7.5
    High

    CVE-2007-1818

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1817

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1816

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1815

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1814

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-0377.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1813

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the katid parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1812

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire_visiteur parameter.

    Source:Crackers_Child
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1811

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1810

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1809

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.

    Source:GoLd_M
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1808

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the camid parameter in a showcam action.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1807

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

    Source:ajann
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1805

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the genreid parameter.

    Source:ajann
    Published:2 Apr 2007
    7.8
    High

    CVE-2007-1804

    Last Modified: 27 Nov 2013

    PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.

    Source:Luigi Auriemma
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1801

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.

    Source:GoLd_M
    Published:2 Apr 2007
    10
    Critical

    CVE-2007-1795

    Last Modified: 29 Sept 2016

    JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Dj7xpl
    Published:2 Apr 2007
    4.9
    Medium

    CVE-2007-1793

    Last Modified: 25 Nov 2013

    SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.

    Source:David Matousek
    Published:2 Apr 2007
    7.5
    High

    CVE-2007-1791

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Kacper
    Published:31 Mar 2007
    6.8
    Medium

    CVE-2007-1790

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.

    Source:ThE dE@Th
    Published:31 Mar 2007
    9.3
    Critical

    CVE-2007-1787

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.

    Source:K-159
    Published:31 Mar 2007
    7.1
    High

    CVE-2007-1785

    Last Modified: 23 Apr 2026

    The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.

    Source:Shirkdog
    Published:31 Mar 2007
    10
    Critical

    CVE-2007-1778

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:ThE TiGeR
    Published:30 Mar 2007
    7.5
    High

    CVE-2007-1777

    Last Modified: 22 Nov 2013

    Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow.

    Source:Stefan Esser
    Published:30 Mar 2007
    6.8
    Medium

    CVE-2007-1776

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.

    Source:ajann
    Published:30 Mar 2007
    2.6
    Low

    CVE-2007-1773

    Last Modified: 22 Nov 2013

    Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. (dot dot) in the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php, different vectors than CVE-2006-6384.

    Source:Lostmon
    Published:30 Mar 2007
    7.1
    High

    CVE-2007-1772

    Last Modified: 22 Nov 2013

    The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.

    Source:Handrix
    Published:30 Mar 2007
    9.3
    Critical

    CVE-2007-1771

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.

    Source:kezzap66345
    Published:30 Mar 2007
    10
    Critical

    CVE-2007-1770

    Last Modified: 5 Oct 2016

    Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.

    Source:Heretic2
    Published:30 Mar 2007
    10
    Critical

    CVE-2007-1766

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:Bithedz
    Published:30 Mar 2007
    9.3
    Critical

    CVE-2007-1765

    Last Modified: 29 Sept 2016

    Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.

    Source:Marsu
    Published:30 Mar 2007
    9.3
    Critical

    CVE-2007-1749

    Last Modified: 25 Dec 2013

    Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.

    Source:Ben Nagy & Derek Soeder
    Published:14 Aug 2007
    10
    Critical

    CVE-2007-1748

    Last Modified: 7 Mar 2011

    Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.

    Source:Metasploit
    Published:13 Apr 2007
    6.9
    Medium

    CVE-2007-1738

    Last Modified: 8 Nov 2016

    TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.

    Source:Marco Ivaldi
    Published:28 Mar 2007
    9.3
    Critical

    CVE-2007-1735

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.

    Source:Jonathan So
    Published:28 Mar 2007
    7.2
    High

    CVE-2007-1734

    Last Modified: 3 Oct 2016

    The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.

    Source:Robert Swiecki
    Published:28 Mar 2007
    10
    Critical

    CVE-2007-1733

    Last Modified: 23 Apr 2026

    Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112.

    Source:skillTube
    Published:28 Mar 2007
    6.6
    Medium

    CVE-2007-1730

    Last Modified: 3 Oct 2016

    Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.

    Source:Robert Swiecki
    Published:28 Mar 2007
    6.5
    Medium

    CVE-2007-1726

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/.

    Source:Hessam-x
    Published:28 Mar 2007
    9.3
    Critical

    CVE-2007-1725

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.

    Source:Hessam-x
    Published:28 Mar 2007
    10
    Critical

    CVE-2007-1721

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.

    Source:K-159
    Published:28 Mar 2007
    7.5
    High

    CVE-2007-1720

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.

    Source:bd0rk
    Published:28 Mar 2007
    7.2
    High

    CVE-2007-1719

    Last Modified: 24 Nov 2017

    Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.

    Source:harry
    Published:28 Mar 2007
    7.8
    High

    CVE-2007-1718

    Last Modified: 22 Nov 2013

    CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of the (1) Subject or (2) To parameter, as demonstrated by a parameter containing a "\r\n\t\n" sequence, related to an increment bug in the SKIP_LONG_HEADER_SEP macro.

    Source:Stefan Esser
    Published:26 Mar 2007
    5
    Medium

    CVE-2007-1717

    Last Modified: 22 Nov 2013

    The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.

    Source:Stefan Esser
    Published:28 Mar 2007
    7.5
    High

    CVE-2007-1715

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.

    Source:Crackers_Child
    Published:27 Mar 2007
    6.8
    Medium

    CVE-2007-1714

    Last Modified: 22 Nov 2013

    Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter.

    Source:Crackers_Child
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1712

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:CyberGhost
    Published:27 Mar 2007
    6.8
    Medium

    CVE-2007-1711

    Last Modified: 30 Sept 2016

    Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).

    Source:Stefan Esser
    Published:25 Mar 2007
    4.3
    Medium

    CVE-2007-1709

    Last Modified: 30 Sept 2016

    Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.

    Source:rgod
    Published:27 Mar 2007