7.5
    High

    CVE-2007-2426

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.

    Source:GoLd_M
    Published:2 May 2007
    5
    Medium

    CVE-2007-2425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter.

    Source:DNX
    Published:2 May 2007
    7.5
    High

    CVE-2007-2424

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter.

    Source:kezzap66345
    Published:2 May 2007
    5.8
    Medium

    CVE-2007-2423

    Last Modified: 30 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:En Douli
    Published:2 May 2007
    7.5
    High

    CVE-2007-2420

    Last Modified: 30 Nov 2013

    SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:RMx
    Published:2 May 2007
    7.5
    High

    CVE-2007-2416

    Last Modified: 1 Dec 2013

    SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter.

    Source:ilkerkandemir
    Published:1 May 2007
    4.3
    Medium

    CVE-2007-2401

    Last Modified: 12 Dec 2013

    CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.

    Source:Richard Moore
    Published:25 Jun 2007
    9.3
    Critical

    CVE-2007-2394

    Last Modified: 19 Oct 2016

    Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.

    Source:David Vaartjes
    Published:15 Jul 2007
    9.4
    Critical

    CVE-2007-2386

    Last Modified: 6 Mar 2011

    Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.

    Source:Metasploit
    Published:24 May 2007
    7.5
    High

    CVE-2007-2373

    Last Modified: 30 Sept 2016

    SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:30 Apr 2007
    10
    Critical

    CVE-2007-2372

    Last Modified: 23 Nov 2016

    admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.

    Source:BlackHawk
    Published:30 Apr 2007
    10
    Critical

    CVE-2007-2371

    Last Modified: 23 Nov 2016

    admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.

    Source:BlackHawk
    Published:30 Apr 2007
    7.5
    High

    CVE-2007-2370

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.

    Source:ajann
    Published:30 Apr 2007
    5
    Medium

    CVE-2007-2369

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Source:Trex
    Published:30 Apr 2007
    5
    Medium

    CVE-2007-2368

    Last Modified: 23 Apr 2026

    picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.

    Source:Trex
    Published:30 Apr 2007
    10
    Critical

    CVE-2007-2367

    Last Modified: 27 Apr 2011

    Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.

    Source:WiLdBoY
    Published:30 Apr 2007
    7.4
    High

    CVE-2007-2366

    Last Modified: 23 Apr 2026

    Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

    Source:Marsu
    Published:30 Apr 2007
    9.3
    Critical

    CVE-2007-2365

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

    Source:Marsu
    Published:30 Apr 2007
    7.5
    High

    CVE-2007-2364

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/.

    Source:GoLd_M
    Published:30 Apr 2007
    8.5
    High

    CVE-2007-2363

    Last Modified: 31 Oct 2016

    Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.

    Source:fl0 fl0w
    Published:30 Apr 2007
    9
    Critical

    CVE-2007-2362

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.

    Source:mu-b
    Published:30 Apr 2007
    6.8
    Medium

    CVE-2007-2356

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.

    Source:Marsu
    Published:27 Apr 2007
    5
    Medium

    CVE-2007-2353

    Last Modified: 30 Nov 2013

    Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

    Published:30 Apr 2007
    7.5
    High

    CVE-2007-2347

    Last Modified: 13 Dec 2016

    PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

    Source:kezzap66345
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2346

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php.

    Source:bd0rk
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2345

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:kezzap66345
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.

    Source:CyberGhost
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2341

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.

    Source:koray
    Published:27 Apr 2007
    6.8
    Medium

    CVE-2007-2340

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.

    Source:Alkomandoz Hacker
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2339

    Last Modified: 29 Nov 2013

    Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.

    Source:Janek Vind
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2338

    Last Modified: 29 Nov 2013

    Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.

    Source:Janek Vind
    Published:27 Apr 2007
    4.3
    Medium

    CVE-2007-2337

    Last Modified: 28 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in external/magpierss/scripts/, the (2) rss_url parameter to (c) magpie_slashbox.php in external/magpierss/scripts/, and the (3) body parameter to the (d) weblogmodule (aka Weblog Comments) module.

    Source:Hamid Ebadi
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2330

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Source:alijsb
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2327

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.

    Source:alijsb
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2326

    Last Modified: 29 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.

    Source:alijsb
    Published:27 Apr 2007
    10
    Critical

    CVE-2007-2325

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.

    Source:Ali & Saeid
    Published:27 Apr 2007
    7.8
    High

    CVE-2007-2324

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:GoLd_M
    Published:27 Apr 2007
    7.5
    High

    CVE-2007-2320

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.

    Source:Kacper
    Published:26 Apr 2007
    6.8
    Medium

    CVE-2007-2319

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.

    Source:Cold Zero
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2317

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.

    Source:Cold Zero
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2313

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Source:bd0rk
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2312

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement.

    Source:brOmstar
    Published:26 Apr 2007
    4.3
    Medium

    CVE-2007-2310

    Last Modified: 27 Nov 2013

    Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.

    Source:the_Edit0r
    Published:26 Apr 2007
    4.3
    Medium

    CVE-2007-2308

    Last Modified: 27 Nov 2013

    Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.

    Source:the_Edit0r
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2307

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.

    Source:GoLd_M
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2305

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:Omni
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2304

    Last Modified: 27 Oct 2016

    Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.

    Source:GoLd_M
    Published:26 Apr 2007
    6.8
    Medium

    CVE-2007-2303

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

    Source:BeyazKurt
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2302

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.

    Source:mdx
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2301

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.

    Source:GoLd_M
    Published:26 Apr 2007