Total
277631 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2007-0695 | 1 Free Lan Intra Internet Portal | 1 Free Lan Intra Internet Portal | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions. | ||||
CVE-2007-0694 | 1 Dian Gemilang | 1 Dgnews | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter. | ||||
CVE-2007-0693 | 1 Dian Gemilang | 1 Dgnews | 2024-11-21 | N/A |
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS). | ||||
CVE-2007-0692 | 1 Dgnews | 1 Dgnews | 2024-11-21 | N/A |
DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages. | ||||
CVE-2007-0690 | 1 Myevent | 1 Myevent | 2024-11-21 | N/A |
myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages. | ||||
CVE-2007-0689 | 1 Mybb | 1 Mybb | 2024-11-21 | N/A |
MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message. | ||||
CVE-2007-0688 | 1 Hunkaray Duyuru | 1 Scripti | 2024-11-21 | N/A |
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2007-0687 | 1 Michelle | 1 L2j Dropcalc | 2024-11-21 | N/A |
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter. | ||||
CVE-2007-0686 | 1 Intel | 1 2200bg Proset Wireless | 2024-11-21 | N/A |
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651. NOTE: this issue might overlap CVE-2006-3992. | ||||
CVE-2007-0685 | 1 Microsoft | 1 Windows Mobile | 2024-11-21 | N/A |
Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow. | ||||
CVE-2007-0684 | 1 Cerulean Portal System | 1 Cerulean Portal System | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | ||||
CVE-2007-0683 | 1 Omegaboard Project | 1 Omegaboard | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | ||||
CVE-2007-0682 | 1 Jv2 | 1 Folder Gallery | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter. | ||||
CVE-2007-0681 | 1 Extcalendar Project | 1 Extcalendar | 2024-11-21 | 9.8 Critical |
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php. | ||||
CVE-2007-0680 | 1 Phpbb Tweaked | 1 Phpbb Tweaked | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | ||||
CVE-2007-0679 | 1 Nicolas Grandjean | 1 Phpmyring | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter. | ||||
CVE-2007-0678 | 1 Fullaspsite | 1 Asp Hosting Site | 2024-11-21 | N/A |
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter. | ||||
CVE-2007-0677 | 1 Cronosys | 1 Cadre Php Framework | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter. | ||||
CVE-2007-0676 | 1 Exo | 1 Exophpdesk | 2024-11-21 | N/A |
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2007-0675 | 1 Microsoft | 1 Windows Vista | 2024-11-21 | N/A |
A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer. |