VYPR

CVEs

383,661 total · page 7105 of 7,674

  • CVE-2007-6610Jan 3, 2008
    risk 0.00cvss —epss 0.02

    unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument. NOTE: this might only be a vulnerability when unp is invoked by a third…

  • CVE-2007-6602Dec 31, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.

  • CVE-2007-6603Dec 31, 2007
    risk 0.03cvss —epss 0.03

    Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can…

  • CVE-2007-6604Dec 31, 2007
    risk 0.03cvss —epss 0.04

    Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password…

  • CVE-2007-6605Dec 31, 2007
    risk 0.03cvss —epss 0.04

    Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four arguments to the Start method.

  • CVE-2007-6606Dec 31, 2007
    risk 0.00cvss —epss 0.02

    OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

  • CVE-2007-6607Dec 31, 2007
    risk 0.00cvss —epss 0.02

    OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various error messages.

  • CVE-2007-6608Dec 31, 2007
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIRST parameters to admin/staff_del_confirm.php, (3) the name parameter to admin/theme_del_confirm.php,…

  • CVE-2007-6609Dec 31, 2007
    risk 0.03cvss —epss 0.05

    Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

  • CVE-2007-6337Dec 31, 2007
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.

  • CVE-2007-6595Dec 31, 2007
    risk 0.00cvss —epss 0.00

    ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.

  • CVE-2007-6596Dec 31, 2007
    risk 0.00cvss —epss 0.02

    ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.

  • CVE-2007-6597Dec 31, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and (3) the Date parameter to blogs.asp.

  • CVE-2007-6565Dec 28, 2007
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component.

  • CVE-2007-6566Dec 28, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

  • CVE-2007-6567Dec 28, 2007
    risk 0.04cvss —epss 0.07

    Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.

  • CVE-2007-6568Dec 28, 2007
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

  • CVE-2007-6569Dec 28, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.

  • CVE-2007-6570Dec 28, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.

  • CVE-2007-6571Dec 28, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.

  • CVE-2007-6572Dec 28, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.

  • CVE-2007-6573Dec 28, 2007
    risk 0.00cvss —epss 0.02

    QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551.

  • CVE-2007-6574Dec 28, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3)…

  • CVE-2007-6575Dec 28, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.

  • CVE-2007-6576Dec 28, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Adult Script 1.6.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) videolink_count.php or (2) links.php.

  • CVE-2007-6577Dec 28, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.

  • CVE-2007-6578Dec 28, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-6579Dec 28, 2007
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id…

  • CVE-2007-6580Dec 28, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.

  • CVE-2007-6581Dec 28, 2007
    risk 0.03cvss —epss 0.04

    Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4)…

  • CVE-2007-6582Dec 28, 2007
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.

  • CVE-2007-6583Dec 28, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip parameter.

  • CVE-2007-6584Dec 28, 2007
    risk 0.04cvss —epss 0.09

    Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to…

  • CVE-2007-6585Dec 28, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.

  • CVE-2007-6586Dec 28, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.

  • CVE-2007-6587Dec 28, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-6588Dec 28, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows remote attackers to inject arbitrary web script or HTML via the username field in an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2007-6589Dec 28, 2007
    risk 0.00cvss —epss 0.01

    The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a…

  • CVE-2007-6591Dec 28, 2007
    risk 0.00cvss —epss 0.01

    KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the…

  • CVE-2007-6592Dec 28, 2007
    risk 0.00cvss —epss 0.01

    Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into…

  • CVE-2007-6593Dec 28, 2007
    risk 0.04cvss —epss 0.06

    Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3…

  • CVE-2007-6594Dec 28, 2007
    risk 0.00cvss —epss 0.00

    IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan…

  • CVE-2007-6543Dec 28, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-6544Dec 28, 2007
    risk 0.03cvss —epss 0.04

    Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6)…

  • CVE-2007-6545Dec 28, 2007
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav…

  • CVE-2007-6546Dec 28, 2007
    risk 0.03cvss —epss 0.03

    RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.

  • CVE-2007-6547Dec 28, 2007
    risk 0.03cvss —epss 0.02

    RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

  • CVE-2007-6548Dec 28, 2007
    risk 0.04cvss —epss 0.08

    Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (3) the disclaimer parameter…

  • CVE-2007-6549Dec 28, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using."

  • CVE-2007-6550Dec 28, 2007
    risk 0.04cvss —epss 0.07

    form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.