### 1999/CVE 1999 0001 (1999/CVE-1999-0001.md) ### [CVE-1999-0001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0001) ### Description ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/awesome-cve-repo - https://github.com/ChaoticWagon/Llama3.2_CVE - https://github.com/MarcusGutierrez/complex-vulnerabilities - https://github.com/OrlandoNE/NIST_NVD_sh - https://github.com/TheAxumite/Project - https://github.com/TheAxumite/SLOOTH-Security-Vulnerability-Search-and-Management - https://github.com/UNC-Cofires/SystemicCyberRisks - https://github.com/brandon-t-elliott/cve2epss - https://github.com/dogasantos/msfcve - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/flowground/anchore-io-connector - https://github.com/giterlizzi/epss-time-series-feed - https://github.com/jimmyislive/gocve - https://github.com/morpheuslord/CVE-llm_dataset - https://github.com/myishay/cve-fetcher - https://github.com/nzelyn/CVE-llm_dataset-main - https://github.com/prio-n/prio-n-kb-api-samples - https://github.com/quentinmayo/get_nvd_data_from_online_to_csv - https://github.com/splunk-soar-connectors/threatstream --- ### 1999/CVE 1999 0002 (1999/CVE-1999-0002.md) ### [CVE-1999-0002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0002) ### Description Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. ### POC #### Reference No PoCs from references. #### Github - https://github.com/KaanSK/go-epss - https://github.com/equalbandoli/go-epss - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/giterlizzi/epss-time-series-feed - https://github.com/impartialdig/go-epss - https://github.com/jimmyislive/gocve - https://github.com/kaansk/go-epss - https://github.com/perfecttermin/go-epss - https://github.com/quentinmayo/get_nvd_data_from_online_to_csv - https://github.com/slightbaggage/go-epss - https://github.com/unwieldybull/go-epss --- ### 1999/CVE 1999 0003 (1999/CVE-1999-0003.md) ### [CVE-1999-0003](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0003) ### Description Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Kuromesi/Py4CSKG - https://github.com/jimmyislive/gocve --- ### 1999/CVE 1999 0004 (1999/CVE-1999-0004.md) ### [CVE-1999-0004](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0004) ### Description MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook. ### POC #### Reference No PoCs from references. #### Github - https://github.com/jimmyislive/gocve --- ### 1999/CVE 1999 0005 (1999/CVE-1999-0005.md) ### [CVE-1999-0005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0005) ### Description Arbitrary command execution via IMAP buffer overflow in authenticate command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/jimmyislive/gocve --- ### 1999/CVE 1999 0007 (1999/CVE-1999-0007.md) ### [CVE-1999-0007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0007) ### Description Information from SSL-encrypted sessions via PKCS #1. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0016 (1999/CVE-1999-0016.md) ### [CVE-1999-0016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0016) ### Description Land IP denial of service. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/Pommaq/CVE-1999-0016-POC - https://github.com/ascendantlogic/opensims - https://github.com/pexmee/CVE-1999-0016-Land-DOS-tool --- ### 1999/CVE 1999 0019 (1999/CVE-1999-0019.md) ### [CVE-1999-0019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0019) ### Description Delete or create a file via rpc.statd, due to invalid information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/BlackburnHax/inntinn - https://github.com/Heretyc/inntinn --- ### 1999/CVE 1999 0027 (1999/CVE-1999-0027.md) ### [CVE-1999-0027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0027) ### Description root privileges via buffer overflow in eject command on SGI IRIX systems. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Kuromesi/Py4CSKG --- ### 1999/CVE 1999 0028 (1999/CVE-1999-0028.md) ### [CVE-1999-0028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0028) ### Description root privileges via buffer overflow in login/scheme command on SGI IRIX systems. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0046 (1999/CVE-1999-0046.md) ### [CVE-1999-0046](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0046) ### Description Buffer overflow of rlogin program using TERM environmental variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/OWASP/pytm - https://github.com/RachidaSK/pytm-hardware - https://github.com/croates23/pytm-hardware - https://github.com/huhu1235/pytm - https://github.com/izar/pytm - https://github.com/moonlight2566/fghth - https://github.com/royhutw/pytm01 --- ### 1999/CVE 1999 0067 (1999/CVE-1999-0067.md) ### [CVE-1999-0067](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0067) ### Description phf CGI program allows remote command execution through shell metacharacters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ForAllSecure/VulnerabilitiesLab - https://github.com/lauravoicu/Common-Vulnerabilities-Exposures - https://github.com/lauravoicu/Vulnerabilities - https://github.com/lauravoicu/vulnerabilities --- ### 1999/CVE 1999 0070 (1999/CVE-1999-0070.md) ### [CVE-1999-0070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0070) ### Description