Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0364

Published Jan 19, 2007

Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0365

Published Jan 19, 2007

Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6942

Published Jan 19, 2007

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6943

Published Jan 19, 2007

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6944

Published Jan 19, 2007

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5963

Published Jan 19, 2007

Directory traversal vulnerability in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows user-assisted remote attackers to extract files to arbitrary pathnames via a ../ (dot d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5964

Published Jan 19, 2007

choShilA.bpl in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows local users, and user-assisted remote attackers to cause a denial of service (system crash) by right clickin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0350

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0352

Published Jan 19, 2007

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that beg…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0353

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO str…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0354

Published Jan 19, 2007

SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0357

Published Jan 19, 2007

Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) seque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0358

Published Jan 19, 2007

Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vector…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0359

Published Jan 19, 2007

PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0360

Published Jan 19, 2007

PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0361

Published Jan 19, 2007

PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0362

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecifie…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0363

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6941

Published Jan 19, 2007

index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0349

Published Jan 19, 2007

Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0329

Published Jan 18, 2007

download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallery…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,201-6,225 of 6,516 CVEsPage 249 of 261