6.8
    Medium

    CVE-2007-0015

    Last Modified: 11 Nov 2016

    Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.

    Source:MoAB
    Published:1 Jan 2007
    2.1
    Low

    CVE-2007-0010

    Last Modified: 12 Nov 2013

    The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.

    Source:Lubomir Kundrak
    Published:10 Jan 2007
    6.9
    Medium

    CVE-2007-0005

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.

    Source:Daniel Roethlisberger
    Published:6 Mar 2007
    4.7
    Medium

    CVE-2007-0001

    Last Modified: 18 Nov 2013

    The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.

    Source:Steve Grubb
    Published:20 Feb 2007
    7.5
    High

    CVE-2006-20001

    Last Modified: 13 Feb 2025

    A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.

    Published:17 Jan 2023
    7.5
    High

    CVE-2006-7247

    Last Modified: 1 Sept 2017

    SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

    Source:rgod
    Published:6 Sept 2012
    9.3
    Critical

    CVE-2006-7236

    Last Modified: 4 Apr 2014

    The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.

    Source:Paul Szabo
    Published:2 Jan 2009
    5
    Medium

    CVE-2006-7235

    Last Modified: 16 Oct 2013

    Teamtek Universal FTP Server 1.0.50 allows remote attackers to cause a denial of service (daemon crash or hang) via (1) multiple STOR (aka PUT) commands, or an MKD command followed by (2) a '*' argument, (3) a '|' argument, (4) spaces, or (5) a long string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Adriel T. Desautels
    Published:11 Dec 2008
    4.6
    Medium

    CVE-2006-7234

    Last Modified: 26 Mar 2014

    Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.

    Source:Piotr Engelking
    Published:3 Oct 2006
    7.5
    High

    CVE-2006-7231

    Last Modified: 5 Oct 2017

    SQL injection vulnerability in display.asp in Civica Software Civica allows remote attackers to execute arbitrary SQL commands via the Entry parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CodeXpLoder'tq
    Published:31 Dec 2006
    6.8
    Medium

    CVE-2006-7222

    Last Modified: 28 Dec 2013

    Buffer overflow in the CFLICStream::_deltachunk function in FLICSource.cpp in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to execute arbitrary code via a crafted FLI file.

    Source:wushi
    Published:28 Aug 2007
    5
    Medium

    CVE-2006-7210

    Last Modified: 23 Apr 2026

    Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.

    Source:Preddy
    Published:27 Jun 2007
    6.8
    Medium

    CVE-2006-7208

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:h4ntu
    Published:26 Jun 2007
    7.8
    High

    CVE-2006-7206

    Last Modified: 30 Sept 2016

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.

    Source:anonymous
    Published:22 Jun 2007
    4.3
    Medium

    CVE-2006-7196

    Last Modified: 29 Dec 2013

    Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

    Source:Tushar Vartak
    Published:26 Apr 2007
    6.8
    Medium

    CVE-2006-7194

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.

    Source:the_day
    Published:18 Apr 2007
    9.3
    Critical

    CVE-2006-7185

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a URL in the relative_root parameter.

    Source:DeltahackingTEAM
    Published:30 Mar 2007
    6.8
    Medium

    CVE-2006-7184

    Last Modified: 11 Oct 2013

    Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Cyber Security
    Published:30 Mar 2007
    10
    Critical

    CVE-2006-7183

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.

    Source:Kacper
    Published:30 Mar 2007
    10
    Critical

    CVE-2006-7173

    Last Modified: 22 Nov 2017

    Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.

    Source:rgod
    Published:20 Mar 2007
    7.5
    High

    CVE-2006-7172

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into $_SERVER['HTTP_PC_REMOTE_ADDR'], or (2) ip parameter.

    Source:rgod
    Published:20 Mar 2007
    7.5
    High

    CVE-2006-7170

    Last Modified: 18 Oct 2013

    Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.

    Source:laurent gaffie
    Published:20 Mar 2007
    6.8
    Medium

    CVE-2006-7169

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.