test-cgi program allows an attacker to list files on the server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/starnightcyber/vul-info-collect --- ### 1999/CVE 1999 0078 (1999/CVE-1999-0078.md) ### [CVE-1999-0078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0078) ### Description pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/AnyMaster/EQGRP - https://github.com/CKmaenn/EQGRP - https://github.com/CybernetiX-S3C/EQGRP_Linux - https://github.com/Drift-Security/Shadow_Brokers-Vs-NSA - https://github.com/IHA114/EQGRP - https://github.com/Mofty/EQGRP - https://github.com/MrAli-Code/EQGRP - https://github.com/Muhammd/EQGRP - https://github.com/Nekkidso/EQGRP - https://github.com/Ninja-Tw1sT/EQGRP - https://github.com/R3K1NG/ShadowBrokersFiles - https://github.com/Soldie/EQGRP-nasa - https://github.com/antiscammerarmy/ShadowBrokersFiles - https://github.com/bensongithub/EQGRP - https://github.com/cipherreborn/SB--.-HACK-the-EQGRP-1 - https://github.com/cyberheartmi9/EQGRP - https://github.com/hackcrypto/EQGRP - https://github.com/happysmack/x0rzEQGRP - https://github.com/kongjiexi/leaked2 - https://github.com/maxcvnd/bdhglopoj - https://github.com/namangangwar/EQGRP - https://github.com/r3p3r/x0rz-EQGRP - https://github.com/readloud/EQGRP - https://github.com/shakenetwork/shadowbrokerstuff - https://github.com/sinloss/EQGRP - https://github.com/thePevertedSpartan/EQ1 - https://github.com/thetrentus/EQGRP - https://github.com/thetrentus/ShadowBrokersStuff - https://github.com/thetrentusdev/shadowbrokerstuff - https://github.com/whoami-a51/secret-tools-nsa - https://github.com/wuvuw/EQGR - https://github.com/x0rz/EQGRP --- ### 1999/CVE 1999 0082 (1999/CVE-1999-0082.md) ### [CVE-1999-0082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0082) ### Description CWD ~root command in ftpd allows root access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CyberSecAI/cve_dedup - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 0084 (1999/CVE-1999-0084.md) ### [CVE-1999-0084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0084) ### Description Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 0088 (1999/CVE-1999-0088.md) ### [CVE-1999-0088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0088) ### Description IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. ### POC #### Reference - http://www-1.ibm.com/services/brs/brspwhub.nsf/advisories/852567CC004F9038852566BF007B6393/$file/ERS-SVA-E01-1998_004_1.txt #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0095 (1999/CVE-1999-0095.md) ### [CVE-1999-0095](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0095) ### Description The debug command in Sendmail is enabled, allowing attackers to execute commands as root. ### POC #### Reference - http://seclists.org/fulldisclosure/2019/Jun/16 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/AnnetteNCF/NVD-CVE-API - https://github.com/Arjit1512/Securin - https://github.com/CyberSecAI/cve_dedup - https://github.com/MSUSEL/msusecl-data-utility - https://github.com/MSUSEL/msusecl-pique-data - https://github.com/MateoRamirezRubio1/crm_vulnerabilities_challenge - https://github.com/Samridh-Gaur/Securin_Samridh_Gaur - https://github.com/Vishallas/custom-cve-api - https://github.com/abxnxsh/cve_securin - https://github.com/andresrueda90/nist_api - https://github.com/d01mittal/NLP-Project - https://github.com/joscanoga/Reto-python-CRM - https://github.com/manojkumarl24/Securin-CVE-API - https://github.com/markyu0401/api-request- - https://github.com/muchdogesec/cve2stix - https://github.com/soumyajitjalua1/NLP_CVE_project --- ### 1999/CVE 1999 0101 (1999/CVE-1999-0101.md) ### [CVE-1999-0101](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0101) ### Description Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/giterlizzi/epss-time-series-feed --- ### 1999/CVE 1999 0103 (1999/CVE-1999-0103.md) ### [CVE-1999-0103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0103) ### Description Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-2014-0239 - https://github.com/vdanen/vex-reader --- ### 1999/CVE 1999 0105 (1999/CVE-1999-0105.md) ### [CVE-1999-0105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0105) ### Description finger allows recursive searches by using a long string of @ symbols. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0105 --- ### 1999/CVE 1999 0107 (1999/CVE-1999-0107.md) ### [CVE-1999-0107](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0107) ### Description Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0130 (1999/CVE-1999-0130.md) ### [CVE-1999-0130](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0130) ### Description Local users can start Sendmail in daemon mode and gain root privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/baangfilip/Cybersecurity-Vulnerability-Viewer --- ### 1999/CVE 1999 0145 (1999/CVE-1999-0145.md) ### [CVE-1999-0145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0145) ### Description Sendmail WIZ command enabled, allowing root access. ### POC #### Reference - http://seclists.org/fulldisclosure/2019/Jun/16 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0154 (1999/CVE-1999-0154.md) ### [CVE-1999-0154](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0154) ### Description IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0156 (1999/CVE-1999-0156.md) ### [CVE-1999-0156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0156) ### Description wu-ftpd FTP daemon allows any user and password combination. