7.8
    High

    CVE-2007-2539

    Last Modified: 28 Nov 2016

    The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.

    Source:rgod
    Published:9 May 2007
    7.5
    High

    CVE-2007-2538

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter.

    Source:rgod
    Published:9 May 2007
    6.5
    Medium

    CVE-2007-2537

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the X-Forwarded-For (X_FORWARDED_FOR) HTTP header.

    Source:Gu1ll4um3r0m41n
    Published:9 May 2007
    7.8
    High

    CVE-2007-2536

    Last Modified: 7 Oct 2017

    PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

    Source:Jean-Sébastien
    Published:9 May 2007
    4.3
    Medium

    CVE-2007-2532

    Last Modified: 1 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734.

    Source:CorryL
    Published:9 May 2007
    7.5
    High

    CVE-2007-2531

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a URL in the beryliumroot parameter.

    Source:ThE TiGeR
    Published:9 May 2007
    7.5
    High

    CVE-2007-2530

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL in the RESPATH parameter to (1) dosearch.php or (2) printfriendly.php.

    Source:kezzap66345
    Published:9 May 2007
    7.5
    High

    CVE-2007-2527

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the HomeDir parameter to (1) dp_logs.php or (2) index.php.

    Source:ThE TiGeR
    Published:8 May 2007
    9.3
    Critical

    CVE-2007-2526

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode VNC Manager 3.6 allows remote attackers to execute arbitrary code via a long argument.

    Source:shinnai
    Published:8 May 2007
    4.3
    Medium

    CVE-2007-2524

    Last Modified: 2 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.

    Source:ciri
    Published:8 May 2007
    7.2
    High

    CVE-2007-2523

    Last Modified: 4 Dec 2013

    CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a stack-based buffer overflow in InoCore.dll before 8.0.448.0.

    Source:binagres
    Published:11 May 2007
    7.5
    High

    CVE-2007-2521

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter.

    Source:kezzap66345
    Published:8 May 2007
    6.8
    Medium

    CVE-2007-2520

    Last Modified: 12 Dec 2013

    SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.

    Source:netVigilance
    Published:26 Jun 2007
    6.8
    Medium

    CVE-2007-2519

    Last Modified: 6 Dec 2013

    Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.

    Source:Gregory Beaver
    Published:22 May 2007
    10
    Critical

    CVE-2007-2508

    Last Modified: 6 Mar 2011

    Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.

    Source:Metasploit
    Published:8 May 2007
    7.8
    High

    CVE-2007-2507

    Last Modified: 21 Nov 2016

    Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter.

    Source:Dj7xpl
    Published:4 May 2007
    7.8
    High

    CVE-2007-2506

    Last Modified: 15 Nov 2017

    WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.

    Source:Eelko Neven
    Published:4 May 2007
    10
    Critical

    CVE-2007-2503

    Last Modified: 28 Nov 2013

    Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion

    Source:Omni
    Published:4 May 2007
    9.3
    Critical

    CVE-2007-2498

    Last Modified: 3 Oct 2016

    libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information.

    Source:Marsu
    Published:4 May 2007
    7.8
    High

    CVE-2007-2497

    Last Modified: 30 Sept 2016

    RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue was referred to as a "memory leak," but it is not clear if this is correct.

    Source:n00b
    Published:4 May 2007
    7.8
    High

    CVE-2007-2496

    Last Modified: 23 Apr 2026

    The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.

    Source:shinnai
    Published:4 May 2007
    7.5
    High

    CVE-2007-2495

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:4 May 2007
    10
    Critical

    CVE-2007-2494

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:4 May 2007
    10
    Critical

    CVE-2007-2493

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:bd0rk
    Published:4 May 2007
    7.5
    High

    CVE-2007-2492

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.

    Source:Ali Abbasi
    Published:4 May 2007
    7.5
    High

    CVE-2007-2487

    Last Modified: 12 Jul 2017

    Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287.

    Source:preth00nker
    Published:3 May 2007
    5
    Medium

    CVE-2007-2486

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter.

    Source:Dj7xpl
    Published:3 May 2007
    7.5
    High

    CVE-2007-2485

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Source:Crackers_Child
    Published:3 May 2007
    6.8
    Medium

    CVE-2007-2484

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Source:K-159
    Published:3 May 2007
    6.8
    Medium

    CVE-2007-2483

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.

    Source:K-159
    Published:3 May 2007
    6.8
    Medium

    CVE-2007-2482

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.

    Source:K-159
    Published:3 May 2007
    6.8
    Medium

    CVE-2007-2481

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Source:K-159
    Published:3 May 2007
    7.5
    High

    CVE-2007-2474

    Last Modified: 20 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.

    Source:s3rv3r_hack3r
    Published:2 May 2007
    7.5
    High

    CVE-2007-2473

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.

    Source:Daniel Lucq
    Published:2 May 2007
    5
    Medium

    CVE-2007-2471

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter.

    Source:ettee
    Published:2 May 2007
    7.5
    High

    CVE-2007-2458

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.

    Source:irvian
    Published:2 May 2007
    7.5
    High

    CVE-2007-2457

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.

    Source:irvian
    Published:2 May 2007
    7.5
    High

    CVE-2007-2456

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.

    Source:Alkomandoz Hacker
    Published:2 May 2007
    4.3
    Medium

    CVE-2007-2449

    Last Modified: 10 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

    Source:anonymous
    Published:13 Jun 2007
    6
    Medium

    CVE-2007-2447

    Last Modified: 6 Sept 2017

    The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

    Source:Metasploit
    Published:14 May 2007
    10
    Critical

    CVE-2007-2446

    Last Modified: 23 Sept 2016

    Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).

    Source:Adriano Lima
    Published:14 May 2007
    5
    Medium

    CVE-2007-2441

    Last Modified: 5 Dec 2013

    Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.

    Source:Derek Abdine
    Published:16 May 2007
    5
    Medium

    CVE-2007-2440

    Last Modified: 5 Dec 2013

    Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a "\web-inf" sequence.

    Source:Derek Abdine
    Published:16 May 2007
    5.5
    Medium

    CVE-2007-2437

    Last Modified: 1 Dec 2013

    The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.

    Source:Derek Abdine
    Published:2 May 2007
    10
    Critical

    CVE-2007-2434

    Last Modified: 1 Dec 2013

    Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query.

    Source:Thomas Pollet
    Published:2 May 2007
    6.8
    Medium

    CVE-2007-2431

    Last Modified: 23 Apr 2026

    Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.

    Source:rgod
    Published:2 May 2007
    7.8
    High

    CVE-2007-2430

    Last Modified: 23 Apr 2026

    shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.

    Source:rgod
    Published:2 May 2007
    10
    Critical

    CVE-2007-2429

    Last Modified: 30 Nov 2013

    ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:anonymous
    Published:2 May 2007
    7.5
    High

    CVE-2007-2428

    Last Modified: 29 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.

    Source:CodeXpLoder'tq
    Published:2 May 2007
    7.5
    High

    CVE-2007-2427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Mehmet Ince
    Published:2 May 2007