9.3
    Critical

    CVE-2007-1943

    Last Modified: 26 Nov 2013

    Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.

    Source:Ivan Fratric
    Published:11 Apr 2007
    9.3
    Critical

    CVE-2007-1942

    Last Modified: 30 Dec 2016

    Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.

    Source:Ivan Fratric
    Published:11 Apr 2007
    6.8
    Medium

    CVE-2007-1937

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.

    Source:Dj7xpl
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1934

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.

    Source:bd0rk
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1933

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.

    Source:Dj7xpl
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1932

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.

    Source:BeyazKurt
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1931

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

    Source:Kacper
    Published:10 Apr 2007
    7.8
    High

    CVE-2007-1930

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.

    Source:GoLd_M
    Published:10 Apr 2007
    5
    Medium

    CVE-2007-1929

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter.

    Source:GoLd_M
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1928

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.

    Source:the_Edit0r
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1920

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.

    Source:Kacper
    Published:10 Apr 2007
    4.3
    Medium

    CVE-2007-1919

    Last Modified: 26 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Arham Muhammad
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1912

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.

    Source:muts
    Published:10 Apr 2007
    7.1
    High

    CVE-2007-1911

    Last Modified: 14 Aug 2017

    Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.

    Source:muts
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1910

    Last Modified: 14 Aug 2017

    Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.

    Source:muts
    Published:10 Apr 2007
    7.5
    High

    CVE-2007-1909

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.

    Source:h a c k e r _ X
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1908

    Last Modified: 23 Apr 2026

    PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.

    Source:Dj7xpl
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1907

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:kezzap66345
    Published:10 Apr 2007
    6.8
    Medium

    CVE-2007-1906

    Last Modified: 26 Nov 2013

    Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.

    Source:Liz0ziM
    Published:10 Apr 2007
    4.3
    Medium

    CVE-2007-1905

    Last Modified: 26 Nov 2013

    Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".

    Source:John Martinelli
    Published:10 Apr 2007
    2.6
    Low

    CVE-2007-1903

    Last Modified: 4 Dec 2013

    Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter.

    Source:Jesper Jurcenoks
    Published:14 May 2007
    6.8
    Medium

    CVE-2007-1902

    Last Modified: 5 Dec 2013

    Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php.

    Source:Jesper Jurcenoks
    Published:14 May 2007
    5.1
    Medium

    CVE-2007-1899

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.

    Source:Jesper Jurcenoks
    Published:9 Jul 2008
    5.8
    Medium

    CVE-2007-1898

    Last Modified: 5 Dec 2013

    formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

    Source:Jesper Jurcenoks
    Published:16 May 2007
    6.5
    Medium

    CVE-2007-1897

    Last Modified: 30 Sept 2016

    SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

    Source:Sumit Siddharth
    Published:9 Apr 2007
    5.8
    Medium

    CVE-2007-1896

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.

    Source:Xst3nZ
    Published:9 Apr 2007
    6.8
    Medium

    CVE-2007-1895

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.

    Source:Xst3nZ
    Published:9 Apr 2007
    7.5
    High

    CVE-2007-1890

    Last Modified: 25 Nov 2013

    Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

    Source:Stefan Esser
    Published:6 Apr 2007
    6.5
    Medium

    CVE-2007-1882

    Last Modified: 23 Apr 2026

    qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.

    Source:Isma Khan
    Published:6 Apr 2007
    6.8
    Medium

    CVE-2007-1881

    Last Modified: 20 Sept 2016

    Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges via unspecified vectors.

    Source:MaD
    Published:6 Apr 2007
    4.3
    Medium

    CVE-2007-1873

    Last Modified: 22 Nov 2013

    Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search script.

    Source:The[Boss]
    Published:13 Apr 2007
    4.3
    Medium

    CVE-2007-1872

    Last Modified: 27 Nov 2013

    Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search id.

    Source:Hanno Boeck
    Published:13 Apr 2007
    10
    Critical

    CVE-2007-1868

    Last Modified: 7 Mar 2011

    The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

    Source:Metasploit
    Published:4 Apr 2007
    10
    Critical

    CVE-2007-1867

    Last Modified: 31 Oct 2016

    Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.

    Source:Marsu
    Published:4 Apr 2007
    10
    Critical

    CVE-2007-1866

    Last Modified: 5 Dec 2016

    Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.

    Source:mu-b
    Published:4 Apr 2007
    4.9
    Medium

    CVE-2007-1861

    Last Modified: 6 Sept 2016

    The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.

    Source:Alexey Kuznetsov
    Published:25 Apr 2007
    2.6
    Low

    CVE-2007-1858

    Last Modified: 23 Apr 2026

    The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

    Published:19 Apr 2007
    7.5
    High

    CVE-2007-1851

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php.

    Source:Hamid Ebadi
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1849

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

    Source:HACKERS PAL
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.

    Source:ajann
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1845

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.

    Source:UNIQUE-KEY
    Published:3 Apr 2007
    6.8
    Medium

    CVE-2007-1843

    Last Modified: 3 Oct 2016

    PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter.

    Source:ka0x
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1842

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.

    Source:GoLd_M
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1839

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.

    Source:Alkomandoz Hacker
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1838

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1837

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.

    Source:kezzap66345
    Published:3 Apr 2007
    4.6
    Medium

    CVE-2007-1835

    Last Modified: 25 Nov 2013

    PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

    Source:Stefan Esser
    Published:3 Apr 2007
    7.5
    High

    CVE-2007-1825

    Last Modified: 25 Nov 2013

    Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.

    Source:Stefan Esser
    Published:14 Feb 2007
    9.3
    Critical

    CVE-2007-1819

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.

    Source:Metasploit
    Published:2 Apr 2007