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0156 --- ### 1999/CVE 1999 0158 (1999/CVE-1999-0158.md) ### [CVE-1999-0158](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0158) ### Description Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known. ### POC #### Reference - http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0162 (1999/CVE-1999-0162.md) ### [CVE-1999-0162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0162) ### Description The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0162 --- ### 1999/CVE 1999 0163 (1999/CVE-1999-0163.md) ### [CVE-1999-0163](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0163) ### Description In older versions of Sendmail, an attacker could use a pipe character to execute root commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0163 --- ### 1999/CVE 1999 0165 (1999/CVE-1999-0165.md) ### [CVE-1999-0165](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0165) ### Description NFS cache poisoning. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0165 --- ### 1999/CVE 1999 0170 (1999/CVE-1999-0170.md) ### [CVE-1999-0170](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0170) ### Description Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. ### POC #### Reference No PoCs from references. #### Github - https://github.com/4martinez/pentest-kevgir - https://github.com/ARPSyndicate/cve-scores - https://github.com/GabrielNetSec/SOC-Blue-Team - https://github.com/Live-Hack-CVE/CVE-1999-0170 --- ### 1999/CVE 1999 0174 (1999/CVE-1999-0174.md) ### [CVE-1999-0174](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0174) ### Description The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0180 (1999/CVE-1999-0180.md) ### [CVE-1999-0180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0180) ### Description in.rshd allows users to login with a NULL username and execute commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0180 --- ### 1999/CVE 1999 0182 (1999/CVE-1999-0182.md) ### [CVE-1999-0182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0182) ### Description Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Parist0nH1ll/Vulnerabilities-Write-Ups --- ### 1999/CVE 1999 0183 (1999/CVE-1999-0183.md) ### [CVE-1999-0183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0183) ### Description Linux implementations of TFTP would allow access to files outside the restricted directory. ### POC #### Reference No PoCs from references. #### Github - https://github.com/KeerthiYasasvi/Honeypot-Data-Analysis-using-T-pot --- ### 1999/CVE 1999 0192 (1999/CVE-1999-0192.md) ### [CVE-1999-0192](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0192) ### Description Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/AnyMaster/EQGRP - https://github.com/CKmaenn/EQGRP - https://github.com/CybernetiX-S3C/EQGRP_Linux - https://github.com/Drift-Security/Shadow_Brokers-Vs-NSA - https://github.com/IHA114/EQGRP - https://github.com/Mofty/EQGRP - https://github.com/MrAli-Code/EQGRP - https://github.com/Muhammd/EQGRP - https://github.com/Nekkidso/EQGRP - https://github.com/Ninja-Tw1sT/EQGRP - https://github.com/R3K1NG/ShadowBrokersFiles - https://github.com/Soldie/EQGRP-nasa - https://github.com/antiscammerarmy/ShadowBrokersFiles - https://github.com/bensongithub/EQGRP - https://github.com/cipherreborn/SB--.-HACK-the-EQGRP-1 - https://github.com/cyberheartmi9/EQGRP - https://github.com/hackcrypto/EQGRP - https://github.com/happysmack/x0rzEQGRP - https://github.com/kongjiexi/leaked2 - https://github.com/maxcvnd/bdhglopoj - https://github.com/namangangwar/EQGRP - https://github.com/r3p3r/x0rz-EQGRP - https://github.com/readloud/EQGRP - https://github.com/shakenetwork/shadowbrokerstuff - https://github.com/sinloss/EQGRP - https://github.com/thePevertedSpartan/EQ1 - https://github.com/thetrentus/EQGRP - https://github.com/thetrentus/ShadowBrokersStuff - https://github.com/thetrentusdev/shadowbrokerstuff - https://github.com/whoami-a51/secret-tools-nsa - https://github.com/wuvuw/EQGR - https://github.com/x0rz/EQGRP --- ### 1999/CVE 1999 0195 (1999/CVE-1999-0195.md) ### [CVE-1999-0195](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0195) ### Description Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0195 --- ### 1999/CVE 1999 0199 (1999/CVE-1999-0199.md) ### [CVE-1999-0199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0199) ### Description manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/SplashFan/parsers_3rd_year - https://github.com/u91738/cvematch --- ### 1999/CVE 1999 0201 (1999/CVE-1999-0201.md) ### [CVE-1999-0201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0201) ### Description A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chkp-dhouari/CloudGuard-ShiftLeft-CICD - https://github.com/dcambronero/shiftleft - https://github.com/najla-zwawi/SpectrolOpsTest - https://github.com/nilsujma-dev/CloudGuard-ShiftLeft-CICD - https://github.com/p3sky/Cloudguard-Shifleft-CICD - https://github.com/puryersc/shiftleftv2 - https://github.com/puryersc/shiftleftv3 - https://github.com/puryersc/shiftleftv4 --- ### 1999/CVE 1999 0204 (1999/CVE-1999-0204.md) ### [CVE-1999-0204](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0204) ### Description Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0206 (1999/CVE-1999-0206.md) ### [CVE-1999-0206](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0206) ### Description MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/bwmelon97/SE_HW_2 - https://github.com/satbekmyrza/repo-afl-a2 --- ### 1999/CVE 1999 0209 (1999/CVE-1999-0209.md) ### [CVE-1999-0209](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0209) ### Description The SunView (SunTools) selection_svc facility allows remote users to read files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 0210 (1999/CVE-1999-0210.md) ### [CVE-1999-0210](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0210) ### Description Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0211 (1999/CVE-1999-0211.md) ### [CVE-1999-0211](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0211) ### Description Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone. ### POC #### Reference No PoCs from references. #### Github - https://github.com/abeltrar/app_security - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/polinahell/cve-test --- ### 1999/CVE 1999 0220 (1999/CVE-1999-0220.md) ### [CVE-1999-0220](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0220) ### Description Attackers can do a denial of service of IRC by crashing the server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0220 --- ### 1999/CVE 1999 0221 (1999/CVE-1999-0221.md) ### [CVE-1999-0221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0221) ### Description Denial of service of Ascend routers through port 150 (remote administration). ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0221 --- ### 1999/CVE 1999 0224 (1999/CVE-1999-0224.md) ### [CVE-1999-0224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0224) ### Description Denial of service in Windows NT messenger service through a long username. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0224 --- ### 1999/CVE 1999 0225 (1999/CVE-1999-0225.md) ### [CVE-1999-0225](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0225) ### Description Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0232 (1999/CVE-1999-0232.md) ### [CVE-1999-0232](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0232) ### Description Buffer overflow in NCSA WebServer (version 1.5c) gives remote access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0232 --- ### 1999/CVE 1999 0236 (1999/CVE-1999-0236.md) ### [CVE-1999-0236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0236) ### Description ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/starnightcyber/vul-info-collect --- ### 1999/CVE 1999 0242 (1999/CVE-1999-0242.md) ### [CVE-1999-0242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0242) ### Description Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0244 (1999/CVE-1999-0244.md) ### [CVE-1999-0244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0244) ### Description Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0245 (1999/CVE-1999-0245.md) ### [CVE-1999-0245](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0245) ### Description Some configurations of NIS+ in Linux allowed attackers to log in as the user "+". ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0247 (1999/CVE-1999-0247.md) ### [CVE-1999-0247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0247) ### Description Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0248 (1999/CVE-1999-0248.md) ### [CVE-1999-0248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0248) ### Description A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0249 (1999/CVE-1999-0249.md) ### [CVE-1999-0249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0249) ### Description Windows NT RSHSVC program allows remote users to execute arbitrary commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-1999-0249 --- ### 1999/CVE 1999 0250 (1999/CVE-1999-0250.md) ### [CVE-1999-0250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0250) ### Description Denial of service in Qmail through long SMTP commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0251 (1999/CVE-1999-0251.md) ### [CVE-1999-0251](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0251) ### Description Denial of service in talk program allows remote attackers to disrupt a user's display. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0251 --- ### 1999/CVE 1999 0252 (1999/CVE-1999-0252.md) ### [CVE-1999-0252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0252) ### Description Buffer overflow in listserv allows arbitrary command execution. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0256 (1999/CVE-1999-0256.md) ### [CVE-1999-0256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0256) ### Description Buffer overflow in War FTP allows remote execution of commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/PKSJTeam/Metasploit - https://github.com/iricartb/buffer-overflow-warftp-1.65 - https://github.com/x00itachi/metasploit-exploit-search-online --- ### 1999/CVE 1999 0259 (1999/CVE-1999-0259.md) ### [CVE-1999-0259](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0259) ### Description cfingerd lists all users on a system via search.