7.8
    High

    CVE-2007-0887

    Last Modified: 23 Apr 2026

    axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).

    Source:mu-b
    Published:12 Feb 2007
    10
    Critical

    CVE-2007-0886

    Last Modified: 23 Apr 2026

    Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.

    Source:mu-b
    Published:12 Feb 2007
    6.8
    Medium

    CVE-2007-0885

    Last Modified: 14 Nov 2013

    Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:BL4CK
    Published:12 Feb 2007
    5
    Medium

    CVE-2007-0883

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Sebastian Wolfgarten
    Published:12 Feb 2007
    10
    Critical

    CVE-2007-0882

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

    Source:MC
    Published:12 Feb 2007
    6.8
    Medium

    CVE-2007-0881

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php. NOTE: vector 2 might be the same as CVE-2006-4750.

    Source:y3dips
    Published:12 Feb 2007
    7.5
    High

    CVE-2007-0873

    Last Modified: 27 Sept 2016

    nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.

    Source:sn0oPy
    Published:12 Feb 2007
    5
    Medium

    CVE-2007-0872

    Last Modified: 14 Nov 2013

    Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:Stefano Di Paola
    Published:12 Feb 2007
    7.5
    High

    CVE-2007-0871

    Last Modified: 14 Nov 2013

    Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.

    Source:hamed bazargani
    Published:12 Feb 2007
    7.5
    High

    CVE-2007-0867

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.

    Source:ajann
    Published:9 Feb 2007
    7.5
    High

    CVE-2007-0865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:9 Feb 2007
    7.5
    High

    CVE-2007-0864

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:9 Feb 2007
    7.2
    High

    CVE-2007-0849

    Last Modified: 14 Nov 2013

    scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.

    Source:Daniel Schulte
    Published:8 Feb 2007
    7.5
    High

    CVE-2007-0848

    Last Modified: 13 Dec 2016

    PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.

    Source:Denven
    Published:8 Feb 2007
    7.5
    High

    CVE-2007-0847

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.

    Source:GregStar
    Published:8 Feb 2007
    6.8
    Medium

    CVE-2007-0846

    Last Modified: 27 Sept 2016

    Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.

    Source:GregStar
    Published:8 Feb 2007
    7.5
    High

    CVE-2007-0845

    Last Modified: 23 Apr 2026

    admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.

    Source:diwou
    Published:8 Feb 2007
    4.6
    Medium

    CVE-2007-0843

    Last Modified: 16 Nov 2013

    The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.

    Source:3APA3A
    Published:23 Feb 2007
    7.5
    High

    CVE-2007-0839

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.

    Source:MadNet
    Published:8 Feb 2007
    7.5
    High

    CVE-2007-0837

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.

    Source:GoLd_M
    Published:8 Feb 2007
    4
    Medium

    CVE-2007-0836

    Last Modified: 21 Dec 2016

    admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:anonymous
    Published:8 Feb 2007
    7.5
    High

    CVE-2007-0828

    Last Modified: 13 Nov 2013

    PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.

    Source:Blaster
    Published:7 Feb 2007
    6.8
    Medium

    CVE-2007-0827

    Last Modified: 23 Apr 2026

    The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.

    Source:cocoruder
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0826

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Source:cl24zy
    Published:7 Feb 2007
    7.8
    High

    CVE-2007-0825

    Last Modified: 23 Apr 2026

    FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.

    Source:Marsu
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0824

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter.

    Source:ajann
    Published:7 Feb 2007
    5
    Medium

    CVE-2007-0821

    Last Modified: 13 Nov 2013

    Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:laurent gaffie
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0820

    Last Modified: 13 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:laurent gaffie
    Published:7 Feb 2007
    4.3
    Medium

    CVE-2007-0817

    Last Modified: 13 Nov 2013

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.

    Source:digi7al64
    Published:7 Feb 2007
    5
    Medium

    CVE-2007-0816

    Last Modified: 23 Apr 2026

    The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.

    Source:Shirkdog
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0812

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.

    Source:rgod
    Published:7 Feb 2007
    4.3
    Medium

    CVE-2007-0811

    Last Modified: 27 Sept 2016

    Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.

    Source:AmesianX
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0810

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter. NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.

    Source:GoLd_M
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0809

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:7 Feb 2007
    2.1
    Low

    CVE-2007-0805

    Last Modified: 23 Apr 2026

    The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.

    Source:bunker
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0804

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

    Source:Kacper
    Published:7 Feb 2007
    7.5
    High

    CVE-2007-0797

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.

    Source:ThE dE@Th
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0790

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.

    Source:Marsu
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0786

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0785

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

    Source:GoLd_M
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0774

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.

    Source:Xpl017Elz
    Published:27 Feb 2007
    4.3
    Medium

    CVE-2007-0768

    Last Modified: 11 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.

    Source:Hai Nam Luke
    Published:6 Feb 2007
    9.3
    Critical

    CVE-2007-0766

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.

    Source:shinnai
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0765

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.

    Source:ajann
    Published:6 Feb 2007
    6.5
    Medium

    CVE-2007-0764

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.

    Source:Kacper
    Published:6 Feb 2007
    6.8
    Medium

    CVE-2007-0763

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.

    Source:Kacper
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0762

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0761

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.

    Source:Mehmet Ince
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0760

    Last Modified: 29 Nov 2016

    EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.

    Source:Eight10
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0759

    Last Modified: 13 Nov 2013

    Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.

    Source:Tal Argoni
    Published:6 Feb 2007