10
    Critical

    CVE-2007-2194

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.

    Source:Marsu
    Published:24 Apr 2007
    9.3
    Critical

    CVE-2007-2193

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:24 Apr 2007
    9.3
    Critical

    CVE-2007-2192

    Last Modified: 23 Apr 2026

    Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.

    Source:Marsu
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2191

    Last Modified: 28 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

    Source:XenoMuta
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2189

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:24 Apr 2007
    10
    Critical

    CVE-2007-2187

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.

    Source:mu-b
    Published:24 Apr 2007
    5
    Medium

    CVE-2007-2186

    Last Modified: 23 Apr 2026

    Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

    Source:n00b
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2185

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.

    Source:GoLd_M
    Published:24 Apr 2007
    5
    Medium

    CVE-2007-2184

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter.

    Source:Dj7xpl
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2183

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.

    Source:Dj7xpl
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2182

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.

    Source:Dj7xpl
    Published:24 Apr 2007
    6.8
    Medium

    CVE-2007-2181

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.

    Source:g00ns
    Published:24 Apr 2007
    7.1
    High

    CVE-2007-2180

    Last Modified: 30 Sept 2016

    Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.

    Source:WiLdBoY
    Published:24 Apr 2007
    7.6
    High

    CVE-2007-2175

    Last Modified: 6 Mar 2011

    Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.

    Source:Metasploit
    Published:24 Apr 2007
    7.5
    High

    CVE-2007-2169

    Last Modified: 30 Sept 2016

    Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field. NOTE: an earlier report indicated that the add action can be reached through a request to index.php.

    Source:Dj7xpl
    Published:22 Apr 2007
    7.5
    High

    CVE-2007-2168

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Dj7xpl
    Published:22 Apr 2007
    7.5
    High

    CVE-2007-2167

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.

    Source:Dj7xpl
    Published:22 Apr 2007
    6.8
    Medium

    CVE-2007-2166

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter.

    Source:Alkomandoz Hacker
    Published:22 Apr 2007
    7.5
    High

    CVE-2007-2158

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.

    Source:Dj7xpl
    Published:19 Apr 2007
    7.8
    High

    CVE-2007-2157

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Dj7xpl
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2156

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.

    Source:GoLd_M
    Published:19 Apr 2007
    7.8
    High

    CVE-2007-2155

    Last Modified: 27 Nov 2013

    Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.

    Source:Dr.RoVeR
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2154

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.

    Source:Dj7xpl
    Published:19 Apr 2007
    10
    Critical

    CVE-2007-2149

    Last Modified: 23 Apr 2026

    Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain privileges by reading the files, and allows remote attackers to obtain credentials via a direct request for admin/options.php.

    Source:Gammarays
    Published:19 Apr 2007
    6.5
    Medium

    CVE-2007-2148

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

    Source:Gammarays
    Published:19 Apr 2007
    10
    Critical

    CVE-2007-2147

    Last Modified: 23 Apr 2026

    admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.

    Source:Gammarays
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2146

    Last Modified: 2 Jan 2017

    The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Dj7xpl
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2145

    Last Modified: 2 Jan 2017

    The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: some of these details are obtained from third party information.

    Source:Dj7xpl
    Published:19 Apr 2007
    6.8
    Medium

    CVE-2007-2144

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Cold Zero
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2143

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Cold Zero
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2142

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.

    Source:Alkomandoz Hacker
    Published:19 Apr 2007
    7.5
    High

    CVE-2007-2141

    Last Modified: 27 Apr 2011

    Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.

    Source:Gammarays
    Published:19 Apr 2007
    10
    Critical

    CVE-2007-2139

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.

    Source:Metasploit
    Published:25 Apr 2007
    6.8
    Medium

    CVE-2007-2098

    Last Modified: 28 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters.

    Source:the_Edit0r
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2094

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter.

    Source:Dj7xpl
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2093

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.

    Source:Gammarays
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2092

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Gammarays
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2091

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.

    Source:GoLd_M
    Published:18 Apr 2007
    6.8
    Medium

    CVE-2007-2090

    Last Modified: 27 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:the_Edit0r
    Published:18 Apr 2007
    6.8
    Medium

    CVE-2007-2089

    Last Modified: 6 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.

    Source:Cold Zero
    Published:18 Apr 2007
    6.8
    Medium

    CVE-2007-2087

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:irvian
    Published:18 Apr 2007
    6.8
    Medium

    CVE-2007-2086

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/.

    Source:irvian
    Published:18 Apr 2007
    6.9
    Medium

    CVE-2007-2083

    Last Modified: 27 Nov 2013

    vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.

    Source:Matousec Transparent security
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2081

    Last Modified: 28 Nov 2013

    MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.

    Source:BlackHawk
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2080

    Last Modified: 3 Oct 2016

    Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.

    Source:rgod
    Published:18 Apr 2007
    9.3
    Critical

    CVE-2007-2079

    Last Modified: 3 Oct 2016

    The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact. NOTE: it could be argued that this is an issue in mssql_connect (CVE-2007-1411.1) in PHP, or an issue in the ADOdb Library, and the proper fix should be in one of these products; if so, then this should not be treated as a vulnerability in XAMPP.

    Source:rgod
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2070

    Last Modified: 20 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

    Source:irvian
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2069

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dsn[phptype] parameter.

    Source:GoLd_M
    Published:18 Apr 2007
    6.8
    Medium

    CVE-2007-2068

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.

    Source:Alkomandoz Hacker
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2067

    Last Modified: 29 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.

    Source:GoLd_M
    Published:18 Apr 2007