**@target. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0265 (1999/CVE-1999-0265.md) ### [CVE-1999-0265](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0265) ### Description ICMP redirect messages may crash or lock up a host. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Linathimqalo/cloud-honeypot-analysis --- ### 1999/CVE 1999 0266 (1999/CVE-1999-0266.md) ### [CVE-1999-0266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0266) ### Description The info2www CGI script allows remote file access or remote command execution. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0267 (1999/CVE-1999-0267.md) ### [CVE-1999-0267](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0267) ### Description Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0268 (1999/CVE-1999-0268.md) ### [CVE-1999-0268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0268) ### Description MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0269 (1999/CVE-1999-0269.md) ### [CVE-1999-0269](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0269) ### Description Netscape Enterprise servers may list files through the PageServices query. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/jandercalmeida/jangow --- ### 1999/CVE 1999 0274 (1999/CVE-1999-0274.md) ### [CVE-1999-0274](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0274) ### Description Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0278 (1999/CVE-1999-0278.md) ### [CVE-1999-0278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0278) ### Description In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A913 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0281 (1999/CVE-1999-0281.md) ### [CVE-1999-0281](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0281) ### Description Denial of service in IIS using long URLs. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0285 (1999/CVE-1999-0285.md) ### [CVE-1999-0285](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0285) ### Description Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-1999-0285 --- ### 1999/CVE 1999 0291 (1999/CVE-1999-0291.md) ### [CVE-1999-0291](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0291) ### Description The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0291 --- ### 1999/CVE 1999 0298 (1999/CVE-1999-0298.md) ### [CVE-1999-0298](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0298) ### Description ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0334 (1999/CVE-1999-0334.md) ### [CVE-1999-0334](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0334) ### Description In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Akilasanjana/Akila-assessment-1 - https://github.com/Mahithosh27/NVD-CVE-project - https://github.com/Mohith-Ganesh/CVE_API_INTEGRATION - https://github.com/jenniferjes/CVE-Management-App --- ### 1999/CVE 1999 0372 (1999/CVE-1999-0372.md) ### [CVE-1999-0372](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0372) ### Description The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SamanShafigh/vulBERT --- ### 1999/CVE 1999 0391 (1999/CVE-1999-0391.md) ### [CVE-1999-0391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0391) ### Description The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0407 (1999/CVE-1999-0407.md) ### [CVE-1999-0407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0407) ### Description By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0412 (1999/CVE-1999-0412.md) ### [CVE-1999-0412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0412) ### Description In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0415 (1999/CVE-1999-0415.md) ### [CVE-1999-0415](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0415) ### Description The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. ### POC #### Reference - http://www.cisco.com/warp/public/770/7xxconn-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0416 (1999/CVE-1999-0416.md) ### [CVE-1999-0416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0416) ### Description Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port. ### POC #### Reference - http://www.cisco.com/warp/public/770/7xxconn-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0426 (1999/CVE-1999-0426.md) ### [CVE-1999-0426](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0426) ### Description The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/zaydabushamma/zaydabushamma.md --- ### 1999/CVE 1999 0428 (1999/CVE-1999-0428.md) ### [CVE-1999-0428](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0428) ### Description OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 1999/CVE 1999 0449 (1999/CVE-1999-0449.md) ### [CVE-1999-0449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0449) ### Description The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0454 (1999/CVE-1999-0454.md) ### [CVE-1999-0454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0454) ### Description A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/trend-anz/TippingPoint-Open-Patch --- ### 1999/CVE 1999 0497 (1999/CVE-1999-0497.md) ### [CVE-1999-0497](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0497) ### Description Anonymous FTP is enabled. