7.5
    High

    CVE-2007-1613

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.

    Source:GoLd_M
    Published:23 Mar 2007
    7.5
    High

    CVE-2007-1612

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter.

    Source:Kacper
    Published:23 Mar 2007
    4.3
    Medium

    CVE-2007-1606

    Last Modified: 21 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.

    Source:laurent gaffie
    Published:22 Mar 2007
    7.5
    High

    CVE-2007-1604

    Last Modified: 21 Nov 2013

    Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.

    Source:laurent gaffie
    Published:22 Mar 2007
    9.3
    Critical

    CVE-2007-1600

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.

    Source:Cold Zero
    Published:22 Mar 2007
    9.3
    Critical

    CVE-2007-1596

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.

    Source:Cold Zero
    Published:22 Mar 2007
    7.8
    High

    CVE-2007-1590

    Last Modified: 23 Apr 2026

    The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.

    Source:MADYNES
    Published:21 Mar 2007
    7.8
    High

    CVE-2007-1586

    Last Modified: 21 Nov 2013

    ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.

    Source:Joxean Koret
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1584

    Last Modified: 23 Apr 2026

    Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.

    Source:Stefan Esser
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1583

    Last Modified: 21 Nov 2013

    The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

    Source:Stefan Esser
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1582

    Last Modified: 27 Sept 2016

    The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.

    Source:Stefan Esser
    Published:21 Mar 2007
    9.3
    Critical

    CVE-2007-1581

    Last Modified: 30 Sept 2016

    The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

    Source:Stefan Esser
    Published:21 Mar 2007
    6.3
    Medium

    CVE-2007-1580

    Last Modified: 23 Apr 2026

    FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:". NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument.

    Source:shinnai
    Published:21 Mar 2007
    10
    Critical

    CVE-2007-1579

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.

    Source:Winny Thomas
    Published:21 Mar 2007
    10
    Critical

    CVE-2007-1578

    Last Modified: 23 Apr 2026

    Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.

    Source:mu-b
    Published:21 Mar 2007
    5
    Medium

    CVE-2007-1577

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Source:GoLd_M
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1572

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:WiLdBoY
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1571

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Source:the_day
    Published:21 Mar 2007
    Low

    CVE-2007-1570

    Last Modified: 27 Sept 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1438. Reason: This candidate is a duplicate of CVE-2007-1438. Notes: All CVE users should reference CVE-2007-1438 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:CyberGhost
    Published:21 Mar 2007
    10
    Critical

    CVE-2007-1569

    Last Modified: 28 Apr 2011

    Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file. NOTE: some of these details are obtained from third party information.

    Source:Marsu
    Published:21 Mar 2007
    10
    Critical

    CVE-2007-1568

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.

    Source:Marsu
    Published:21 Mar 2007
    10
    Critical

    CVE-2007-1567

    Last Modified: 25 Oct 2016

    Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

    Source:Winny Thomas
    Published:21 Mar 2007
    7.5
    High

    CVE-2007-1566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.

    Source:ajann
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1564

    Last Modified: 24 Nov 2013

    The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

    Source:mark
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1563

    Last Modified: 24 Nov 2013

    The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

    Source:mark
    Published:21 Mar 2007
    6.8
    Medium

    CVE-2007-1562

    Last Modified: 24 Nov 2013

    The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

    Source:mark
    Published:21 Mar 2007
    7.8
    High

    CVE-2007-1561

    Last Modified: 23 Apr 2026

    The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.

    Source:MADYNES
    Published:21 Mar 2007
    9.3
    Critical

    CVE-2007-1559

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in SonicMediaPlayer.dll.

    Source:Metasploit
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1556

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.

    Source:Mehmet Ince
    Published:21 Mar 2007
    7.5
    High

    CVE-2007-1555

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:Mehmet Ince
    Published:20 Mar 2007
    5
    Medium

    CVE-2007-1553

    Last Modified: 23 Apr 2026

    admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters.

    Source:Kacper
    Published:20 Mar 2007
    7.5
    High

    CVE-2007-1552

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php.

    Source:Gu1ll4um3r0m41n
    Published:20 Mar 2007
    7.5
    High

    CVE-2007-1550

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.

    Source:laurent gaffie
    Published:20 Mar 2007
    7.5
    High

    CVE-2007-1548

    Last Modified: 21 Nov 2013

    SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.

    Source:Ivan Fratric
    Published:20 Mar 2007
    5
    Medium

    CVE-2007-1542

    Last Modified: 22 Jun 2017

    Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:MADYNES
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1540

    Last Modified: 21 Nov 2013

    Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter. NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated.

    Source:Chris Travers
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1539

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.

    Source:bd0rk
    Published:20 Mar 2007
    9.3
    Critical

    CVE-2007-1536

    Last Modified: 21 Nov 2013

    Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.

    Source:Jean-Sebastien Guay-Leroux
    Published:8 Feb 2007
    5
    Medium

    CVE-2007-1531

    Last Modified: 25 Nov 2013

    Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.

    Source:Kristian Hermansen
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1525

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

    Source:Dj7xpl
    Published:20 Mar 2007
    5
    Medium

    CVE-2007-1524

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.

    Source:Bl0od3r
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1522

    Last Modified: 28 Sept 2016

    Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

    Source:Stefan Esser
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1521

    Last Modified: 28 Sept 2016

    Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

    Source:Stefan Esser
    Published:20 Mar 2007
    7.5
    High

    CVE-2007-1518

    Last Modified: 26 Sept 2016

    SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.

    Source:x666
    Published:20 Mar 2007
    7.5
    High

    CVE-2007-1517

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:WiLdBoY
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1516

    Last Modified: 21 Nov 2016

    PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.

    Source:Crackers_Child
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1515

    Last Modified: 21 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php. NOTE: some of these details are obtained from third party information.

    Source:Immerda Project Group
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1514

    Last Modified: 21 Nov 2013

    PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.

    Source:Abdus Samad
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2007-1513

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.

    Source:the_day
    Published:20 Mar 2007
    7.1
    High

    CVE-2007-1511

    Last Modified: 23 Apr 2026

    Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.

    Source:Heretic2
    Published:20 Mar 2007