2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1850Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitr...
CVE-2007-1849Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local...
CVE-2007-1848Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbi...
CVE-2007-1847SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitra...
CVE-2007-1846SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe...
CVE-2007-1845SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allow...
CVE-2007-1844Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrar...
CVE-2007-1843PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, all...
CVE-2007-1842Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute a...
CVE-2007-0242The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the ...
CVE-2007-1834Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow ...
CVE-2007-1833The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 be...
CVE-2007-1832web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename o...
CVE-2007-1831web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted Q...
CVE-2007-1828Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated user...
CVE-2007-1830Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attacker...
CVE-2007-1829Multiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having...
CVE-2007-1840lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which a...
CVE-2007-1827Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenti...
CVE-2007-1839Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra...
CVE-2007-1838SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to ...
CVE-2007-1837Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH...
CVE-2007-1836The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute ...
CVE-2007-1835PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR de...
CVE-2007-1818PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now