4.3
    Medium

    CVE-2007-2300

    Last Modified: 13 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.

    Source:the_Edit0r
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2299

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536.

    Source:Kacper
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2298

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.

    Source:GoLd_M
    Published:26 Apr 2007
    7.6
    High

    CVE-2007-2293

    Last Modified: 29 Nov 2013

    Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.

    Source:Barrie Dempster
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2290

    Last Modified: 29 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.

    Source:alijsb
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2288

    Last Modified: 30 Nov 2013

    PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:Ali7
    Published:26 Apr 2007
    7.5
    High

    CVE-2007-2287

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

    Source:alijsb
    Published:26 Apr 2007
    7.8
    High

    CVE-2007-2285

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.

    Source:Alkomandoz Hacker
    Published:26 Apr 2007
    9.3
    Critical

    CVE-2007-2284

    Last Modified: 24 Sept 2010

    Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.

    Source:Marsu
    Published:26 Apr 2007
    9.3
    Critical

    CVE-2007-2283

    Last Modified: 23 Apr 2026

    Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.

    Source:Marsu
    Published:26 Apr 2007
    10
    Critical

    CVE-2007-2280

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.

    Source:Metasploit
    Published:18 Dec 2009
    7.8
    High

    CVE-2007-2274

    Last Modified: 30 Sept 2016

    The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain.

    Source:n00b
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2273

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.

    Source:kezzap66345
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2272

    Last Modified: 7 Dec 2016

    PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.

    Source:DamaR
    Published:25 Apr 2007
    9.4
    Critical

    CVE-2007-2271

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.

    Source:GoLd_M
    Published:25 Apr 2007
    7.8
    High

    CVE-2007-2270

    Last Modified: 23 Apr 2026

    The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.

    Source:MADYNES
    Published:25 Apr 2007
    5
    Medium

    CVE-2007-2268

    Last Modified: 5 Sept 2016

    Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.

    Source:anonymous
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2262

    Last Modified: 28 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as "File117".

    Source:InyeXion
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2259

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.

    Source:ilker Kandemir
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2258

    Last Modified: 28 Nov 2013

    PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Source:MoHaNdKo
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2257

    Last Modified: 28 Nov 2013

    PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:HACKERS PAL
    Published:25 Apr 2007
    4.3
    Medium

    CVE-2007-2256

    Last Modified: 28 Nov 2013

    Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Source:the_Edit0r
    Published:25 Apr 2007
    5
    Medium

    CVE-2007-2252

    Last Modified: 28 Nov 2013

    Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.

    Source:Hamid Ebadi
    Published:25 Apr 2007
    5
    Medium

    CVE-2007-2250

    Last Modified: 29 Nov 2013

    admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.

    Source:Janek Vind
    Published:25 Apr 2007
    6.5
    Medium

    CVE-2007-2249

    Last Modified: 29 Nov 2013

    include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.

    Source:Janek Vind
    Published:25 Apr 2007
    4.3
    Medium

    CVE-2007-2248

    Last Modified: 29 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.

    Source:Janek Vind
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2247

    Last Modified: 29 Nov 2013

    SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:John Martinelli
    Published:25 Apr 2007
    9.3
    Critical

    CVE-2007-2244

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.

    Source:Marsu
    Published:25 Apr 2007
    9.3
    Critical

    CVE-2007-2239

    Last Modified: 5 Oct 2016

    Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.

    Source:shinnai
    Published:7 May 2007
    9.3
    Critical

    CVE-2007-2238

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.

    Source:Metasploit
    Published:16 Apr 2009
    5.5
    Medium

    CVE-2007-2237

    Last Modified: 23 Apr 2026

    Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

    Source:Kad
    Published:6 Jun 2007
    6.5
    Medium

    CVE-2007-2233

    Last Modified: 27 Nov 2013

    cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.

    Source:Jon Oberheide
    Published:25 Apr 2007
    7.5
    High

    CVE-2007-2232

    Last Modified: 27 Nov 2013

    The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.

    Source:Jon Oberheide
    Published:25 Apr 2007
    9.3
    Critical

    CVE-2007-2223

    Last Modified: 25 Dec 2013

    Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

    Source:anonymous
    Published:14 Aug 2007
    9.3
    Critical

    CVE-2007-2222

    Last Modified: 28 Apr 2011

    Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.

    Source:rgod
    Published:12 Jun 2007
    9.3
    Critical

    CVE-2007-2221

    Last Modified: 5 Oct 2016

    Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the "Arbitrary File Rewrite Vulnerability."

    Source:Andres Tarasco
    Published:8 May 2007
    9.3
    Critical

    CVE-2007-2217

    Last Modified: 23 Apr 2026

    Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.

    Source:Gil-Dong / Woo-Chi
    Published:9 Oct 2007
    9.3
    Critical

    CVE-2007-2216

    Last Modified: 25 Dec 2013

    The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."

    Source:Brett Moore
    Published:14 Aug 2007
    7.5
    High

    CVE-2007-2212

    Last Modified: 9 Nov 2016

    Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:0x86
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2211

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.

    Source:0x86
    Published:24 Apr 2007
    7.8
    High

    CVE-2007-2210

    Last Modified: 28 Nov 2013

    A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to "improper memory handling," possibly a buffer overflow.

    Source:Michal Bucko
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2209

    Last Modified: 23 Apr 2026

    Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources.

    Source:Marsu
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2207

    Last Modified: 28 Nov 2013

    SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.

    Source:John Martinelli
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2205

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

    Source:InyeXion
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2204

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.

    Source:ThE TiGeR
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2202

    Last Modified: 29 Nov 2013

    PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.

    Source:MoHaNdKo
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2201

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.

    Source:InyeXion
    Published:24 Apr 2007
    10
    Critical

    CVE-2007-2200

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.

    Source:GoLd_M
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2199

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

    Source:Mogatil
    Published:24 Apr 2007
    5
    Medium

    CVE-2007-2195

    Last Modified: 28 Nov 2013

    aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.

    Source:Levent Kayan
    Published:24 Apr 2007