Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-6082

Published Nov 22, 2007

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6083

Published Nov 22, 2007

SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6084

Published Nov 22, 2007

SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6085

Published Nov 22, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6086

Published Nov 22, 2007

Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modul…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6087

Published Nov 22, 2007

Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6088

Published Nov 22, 2007

PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6089

Published Nov 22, 2007

PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6090

Published Nov 22, 2007

Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: the provena…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6091

Published Nov 22, 2007

Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6097

Published Nov 22, 2007

Unspecified vulnerability in the ICMP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and remote attack vectors, related to ICMP packe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6098

Published Nov 22, 2007

Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6099

Published Nov 22, 2007

Unspecified vulnerability in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 might leave "media pinholes" open upon a restart of the SIP module, which might make it easier…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6081

Published Nov 21, 2007

AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5612

Published Nov 21, 2007

CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large numb…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6078

Published Nov 21, 2007

Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6079

Published Nov 21, 2007

Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6080

Published Nov 21, 2007

SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. N…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6063

Published Nov 21, 2007

Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 6,516 CVEsPage 22 of 261