    Source:Kacper
    Published:20 Mar 2007
    7.5
    High

    CVE-2006-7168

    Last Modified: 8 Oct 2013

    PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:20 Mar 2007
    7.5
    High

    CVE-2006-7167

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ProRat Server 1.9 Fix2 allows remote attackers to bypass the authentication mechanism for remote login via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:evil dabus
    Published:20 Mar 2007
    7.1
    High

    CVE-2006-7157

    Last Modified: 8 Oct 2013

    Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

    Source:JAAScois
    Published:7 Mar 2007
    10
    Critical

    CVE-2006-7156

    Last Modified: 24 Nov 2016

    PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

    Source:Kw3[R]Ln
    Published:7 Mar 2007
    8.5
    High

    CVE-2006-7152

    Last Modified: 16 Sept 2016

    default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.

    Source:ajann
    Published:7 Mar 2007
    10
    Critical

    CVE-2006-7148

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. NOTE: this might be the same issues as CVE-2006-4893.

    Source:Nima Salehi
    Published:7 Mar 2007
    6.8
    Medium

    CVE-2006-7147

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:boecke
    Published:7 Mar 2007
    7.5
    High

    CVE-2006-7146

    Last Modified: 8 Oct 2013

    PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions

    Source:Nima Salehi
    Published:7 Mar 2007
    6
    Medium

    CVE-2006-7141

    Last Modified: 20 Sept 2016

    Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such as (1) utl_file.put_line and (2) utl_file.get_line, a related issue to CVE-2005-0701. NOTE: this issue is disputed by third parties who state that this is due to an insecure configuration instead of an inherent vulnerability

    Source:Marco Ivaldi
    Published:7 Mar 2007
    2.6
    Low

    CVE-2006-7139

    Last Modified: 9 Oct 2013

    Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

    Source:nnp
    Published:7 Mar 2007
    10
    Critical

    CVE-2006-7136

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.

    Source:iss4m
    Published:7 Mar 2007
    7.5
    High

    CVE-2006-7135

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ThE-WoLf-KsA
    Published:7 Mar 2007
    10
    Critical

    CVE-2006-7134

    Last Modified: 16 Sept 2016

    Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Craig Heffner
    Published:6 Mar 2007
    5
    Medium

    CVE-2006-7133

    Last Modified: 20 Oct 2013

    Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.

    Source:Craig Heffner
    Published:6 Mar 2007
    10
    Critical

    CVE-2006-7132

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang parameter to viewticket.php.

    Source:Kw3[R]Ln
    Published:6 Mar 2007
    10
    Critical

    CVE-2006-7131

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP code via the web_root parameter.

    Source:ddoshomo
    Published:6 Mar 2007
    7.5
    High

    CVE-2006-7130

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770.

    Source:k1tk4t
    Published:6 Mar 2007
    2.1
    Low

    CVE-2006-7129

    Last Modified: 16 Oct 2017

    ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files.

    Source:Matousec Transparent security
    Published:6 Mar 2007
    7.5
    High

    CVE-2006-7128

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter.

    Source:Kacper
    Published:6 Mar 2007
    6.8
    Medium

    CVE-2006-7127

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/main.php and (2) forum/headlines.php.

    Source:ThE TiGeR
    Published:6 Mar 2007
    10
    Critical

    CVE-2006-7120

    Last Modified: 9 Oct 2013

    PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. NOTE: this issue might be in phpHtmlLib. NOTE: CVE disputes this issue for proper installations of maintain, since $phphtmllib is set in includes.inc before being used in example6.php

    Source:ERNE
    Published:6 Mar 2007
    7.5
    High

    CVE-2006-7119

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows remote attackers to execute arbitrary PHP code via a URL in the CFG_PHPGIGGLE_ROOT parameter.

    Source:ajann
    Published:6 Mar 2007
    7.5
    High

    CVE-2006-7118

    Last Modified: 17 Oct 2013

    SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Source:Aria-Security Team
    Published:6 Mar 2007
    6.8
    Medium

    CVE-2006-7117

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and (2) read arbitrary files via ".." sequences in the file parameter in an add_dl action to adm_index.php, as demonstrated by reading connect.php.

    Source:BlackHawk
    Published:6 Mar 2007
    7.5
    High

    CVE-2006-7116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php.

    Source:BlackHawk
    Published:6 Mar 2007
    5
    Medium

    CVE-2006-7114

    Last Modified: 23 Apr 2026

    P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. NOTE: this might be the same issue as CVE-2006-6888.

    Source:Lu7k
    Published:6 Mar 2007
    6
    Medium

    CVE-2006-7112

    Last Modified: 4 Nov 2017

    Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.

    Source:Kacper
    Published:6 Mar 2007