Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-6602

Published Dec 31, 2007

SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6603

Published Dec 31, 2007

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6604

Published Dec 31, 2007

Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6605

Published Dec 31, 2007

Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6606

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6607

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/cus…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6608

Published Dec 31, 2007

Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIR…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6609

Published Dec 31, 2007

Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrar…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6337

Published Dec 31, 2007

Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6595

Published Dec 31, 2007

ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6596

Published Dec 31, 2007

ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6597

Published Dec 31, 2007

Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6565

Published Dec 28, 2007

Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary compo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6566

Published Dec 28, 2007

SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6567

Published Dec 28, 2007

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (do…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6568

Published Dec 28, 2007

PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6573

Published Dec 28, 2007

QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the messag…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6575

Published Dec 28, 2007

SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6576

Published Dec 28, 2007

Multiple SQL injection vulnerabilities in Adult Script 1.6.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) videolink_count.php o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6577

Published Dec 28, 2007

Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 6,516 CVEsPage 1 of 261