Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0559

Published Jan 30, 2007

PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0560

Published Jan 30, 2007

SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0561

Published Jan 30, 2007

Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0562

Published Jan 30, 2007

Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0563

Published Jan 30, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0564

Published Jan 30, 2007

The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0565

Published Jan 30, 2007

CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0566

Published Jan 30, 2007

SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0557

Published Jan 29, 2007

rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a differ…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0347

Published Jan 29, 2007

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6965

Published Jan 29, 2007

CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0538

Published Jan 29, 2007

Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0539

Published Jan 29, 2007

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a sourc…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0540

Published Jan 29, 2007

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a bin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0541

Published Jan 29, 2007

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that cor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0542

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0543

Published Jan 29, 2007

ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwor…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0544

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject fiel…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0545

Published Jan 29, 2007

Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords v…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0546

Published Jan 29, 2007

Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0547

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0548

Published Jan 29, 2007

KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0549

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0550

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0551

Published Jan 29, 2007

Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config]…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,001-6,025 of 6,516 CVEsPage 241 of 261