5
    Medium

    CVE-2007-1158

    Last Modified: 18 Nov 2013

    Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Source:D. Matscheko
    Published:28 Feb 2007
    7.5
    High

    CVE-2007-1156

    Last Modified: 24 Dec 2012

    JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.

    Source:Himeur Nourredine
    Published:27 Feb 2007
    5
    Medium

    CVE-2007-1152

    Last Modified: 14 Feb 2017

    Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php. NOTE: some of these details are obtained from third party information.

    Source:laurent gaffie
    Published:27 Feb 2007
    4.3
    Medium

    CVE-2007-1151

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.

    Source:laurent gaffie
    Published:27 Feb 2007
    5
    Medium

    CVE-2007-1149

    Last Modified: 6 Jan 2017

    Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.

    Source:laurent gaffie
    Published:27 Feb 2007
    7.5
    High

    CVE-2007-1148

    Last Modified: 6 Jan 2017

    PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    4.3
    Medium

    CVE-2007-1142

    Last Modified: 16 Nov 2013

    Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.

    Source:HACKERS PAL
    Published:27 Feb 2007
    7.5
    High

    CVE-2007-1141

    Last Modified: 16 Nov 2013

    PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.

    Source:HACKERS PAL
    Published:27 Feb 2007
    9.4
    Critical

    CVE-2007-1140

    Last Modified: 16 Nov 2013

    Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    5
    Medium

    CVE-2007-1138

    Last Modified: 16 Nov 2013

    Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    7.5
    High

    CVE-2007-1133

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.

    Source:kezzap66345
    Published:27 Feb 2007
    7.5
    High

    CVE-2007-1131

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

    Source:kezzap66345
    Published:27 Feb 2007
    7.5
    High

    CVE-2007-1130

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.

    Source:kezzap66345
    Published:27 Feb 2007
    6.4
    Medium

    CVE-2007-1127

    Last Modified: 17 Nov 2013

    Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    5
    Medium

    CVE-2007-1126

    Last Modified: 17 Nov 2013

    Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    4.3
    Medium

    CVE-2007-1125

    Last Modified: 17 Nov 2013

    Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    5
    Medium

    CVE-2007-1124

    Last Modified: 17 Nov 2013

    Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

    Source:laurent gaffie
    Published:27 Feb 2007
    6.8
    Medium

    CVE-2007-1118

    Last Modified: 5 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.

    Source:ThE dE@Th
    Published:27 Feb 2007
    6.8
    Medium

    CVE-2007-1111

    Last Modified: 17 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.

    Source:Simon Bonnard
    Published:26 Feb 2007
    5
    Medium

    CVE-2007-1110

    Last Modified: 17 Nov 2013

    Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Source:Simon Bonnard
    Published:26 Feb 2007
    6.8
    Medium

    CVE-2007-1108

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.

    Source:burncycle
    Published:26 Feb 2007
    7.5
    High

    CVE-2007-1107

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.

    Source:s0cratex
    Published:26 Feb 2007
    6.8
    Medium

    CVE-2007-1106

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:26 Feb 2007
    5
    Medium

    CVE-2007-1105

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:26 Feb 2007
    4.3
    Medium

    CVE-2007-1104

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.

    Source:GoLd_M
    Published:26 Feb 2007
    4.3
    Medium

    CVE-2007-1101

    Last Modified: 18 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.

    Source:Simon Bonnard
    Published:26 Feb 2007
    7.8
    High

    CVE-2007-1100

    Last Modified: 17 Nov 2013

    Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:laurent gaffie
    Published:26 Feb 2007
    7.1
    High

    CVE-2007-1090

    Last Modified: 18 Nov 2013

    Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.

    Source:sehato
    Published:26 Feb 2007
    7.6
    High

    CVE-2007-1085

    Last Modified: 16 Nov 2013

    Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.

    Source:Yair Amit
    Published:23 Feb 2007
    7.1
    High

    CVE-2007-1082

    Last Modified: 23 Apr 2026

    FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.

    Source:Marsu
    Published:22 Feb 2007
    7.8
    High

    CVE-2007-1080

    Last Modified: 27 Sept 2016

    Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.

    Source:Marsu
    Published:22 Feb 2007
    7.8
    High

    CVE-2007-1079

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.

    Source:Marsu
    Published:22 Feb 2007
    7.5
    High

    CVE-2007-1078

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.

    Source:JuMp-Er
    Published:22 Feb 2007
    7.5
    High

    CVE-2007-1077

    Last Modified: 16 Nov 2013

    SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:xoron
    Published:22 Feb 2007
    7.5
    High

    CVE-2007-1076

    Last Modified: 16 Nov 2013

    Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.

    Source:Hamid Ebadi
    Published:22 Feb 2007
    7.8
    High

    CVE-2007-1075

    Last Modified: 27 Sept 2016

    TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.

    Source:Marsu
    Published:22 Feb 2007
    9.3
    Critical

    CVE-2007-1074

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.

    Source:Marsu
    Published:22 Feb 2007
    7.8
    High

    CVE-2007-1071

    Last Modified: 16 Nov 2013

    Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression. NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.

    Source:Tom Ferris
    Published:22 Feb 2007
    10
    Critical

    CVE-2007-1070

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.

    Source:devcode
    Published:21 Feb 2007
    6.8
    Medium

    CVE-2007-1061

    Last Modified: 26 Sept 2016

    SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).

    Source:krasza
    Published:22 Feb 2007
    6.8
    Medium

    CVE-2007-1060

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.

    Source:K-159
    Published:22 Feb 2007
    6.8
    Medium

    CVE-2007-1059

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter. NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.

    Source:kezzap66345
    Published:22 Feb 2007
    7.5
    High

    CVE-2007-1058

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.

    Source:Mehmet Ince
    Published:21 Feb 2007
    6.9
    Medium

    CVE-2007-1057

    Last Modified: 23 Apr 2026

    The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.

    Source:Jon Hart
    Published:21 Feb 2007
    4.3
    Medium

    CVE-2007-1050

    Last Modified: 16 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.

    Source:sn0oPy
    Published:21 Feb 2007
    4.3
    Medium

    CVE-2007-1049

    Last Modified: 15 Nov 2013

    Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

    Source:PsychoGun
    Published:21 Feb 2007
    5
    Medium

    CVE-2007-1044

    Last Modified: 16 Nov 2013

    Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.

    Source:gheetotank
    Published:21 Feb 2007
    7.5
    High

    CVE-2007-1043

    Last Modified: 15 Nov 2013

    Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.

    Source:sn0oPy
    Published:21 Feb 2007
    9.3
    Critical

    CVE-2007-1041

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.

    Source:Marsu
    Published:21 Feb 2007
    7.5
    High

    CVE-2007-1040

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.

    Source:r0ut3r
    Published:21 Feb 2007