5
    High

    CVE-2007-2609

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR parameter to (1) libs/lom.php; (2) lom_update.php, (3) check-lom.php, and (4) weigh_keywords.php in scripts/; the (b) LIBSDIR parameter to (5) logout.php, (6) help.php, (7) index.php, (8) login.php; and the ETCDIR parameter to (9) web/lom.php.

    Source:GoLd_M
    Published:11 May 2007
    7.5
    High

    CVE-2007-2608

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via a URL in the system[smarty][dir] parameter.

    Source:ThE TiGeR
    Published:11 May 2007
    7.5
    High

    CVE-2007-2607

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter.

    Source:kezzap66345
    Published:11 May 2007
    6.8
    Medium

    CVE-2007-2600

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.

    Source:Silentz
    Published:11 May 2007
    7.5
    High

    CVE-2007-2599

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or (3) the search parameter to search.php.

    Source:Silentz
    Published:11 May 2007
    10
    Critical

    CVE-2007-2598

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:Silentz
    Published:11 May 2007
    7.5
    High

    CVE-2007-2597

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) ordnertiefe parameter to site_conf.php; or the (2) tt_docroot parameter to (a) class.csv.php, (b) produkte_nach_serie.php, or (c) ref_kd_rubrik.php in functionen/; (d) hg_referenz_jobgalerie.php, (e) surfer_anmeldung_NWL.php, (f) produkte_nach_serie_alle.php, (g) surfer_aendern.php, (h) ref_kd_rubrik.php, or (i) referenz.php in module/; or (j) 1/lay.php or (k) 3/lay.php in standard/.

    Source:GoLd_M
    Published:11 May 2007
    7.5
    High

    CVE-2007-2596

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter.

    Source:ThE TiGeR
    Published:11 May 2007
    7.5
    High

    CVE-2007-2594

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CHEMINMODULES] parameter.

    Source:GoLd_M
    Published:11 May 2007
    9.3
    Critical

    CVE-2007-2588

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) HttpDownloadFile, (2) Open, (3) OpenWebFile, (4) DoOleCommand, (5) FTPDownloadFile, (6) FTPUploadFile, (7) HttpUploadFile, (8) Save, or (9) SaveWebFile function.

    Source:shinnai
    Published:9 May 2007
    9.3
    Critical

    CVE-2007-2586

    Last Modified: 22 Jun 2017

    The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

    Source:Andy Davis
    Published:9 May 2007
    9.3
    Critical

    CVE-2007-2585

    Last Modified: 29 Sept 2016

    Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument.

    Source:shinnai
    Published:9 May 2007
    10
    Critical

    CVE-2007-2584

    Last Modified: 23 Apr 2026

    Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument.

    Source:Jambalaya
    Published:9 May 2007
    4
    Medium

    CVE-2007-2583

    Last Modified: 4 Dec 2013

    The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.

    Source:Neil Kettle
    Published:29 Mar 2007
    4.3
    Medium

    CVE-2007-2581

    Last Modified: 1 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.

    Source:Solarius
    Published:9 May 2007
    1.9
    Low

    CVE-2007-2580

    Last Modified: 22 Nov 2017

    Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.

    Source:poplix
    Published:9 May 2007
    6.8
    Medium

    CVE-2007-2576

    Last Modified: 23 Apr 2026

    Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a long OpenDVD property value. NOTE: this issue might be related to CVE-2007-0976.

    Source:shinnai
    Published:9 May 2007
    7.5
    High

    CVE-2007-2575

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.

    Source:ThE TiGeR
    Published:9 May 2007
    5
    Medium

    CVE-2007-2574

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter.

    Source:Dj7xpl
    Published:9 May 2007
    7.5
    High

    CVE-2007-2573

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter.

    Source:ThE TiGeR
    Published:9 May 2007
    7.5
    High

    CVE-2007-2572

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter.

    Source:kezzap66345
    Published:9 May 2007
    7.5
    High

    CVE-2007-2571

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.

    Source:Mehmet Ince
    Published:9 May 2007
    7.5
    High

    CVE-2007-2570

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the sous_rep parameter.

    Source:GoLd_M
    Published:9 May 2007
    7.5
    High

    CVE-2007-2569

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.

    Source:GoLd_M
    Published:9 May 2007
    9.3
    Critical

    CVE-2007-2568

    Last Modified: 3 Mar 2014

    Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track type in a CUE file.

    Source:Provensec
    Published:16 May 2007
    5
    Medium

    CVE-2007-2566

    Last Modified: 27 Apr 2011

    The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package.

    Source:Umesh Wanve
    Published:9 May 2007
    7.1
    High

    CVE-2007-2565

    Last Modified: 15 Nov 2017

    Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file.

    Source:Dr.Ninux
    Published:9 May 2007
    9.3
    Critical

    CVE-2007-2563

    Last Modified: 27 Oct 2016

    Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.

    Source:shinnai
    Published:9 May 2007
    7.5
    High

    CVE-2007-2561

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115.

    Source:ilker Kandemir
    Published:9 May 2007
    5
    Medium

    CVE-2007-2560

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rubrik parameter.

    Source:BeyazKurt
    Published:9 May 2007
    7.5
    High

    CVE-2007-2556

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI.

    Source:DarkFig
    Published:9 May 2007
    7.2
    High

    CVE-2007-2553

    Last Modified: 4 Dec 2013

    Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.

    Source:Daniele Calore
    Published:9 May 2007
    7.5
    High

    CVE-2007-2549

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.

    Source:John Martinelli
    Published:9 May 2007
    4.3
    Medium

    CVE-2007-2547

    Last Modified: 20 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.

    Source:John Martinelli
    Published:9 May 2007
    7.5
    High

    CVE-2007-2545

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/.

    Source:GoLd_M
    Published:9 May 2007
    7.5
    High

    CVE-2007-2544

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the right_file parameter.

    Source:kezzap66345
    Published:9 May 2007
    7.5
    High

    CVE-2007-2543

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Source:Mehmet Ince
    Published:9 May 2007
    7.5
    High

    CVE-2007-2542

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:kezzap66345
    Published:9 May 2007
    7.5
    High

    CVE-2007-2541

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a URL in the urlModulo parameter.

    Source:kezzap66345
    Published:9 May 2007
    7.5
    High

    CVE-2007-2540

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[pathMod] parameter to index.php in (1) mod/image/, (2) mod/liens/, (3) mod/liste/, (4) mod/special/, or (5) mod/texte/.

    Source:GoLd_M
    Published:9 May 2007