7.5
    High

    CVE-2007-1708

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.

    Source:Kacper
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1707

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter.

    Source:Sharingan
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter.

    Source:ajann
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1705

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:CyberGhost
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1704

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1703

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:ajann
    Published:27 Mar 2007
    6.8
    Medium

    CVE-2007-1702

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Cold Zero
    Published:27 Mar 2007
    6.8
    Medium

    CVE-2007-1701

    Last Modified: 30 Sept 2016

    PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".

    Source:Stefan Esser
    Published:14 Feb 2007
    7.5
    High

    CVE-2007-1700

    Last Modified: 22 Nov 2017

    The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

    Source:Stefan Esser
    Published:27 Mar 2007
    10
    Critical

    CVE-2007-1699

    Last Modified: 6 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.

    Source:Cold Zero
    Published:27 Mar 2007
    5
    Medium

    CVE-2007-1698

    Last Modified: 30 Sept 2016

    download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.

    Source:GoLd_M
    Published:27 Mar 2007
    10
    Critical

    CVE-2007-1697

    Last Modified: 30 Sept 2016

    PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.

    Source:GoLd_M
    Published:27 Mar 2007
    7.5
    High

    CVE-2007-1696

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.

    Source:ajann
    Published:27 Mar 2007
    6.8
    Medium

    CVE-2007-1691

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Umesh Wanve
    Published:19 Apr 2007
    6.8
    Medium

    CVE-2007-1690

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary code via unspecified vectors.

    Source:Umesh Wanve
    Published:19 Apr 2007
    10
    Critical

    CVE-2007-1689

    Last Modified: 10 Mar 2011

    Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.

    Source:Metasploit
    Published:16 May 2007
    10
    Critical

    CVE-2007-1687

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll) allow remote attackers to execute arbitrary code via unspecified vectors.

    Source:Umesh Wanve
    Published:10 Apr 2007
    10
    Critical

    CVE-2007-1685

    Last Modified: 10 Dec 2013

    Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

    Source:Dennis Rand
    Published:8 Jun 2007
    6.8
    Medium

    CVE-2007-1683

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Lincoln
    Published:26 Apr 2007
    9.3
    Critical

    CVE-2007-1682

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.

    Source:Metasploit
    Published:27 Aug 2008
    4.3
    Medium

    CVE-2007-1678

    Last Modified: 22 Nov 2013

    Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler.

    Source:CrYpTiC MauleR
    Published:26 Mar 2007
    10
    Critical

    CVE-2007-1675

    Last Modified: 29 Sept 2016

    Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.

    Source:Winny Thomas
    Published:28 Mar 2007
    10
    Critical

    CVE-2007-1674

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.

    Source:Metasploit
    Published:18 Apr 2007
    7.8
    High

    CVE-2007-1669

    Last Modified: 7 Oct 2017

    zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

    Source:Jean-Sébastien
    Published:9 May 2007
    9.3
    Critical

    CVE-2007-1658

    Last Modified: 22 Nov 2013

    Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).

    Source:kingcope
    Published:24 Mar 2007
    7.5
    High

    CVE-2007-1657

    Last Modified: 21 Nov 2013

    Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code via a long file argument.

    Source:starcadi
    Published:24 Mar 2007
    7.8
    High

    CVE-2007-1649

    Last Modified: 30 Sept 2016

    PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

    Source:Stefan Esser
    Published:24 Mar 2007
    7.8
    High

    CVE-2007-1648

    Last Modified: 23 Apr 2026

    0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.

    Source:DiGitalX
    Published:24 Mar 2007
    7.8
    High

    CVE-2007-1647

    Last Modified: 23 Apr 2026

    Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

    Source:xSh
    Published:24 Mar 2007
    10
    Critical

    CVE-2007-1645

    Last Modified: 23 Apr 2026

    Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.

    Source:Umesh Wanve
    Published:24 Mar 2007
    10
    Critical

    CVE-2007-1644

    Last Modified: 22 Nov 2017

    The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).

    Source:Andres Tarasco
    Published:24 Mar 2007
    10
    Critical

    CVE-2007-1643

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.

    Source:Kacper
    Published:24 Mar 2007
    7.5
    High

    CVE-2007-1641

    Last Modified: 7 Jun 2012

    SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter.

    Source:Mehmet Ince
    Published:23 Mar 2007
    10
    Critical

    CVE-2007-1640

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php.

    Source:GoLd_M
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1636

    Last Modified: 30 Sept 2016

    Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.

    Source:GoLd_M
    Published:23 Mar 2007
    9
    Critical

    CVE-2007-1635

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.

    Source:DarkFig
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1634

    Last Modified: 23 Apr 2026

    Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.

    Source:DarkFig
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1633

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.

    Source:GoLd_M
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1630

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:CyberGhost
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1629

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:CyberGhost
    Published:23 Mar 2007
    9.3
    Critical

    CVE-2007-1628

    Last Modified: 30 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files.

    Source:K-159
    Published:23 Mar 2007
    9.3
    Critical

    CVE-2007-1626

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:Cold Zero
    Published:23 Mar 2007
    4.3
    Medium

    CVE-2007-1622

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.

    Source:Alexander Concha
    Published:23 Mar 2007
    10
    Critical

    CVE-2007-1621

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter. NOTE: this issue might be related to CVE-2003-1254.

    Source:GoLd_M
    Published:23 Mar 2007
    10
    Critical

    CVE-2007-1620

    Last Modified: 27 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.

    Source:GoLd_M
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1619

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter.

    Source:ajann
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1618

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:ajann
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1617

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:ajann
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1616

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter.

    Source:ajann
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1615

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:ajann
    Published:23 Mar 2007