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SaravananM092/nmap-automation - https://github.com/Xernary/vapt-project - https://github.com/letchupkt/nmap-automation - https://github.com/mr-bala-kavi/nmap-automation --- ### 1999/CVE 1999 0502 (1999/CVE-1999-0502.md) ### [CVE-1999-0502](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0502) ### Description A Unix account has a default, null, blank, or missing password. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ahm3dhany/IDS-Evasion - https://github.com/danyk20/pentest --- ### 1999/CVE 1999 0505 (1999/CVE-1999-0505.md) ### [CVE-1999-0505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0505) ### Description A Windows NT domain user or administrator account has a guessable password. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0505 --- ### 1999/CVE 1999 0507 (1999/CVE-1999-0507.md) ### [CVE-1999-0507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0507) ### Description An account on a router, firewall, or other network device has a guessable password. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0507 --- ### 1999/CVE 1999 0509 (1999/CVE-1999-0509.md) ### [CVE-1999-0509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0509) ### Description Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/codeN0mad/Vulnerability-assessment-uneeq-internship- --- ### 1999/CVE 1999 0511 (1999/CVE-1999-0511.md) ### [CVE-1999-0511](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0511) ### Description IP forwarding is enabled on a machine which is not a router or firewall. ### POC #### Reference No PoCs from references. #### Github - https://github.com/anvithalolla/Tesla_PenTest --- ### 1999/CVE 1999 0512 (1999/CVE-1999-0512.md) ### [CVE-1999-0512](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0512) ### Description A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/RedTeamShanks/Local-Network-Vulnerability-Assessment --- ### 1999/CVE 1999 0517 (1999/CVE-1999-0517.md) ### [CVE-1999-0517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0517) ### Description An SNMP community name is the default (e.g. public), null, or missing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/KeerthiYasasvi/Honeypot-Data-Analysis-using-T-pot - https://github.com/ialejandrozalles/InvestigacionAplicacionCVE-1999-0517 --- ### 1999/CVE 1999 0519 (1999/CVE-1999-0519.md) ### [CVE-1999-0519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0519) ### Description A NETBIOS/SMB share password is the default, null, or missing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CodingChatRoom/Advance-Reconnaissance- - https://github.com/gabodelmelo/SEC-Walkthrough-EscalateLinux --- ### 1999/CVE 1999 0523 (1999/CVE-1999-0523.md) ### [CVE-1999-0523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0523) ### Description ICMP echo (ping) is allowed from arbitrary hosts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0523 --- ### 1999/CVE 1999 0524 (1999/CVE-1999-0524.md) ### [CVE-1999-0524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0524) ### Description ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. ### POC #### Reference - https://kc.mcafee.com/corporate/index?page=content&id=SB10053 #### Github - https://github.com/BroccoliSnivy/Internship_Task_3 - https://github.com/Live-Hack-CVE/CVE-1999-0524 - https://github.com/Mishraji1999/nessus-vulnerability-scan-task3 - https://github.com/Nissiuser/Vulnerability-Scan-Report - https://github.com/PARADOX-12/vulnerability_scan - https://github.com/PuddinCat/GithubRepoSpider - https://github.com/Ransc0rp1on/ICMP-Timestamp-POC - https://github.com/RudraSehgal7/Vuln-Management - https://github.com/Sanketjaat/Vulnerability-Scan - https://github.com/Xernary/vapt-project - https://github.com/ayemyatoo/ayemyatoo.github.io - https://github.com/castorio32/Vulnerability-Assessment - https://github.com/hrsyadav88/Task-3 - https://github.com/iyadadalan/iTaleem_CaseStudy - https://github.com/mikemackintosh/ruby-qualys - https://github.com/nazgulsenpai/icmp_filter_kernel_module - https://github.com/noraj/ChronoLeak - https://github.com/threatlabindonesia/CVE-1999-0524-ICMP-Timestamp-and-Address-Mask-Request-Exploit --- ### 1999/CVE 1999 0525 (1999/CVE-1999-0525.md) ### [CVE-1999-0525](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0525) ### Description IP traceroute is allowed from arbitrary hosts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0525 --- ### 1999/CVE 1999 0526 (1999/CVE-1999-0526.md) ### [CVE-1999-0526](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0526) ### Description An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0527 (1999/CVE-1999-0527.md) ### [CVE-1999-0527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0527) ### Description The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. ### POC #### Reference No PoCs from references. #### Github - https://github.com/JavierGomezSanchez/cve_exploits --- ### 1999/CVE 1999 0532 (1999/CVE-1999-0532.md) ### [CVE-1999-0532](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0532) ### Description