7.5
    High

    CVE-2007-2065

    Last Modified: 11 Oct 2013

    PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Cyber Security
    Published:18 Apr 2007
    7.5
    High

    CVE-2007-2064

    Last Modified: 27 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.

    Source:SekoMirza
    Published:18 Apr 2007
    9.3
    Critical

    CVE-2007-2062

    Last Modified: 30 Sept 2016

    Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.

    Source:InTeL
    Published:18 Apr 2007
    4.3
    Medium

    CVE-2007-2061

    Last Modified: 27 Nov 2013

    Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Source:David Vieira-Kurz
    Published:18 Apr 2007
    10
    Critical

    CVE-2007-2059

    Last Modified: 27 Nov 2013

    Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.

    Source:Leon Juranic
    Published:18 Apr 2007
    10
    Critical

    CVE-2007-2057

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.

    Source:Jonathan So
    Published:18 Apr 2007
    5
    Medium

    CVE-2007-2052

    Last Modified: 4 Dec 2013

    Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.

    Source:Piotr Engelking
    Published:2 Apr 2007
    5
    Medium

    CVE-2007-2050

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.

    Source:Dj7xpl
    Published:16 Apr 2007
    6.8
    Medium

    CVE-2007-2049

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.

    Source:Cold Zero
    Published:16 Apr 2007
    5
    Medium

    CVE-2007-2048

    Last Modified: 27 Nov 2013

    Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.

    Source:Patrick Webster
    Published:16 Apr 2007
    7.5
    High

    CVE-2007-2044

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.

    Source:Cold Zero
    Published:16 Apr 2007
    7.5
    High

    CVE-2007-2043

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php.

    Source:GoLd_M
    Published:16 Apr 2007
    10
    Critical

    CVE-2007-2031

    Last Modified: 20 Apr 2017

    Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.

    Source:vade79
    Published:16 Apr 2007
    4.4
    Medium

    CVE-2007-2027

    Last Modified: 1 Dec 2013

    Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

    Source:Arnaud Giersch
    Published:4 Apr 2007
    7.5
    High

    CVE-2007-2019

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.

    Source:anonymous
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-2015

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Source:hackberry
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2014

    Last Modified: 26 Nov 2013

    PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.

    Source:hackberry
    Published:12 Apr 2007
    4.3
    Medium

    CVE-2007-2013

    Last Modified: 26 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:hackberry
    Published:12 Apr 2007
    4.3
    Medium

    CVE-2007-2011

    Last Modified: 26 Nov 2013

    Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Source:John Martinelli
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-2009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.

    Source:Dr.RoVeR
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2008

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:Omni
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2007

    Last Modified: 30 Sept 2016

    admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.

    Source:Omni
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2006

    Last Modified: 30 Sept 2016

    Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.

    Source:Omni
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-2005

    Last Modified: 6 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.

    Source:Cold Zero
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2004

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.

    Source:BlackHawk
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-2003

    Last Modified: 23 Apr 2026

    InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.

    Source:BlackHawk
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-2002

    Last Modified: 23 Apr 2026

    InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.

    Source:BlackHawk
    Published:12 Apr 2007
    6.5
    Medium

    CVE-2007-2001

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.

    Source:Xst3nZ
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-2000

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.

    Source:Xst3nZ
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1999

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.

    Source:Co-Sarper-Der
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1998

    Last Modified: 30 Sept 2016

    Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.

    Source:Dj7xpl
    Published:12 Apr 2007
    6.8
    Medium

    CVE-2007-1996

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.

    Source:John Martinelli
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1992

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.

    Source:iskorpitx
    Published:12 Apr 2007
    4.3
    Medium

    CVE-2007-1989

    Last Modified: 27 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.

    Source:nassim
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1986

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.

    Source:kezzap66345
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1983

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.

    Source:bd0rk
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1982

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.

    Source:Hamid Ebadi
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1980

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Mehmet Ince
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.

    Source:ajann
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1978

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.

    Source:Mehmet Ince
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1974

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.

    Source:ajann
    Published:12 Apr 2007
    7.5
    High

    CVE-2007-1971

    Last Modified: 26 Nov 2013

    SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.

    Source:CoNqUeRoR
    Published:11 Apr 2007
    6.8
    Medium

    CVE-2007-1968

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.

    Source:the_Edit0r
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1963

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.

    Source:DarkFig
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1962

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.

    Source:ajann
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1961

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1960

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Source:ajann
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1956

    Last Modified: 26 Nov 2013

    SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.

    Source:John Martinelli
    Published:11 Apr 2007
    9.3
    Critical

    CVE-2007-1948

    Last Modified: 31 Oct 2016

    Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.

    Source:Ivan Fratric
    Published:11 Apr 2007
    3.5
    Low

    CVE-2007-1947

    Last Modified: 26 Nov 2013

    Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the toString function via a certain function declaration, related to incorrect identification of anonymous JavaScript functions, a different issue than CVE-2007-1878.

    Source:Thor Larholm
    Published:11 Apr 2007