5.1
    Medium

    CVE-2007-0609

    Last Modified: 4 Dec 2013

    Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.

    Source:netVigilance
    Published:9 May 2007
    4.3
    Medium

    CVE-2007-0605

    Last Modified: 2 Dec 2013

    Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter.

    Source:Jesper Jurcenoks
    Published:9 May 2007
    6.9
    Medium

    CVE-2007-0602

    Last Modified: 23 Apr 2026

    Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533.

    Source:Sebastian Wolfgarten
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0600

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0598

    Last Modified: 20 Sept 2016

    SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.

    Source:DarkFig
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0591

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:GoLd_M
    Published:30 Jan 2007
    5.8
    Medium

    CVE-2007-0590

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0589

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.

    Source:ajann
    Published:30 Jan 2007
    9.3
    Critical

    CVE-2007-0585

    Last Modified: 27 Sept 2016

    include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks.

    Source:GoLd_M
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0584

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:Mehmet Ince
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0581

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:30 Jan 2007
    6.8
    Medium

    CVE-2007-0580

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.

    Source:Mehmet Ince
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0577

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0576

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.

    Source:ThE dE@Th
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0575

    Last Modified: 11 Nov 2013

    Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.

    Source:Cr@zy_King
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0574

    Last Modified: 11 Nov 2013

    SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:St[at]rExT
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0573

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.

    Source:S.W.A.T.
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0572

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:MackRulZ
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0571

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.

    Source:GoLd_M
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0570

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.

    Source:ThE dE@Th
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0568

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.

    Source:Cold Zero
    Published:30 Jan 2007
    6.8
    Medium

    CVE-2007-0567

    Last Modified: 11 Nov 2013

    Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.

    Source:Doz
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:30 Jan 2007
    4.3
    Medium

    CVE-2007-0562

    Last Modified: 23 Apr 2026

    Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.

    Source:shinnai
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0561

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.

    Source:Mehmet Ince
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0560

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Source:ajann
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0559

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.

    Source:3l3ctric-Cracker
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0558

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.

    Source:3l3ctric-Cracker
    Published:30 Jan 2007
    7.5
    High

    CVE-2007-0554

    Last Modified: 21 Sept 2016

    SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:29 Jan 2007
    5
    Medium

    CVE-2007-0548

    Last Modified: 27 Apr 2011

    KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.

    Source:wingthor
    Published:29 Jan 2007
    5
    Medium

    CVE-2007-0540

    Last Modified: 8 Nov 2013

    WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

    Source:Blake Matheny
    Published:29 Jan 2007
    7.5
    High

    CVE-2007-0535

    Last Modified: 23 Apr 2026

    Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:r0ut3r
    Published:26 Jan 2007
    9
    Critical

    CVE-2007-0528

    Last Modified: 23 Apr 2026

    The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

    Source:Adrian _pagvac_ Pastor
    Published:26 Jan 2007
    7.5
    High

    CVE-2007-0518

    Last Modified: 23 Apr 2026

    Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.

    Source:Milos Zivanovic
    Published:26 Jan 2007
    9.3
    Critical

    CVE-2007-0515

    Last Modified: 26 Sept 2016

    Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.

    Source:xCuter
    Published:26 Jan 2007
    6.8
    Medium

    CVE-2007-0511

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.

    Source:3l3ctric-Cracker
    Published:26 Jan 2007
    7.5
    High

    CVE-2007-0508

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.

    Source:3l3ctric-Cracker
    Published:26 Jan 2007
    10
    Critical

    CVE-2007-0504

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.

    Source:r0ut3r
    Published:26 Jan 2007
    7.5
    High

    CVE-2007-0502

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.

    Source:r00t
    Published:25 Jan 2007
    6.8
    Medium

    CVE-2007-0501

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.

    Source:DeltahackingTEAM
    Published:25 Jan 2007
    7.5
    High

    CVE-2007-0500

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:GoLd_M
    Published:25 Jan 2007
    6.8
    Medium

    CVE-2007-0499

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.

    Source:DeltahackingTEAM
    Published:25 Jan 2007
    7.5
    High

    CVE-2007-0498

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.

    Source:3l3ctric-Cracker
    Published:25 Jan 2007
    6.8
    Medium

    CVE-2007-0497

    Last Modified: 20 Sept 2016

    PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.

    Source:y3dips
    Published:25 Jan 2007
    10
    Critical

    CVE-2007-0496

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.

    Source:3l3ctric-Cracker
    Published:25 Jan 2007
    10
    Critical

    CVE-2007-0495

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.

    Source:3l3ctric-Cracker
    Published:25 Jan 2007
    6.8
    Medium

    CVE-2007-0491

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630. NOTE: Some of these details are obtained from third party information.

    Source:3l3ctric-Cracker
    Published:25 Jan 2007
    6.8
    Medium

    CVE-2007-0489

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:bd0rk
    Published:25 Jan 2007