7.5
    High

    CVE-2007-1510

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Source:WiLdBoY
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1509

    Last Modified: 21 Nov 2013

    Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.

    Source:h4ck3r
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1508

    Last Modified: 8 Jan 2017

    Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.

    Source:Mandr4ke
    Published:20 Mar 2007
    4.3
    Medium

    CVE-2007-1506

    Last Modified: 21 Nov 2013

    Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.

    Source:d3nx
    Published:19 Mar 2007
    9.3
    Critical

    CVE-2007-1501

    Last Modified: 27 Sept 2016

    Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.

    Source:DATA_SNIPER
    Published:19 Mar 2007
    4.3
    Medium

    CVE-2007-1499

    Last Modified: 21 Nov 2013

    Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."

    Source:Aviv Raff
    Published:17 Mar 2007
    7.5
    High

    CVE-2007-1493

    Last Modified: 23 Apr 2026

    nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.

    Source:DarkFig
    Published:16 Mar 2007
    7.1
    High

    CVE-2007-1492

    Last Modified: 24 Nov 2013

    winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.

    Source:Michal Majchrowicz
    Published:16 Mar 2007
    5
    Medium

    CVE-2007-1487

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.

    Source:Dj7xpl
    Published:16 Mar 2007
    4.6
    Medium

    CVE-2007-1484

    Last Modified: 22 Nov 2017

    The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

    Source:Stefan Esser
    Published:16 Mar 2007
    7.5
    High

    CVE-2007-1483

    Last Modified: 27 Apr 2011

    Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.

    Source:Drackanz
    Published:16 Mar 2007
    4.3
    Medium

    CVE-2007-1482

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.

    Source:Mehmet Ince
    Published:16 Mar 2007
    7.5
    High

    CVE-2007-1481

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.

    Source:Mehmet Ince
    Published:16 Mar 2007
    7.5
    High

    CVE-2007-1480

    Last Modified: 23 Apr 2026

    Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.

    Source:Dj7xpl
    Published:16 Mar 2007
    4.3
    Medium

    CVE-2007-1479

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

    Source:Dj7xpl
    Published:16 Mar 2007
    5
    Medium

    CVE-2007-1478

    Last Modified: 27 Sept 2016

    download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.

    Source:Piker
    Published:16 Mar 2007
    1.9
    Low

    CVE-2007-1476

    Last Modified: 24 Nov 2013

    The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.

    Source:David Matousek
    Published:16 Mar 2007
    5.4
    Medium

    CVE-2007-1475

    Last Modified: 28 Sept 2016

    Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

    Source:rgod
    Published:16 Mar 2007
    6.8
    Medium

    CVE-2007-1474

    Last Modified: 21 Nov 2013

    Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

    Source:anonymous
    Published:16 Mar 2007
    4.3
    Medium

    CVE-2007-1473

    Last Modified: 21 Nov 2013

    Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.

    Source:Moritz Naumann
    Published:16 Mar 2007
    6.8
    Medium

    CVE-2007-1472

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.

    Source:the_day
    Published:16 Mar 2007
    7.5
    High

    CVE-2007-1471

    Last Modified: 22 Dec 2016

    admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.

    Source:WiLdBoY
    Published:16 Mar 2007
    7.5
    High

    CVE-2007-1469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.

    Source:WiLdBoY
    Published:16 Mar 2007
    10
    Critical

    CVE-2007-1465

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.

    Source:Alexander Klink
    Published:24 Mar 2007
    6.8
    Medium

    CVE-2007-1459

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.

    Source:the_day
    Published:14 Mar 2007
    6.8
    Medium

    CVE-2007-1458

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files.

    Source:the_day
    Published:14 Mar 2007
    9
    Critical

    CVE-2007-1455

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.

    Source:cyb3rt & 020
    Published:14 Mar 2007
    7.5
    High

    CVE-2007-1453

    Last Modified: 20 Nov 2013

    Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace that precedes the buffer.

    Source:Stefan Esser
    Published:14 Mar 2007
    5
    Medium

    CVE-2007-1452

    Last Modified: 28 Sept 2016

    The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.

    Source:Stefan Esser
    Published:14 Mar 2007
    7.5
    High

    CVE-2007-1446

    Last Modified: 27 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.

    Source:K-159
    Published:14 Mar 2007
    7.5
    High

    CVE-2007-1445

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter.

    Source:BeyazKurt
    Published:14 Mar 2007
    7.5
    High

    CVE-2007-1440

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter.

    Source:WiLdBoY
    Published:13 Mar 2007
    9.3
    Critical

    CVE-2007-1439

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.

    Source:K-159
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1438

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CyberGhost
    Published:13 Mar 2007
    10
    Critical

    CVE-2007-1435

    Last Modified: 21 Nov 2013

    Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:LSO
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1434

    Last Modified: 18 Dec 2016

    SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.

    Source:Omni
    Published:13 Mar 2007
    4.3
    Medium

    CVE-2007-1433

    Last Modified: 18 Dec 2016

    Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.

    Source:Omni
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1432

    Last Modified: 18 Dec 2016

    Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.

    Source:Omni
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1430

    Last Modified: 8 Dec 2016

    PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code via a URL in the cmd parameter.

    Source:RaeD Hasadya
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1428

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter.

    Source:ajann
    Published:13 Mar 2007
    5
    Medium

    CVE-2007-1427

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter.

    Source:h4ck3r
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.

    Source:ajann
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1424

    Last Modified: 20 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php. NOTE: some of these details are obtained from third party information.

    Source:Hasadya Raed
    Published:13 Mar 2007
    9.3
    Critical

    CVE-2007-1423

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.

    Source:Rodrigo Duarte
    Published:13 Mar 2007
    7.5
    High

    CVE-2007-1422

    Last Modified: 20 Nov 2013

    SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-0688.

    Source:Cr@zy_King
    Published:13 Mar 2007
    10
    Critical

    CVE-2007-1421

    Last Modified: 20 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.

    Source:Hasadya Raed
    Published:13 Mar 2007
    2.1
    Low

    CVE-2007-1420

    Last Modified: 20 Nov 2013

    MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.

    Source:S.Streichsbier
    Published:9 Mar 2007
    7.5
    High

    CVE-2007-1417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion.

    Source:WiLdBoY
    Published:12 Mar 2007
    10
    Critical

    CVE-2007-1416

    Last Modified: 20 Nov 2013

    PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.

    Source:Hasadya Raed
    Published:12 Mar 2007
    7.5
    High

    CVE-2007-1415

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.

    Source:K-159
    Published:12 Mar 2007