2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-1481SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i...
CVE-2007-1480Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php ...
CVE-2007-1479Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject ar...
CVE-2007-1478download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil...
CVE-2007-1477Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to includ...
CVE-2007-1475Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4....
CVE-2007-1474Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Fram...
CVE-2007-1473Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login pa...
CVE-2007-1472Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct ...
CVE-2007-1471admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a ...
CVE-2007-1470Multiple buffer overflows in LIBFtp 5.0 allow user-assisted remote attackers to execute arbitrary code via certain long ...
CVE-2007-1469SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQ...
CVE-2007-1468Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject a...
CVE-2007-1278Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, wh...
CVE-2007-1462The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by sto...
CVE-2007-1449Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary ...
CVE-2007-1450SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL...
CVE-2007-1460The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement s...
CVE-2007-1459Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute...
CVE-2007-1458Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code vi...
CVE-2007-1457Buffer overflow in the urarlib_get function in Christian Scheurer UniquE RAR File Library (unrarlib, aka URARFileLib) 0....
CVE-2007-1456PHP remote file inclusion vulnerability in common.php in PHP Photo Album allows remote attackers to execute arbitrary PH...
CVE-2007-1455Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated use...
CVE-2007-1454ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly stri...
CVE-2007-1453Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows contex...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now