7.5
    High

    CVE-2007-0304

    Last Modified: 21 Sept 2016

    SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:chernobiLe
    Published:18 Jan 2007
    6.8
    Medium

    CVE-2007-0302

    Last Modified: 6 Nov 2013

    Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.

    Source:Doz
    Published:18 Jan 2007
    6.8
    Medium

    CVE-2007-0301

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:ajann
    Published:18 Jan 2007
    6.8
    Medium

    CVE-2007-0300

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Source:GoLd_M
    Published:18 Jan 2007
    6.8
    Medium

    CVE-2007-0298

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter.

    Source:ilker Kandemir
    Published:17 Jan 2007
    4
    Medium

    CVE-2007-0297

    Last Modified: 7 Nov 2013

    Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.

    Source:Esteban Martinez Fayo
    Published:17 Jan 2007
    6.6
    Medium

    CVE-2007-0267

    Last Modified: 12 Nov 2013

    The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function. NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.

    Source:LMH
    Published:17 Jan 2007
    6.6
    Medium

    CVE-2007-0264

    Last Modified: 6 Nov 2013

    Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Umesh Wanve
    Published:16 Jan 2007
    10
    Critical

    CVE-2007-0261

    Last Modified: 23 Apr 2026

    snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.

    Source:rgod
    Published:16 Jan 2007
    7.8
    High

    CVE-2007-0257

    Last Modified: 6 Sept 2016

    Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven. As of 20070120, the original researcher has released demonstration code

    Source:anonymous
    Published:16 Jan 2007
    7.8
    High

    CVE-2007-0256

    Last Modified: 26 Sept 2016

    VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.

    Source:shinnai
    Published:16 Jan 2007
    5
    Medium

    CVE-2007-0247

    Last Modified: 7 Nov 2013

    squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

    Source:David Duncan Ross Palmer
    Published:13 Jan 2007
    6.8
    Medium

    CVE-2007-0243

    Last Modified: 20 Sept 2016

    Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.

    Source:luoluo
    Published:17 Jan 2007
    10
    Critical

    CVE-2007-0236

    Last Modified: 23 Apr 2026

    Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.

    Source:MoAB
    Published:16 Jan 2007
    3.7
    Low

    CVE-2007-0235

    Last Modified: 6 Nov 2013

    Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.

    Source:Liu Qishuai
    Published:14 Jan 2007
    7.5
    High

    CVE-2007-0233

    Last Modified: 21 Sept 2016

    wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

    Source:rgod
    Published:13 Jan 2007
    7.5
    High

    CVE-2007-0232

    Last Modified: 16 Nov 2016

    PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.

    Source:irvian
    Published:13 Jan 2007
    7.2
    High

    CVE-2007-0229

    Last Modified: 12 Nov 2013

    Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.

    Source:LMH
    Published:13 Jan 2007
    5
    Medium

    CVE-2007-0228

    Last Modified: 20 Sept 2016

    The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP port 10618, which triggers a NULL pointer dereference.

    Source:Ethan Hunt
    Published:13 Jan 2007
    7.5
    High

    CVE-2007-0226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter).

    Source:ajann
    Published:13 Jan 2007
    6.8
    Medium

    CVE-2007-0225

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:ajann
    Published:13 Jan 2007
    7.5
    High

    CVE-2007-0224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.

    Source:ajann
    Published:13 Jan 2007
    10
    Critical

    CVE-2007-0217

    Last Modified: 27 Sept 2016

    The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.

    Source:Mathew Rowley
    Published:13 Feb 2007
    9.3
    Critical

    CVE-2007-0216

    Last Modified: 23 Apr 2026

    wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."

    Source:chujwamwdupe
    Published:12 Feb 2008
    10
    Critical

    CVE-2007-0213

    Last Modified: 5 Jul 2019

    Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.

    Source:Charles Truscott
    Published:8 May 2007
    7.5
    High

    CVE-2007-0205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.

    Source:DarkFig
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.

    Source:DarkFig
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0200

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.

    Source:DeltahackingTEAM
    Published:11 Jan 2007
    6.8
    Medium

    CVE-2007-0197

    Last Modified: 20 Sept 2016

    Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.

    Source:MoAB
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0196

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information.

    Source:ajann
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0190

    Last Modified: 4 Nov 2013

    PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.

    Source:IbnuSina
    Published:11 Jan 2007
    6.8
    Medium

    CVE-2007-0183

    Last Modified: 4 Nov 2013

    Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Khalsa
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0182

    Last Modified: 3 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/. NOTE: the include/common_function.php vector is already covered by another candidate from the same date.

    Source:IbnuSina
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0181

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.

    Source:k1tk4t
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0179

    Last Modified: 3 Nov 2013

    SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.

    Source:yorn
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0178

    Last Modified: 4 Nov 2013

    PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.

    Source:rUnViRuS
    Published:11 Jan 2007
    5.1
    Medium

    CVE-2007-0177

    Last Modified: 3 Nov 2013

    Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Moshe Ben-Abu
    Published:11 Jan 2007
    6.8
    Medium

    CVE-2007-0173

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Source:Codebreak
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0172

    Last Modified: 22 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.

    Source:beks
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0171

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.

    Source:GoLd_M
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0170

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.

    Source:bd0rk
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0169

    Last Modified: 10 Mar 2011

    Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.

    Source:Metasploit
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0168

    Last Modified: 5 Nov 2013

    The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.

    Source:Tenable NS
    Published:11 Jan 2007
    7.5
    High

    CVE-2007-0167

    Last Modified: 23 Apr 2026

    Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.

    Source:IbnuSina
    Published:10 Jan 2007
    7.8
    High

    CVE-2007-0165

    Last Modified: 3 Nov 2013

    Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.

    Source:Federico L. Bossi Bonin
    Published:10 Jan 2007
    6.8
    Medium

    CVE-2007-0162

    Last Modified: 20 Sept 2016

    Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.

    Source:MoAB
    Published:10 Jan 2007
    4.1
    Medium

    CVE-2007-0161

    Last Modified: 3 Nov 2013

    The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

    Source:Sowhat
    Published:10 Jan 2007
    6.8
    Medium

    CVE-2007-0148

    Last Modified: 23 Apr 2026

    Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.

    Source:MoAB
    Published:9 Jan 2007
    6.8
    Medium

    CVE-2007-0144

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.

    Source:ajann
    Published:9 Jan 2007
    6.8
    Medium

    CVE-2007-0143

    Last Modified: 21 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.

    Source:Mehmet Ince
    Published:9 Jan 2007