A DNS server allows zone transfers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/HeiTang/ZYXEl-CTF-WriteUp - https://github.com/Rodney-O-C-Melby/dns-zone-transfer-test - https://github.com/hackingyseguridad/dnszona - https://github.com/websecnl/Bulk_CVE-1999-0532_Scanner --- ### 1999/CVE 1999 0537 (1999/CVE-1999-0537.md) ### [CVE-1999-0537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0537) ### Description A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0537 --- ### 1999/CVE 1999 0541 (1999/CVE-1999-0541.md) ### [CVE-1999-0541](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0541) ### Description A password for accessing a WWW URL is guessable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0541 --- ### 1999/CVE 1999 0546 (1999/CVE-1999-0546.md) ### [CVE-1999-0546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0546) ### Description The Windows NT guest account is enabled. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0546 --- ### 1999/CVE 1999 0550 (1999/CVE-1999-0550.md) ### [CVE-1999-0550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0550) ### Description A router's routing tables can be obtained from arbitrary hosts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0550 --- ### 1999/CVE 1999 0554 (1999/CVE-1999-0554.md) ### [CVE-1999-0554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0554) ### Description NFS exports system-critical data to the world, e.g. / or a password file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/galtjay/WMW-blog-lists --- ### 1999/CVE 1999 0559 (1999/CVE-1999-0559.md) ### [CVE-1999-0559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0559) ### Description A system-critical Unix file or directory has inappropriate permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0559 --- ### 1999/CVE 1999 0561 (1999/CVE-1999-0561.md) ### [CVE-1999-0561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0561) ### Description IIS has the #exec function enabled for Server Side Include (SSI) files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0561 --- ### 1999/CVE 1999 0565 (1999/CVE-1999-0565.md) ### [CVE-1999-0565](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0565) ### Description A Sendmail alias allows input to be piped to a program. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0565 --- ### 1999/CVE 1999 0569 (1999/CVE-1999-0569.md) ### [CVE-1999-0569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0569) ### Description A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0569 --- ### 1999/CVE 1999 0575 (1999/CVE-1999-0575.md) ### [CVE-1999-0575](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0575) ### Description A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0575 --- ### 1999/CVE 1999 0580 (1999/CVE-1999-0580.md) ### [CVE-1999-0580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0580) ### Description The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0580 --- ### 1999/CVE 1999 0581 (1999/CVE-1999-0581.md) ### [CVE-1999-0581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0581) ### Description The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0581 --- ### 1999/CVE 1999 0582 (1999/CVE-1999-0582.md) ### [CVE-1999-0582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0582) ### Description A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0582 --- ### 1999/CVE 1999 0586 (1999/CVE-1999-0586.md) ### [CVE-1999-0586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0586) ### Description A network service is running on a nonstandard port. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0586 --- ### 1999/CVE 1999 0589 (1999/CVE-1999-0589.md) ### [CVE-1999-0589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0589) ### Description A system-critical Windows NT registry key has inappropriate permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0589 --- ### 1999/CVE 1999 0603 (1999/CVE-1999-0603.md) ### [CVE-1999-0603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0603) ### Description In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0603 --- ### 1999/CVE 1999 0611 (1999/CVE-1999-0611.md) ### [CVE-1999-0611](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0611) ### Description A system-critical Windows NT registry key has an inappropriate value. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0611 --- ### 1999/CVE 1999 0612 (1999/CVE-1999-0612.md) ### [CVE-1999-0612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0612) ### Description A version of finger is running that exposes valid user information to any entity on the network. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0612 - https://github.com/lycaleynes/NMAP-and-Wireshark - https://github.com/lycaleynes/Wireshark --- ### 1999/CVE 1999 0613 (1999/CVE-1999-0613.md) ### [CVE-1999-0613](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0613) ### Description The rpc.sprayd service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0613 --- ### 1999/CVE 1999 0624 (1999/CVE-1999-0624.md) ### [CVE-1999-0624](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0624) ### Description The rstat/rstatd service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0624 --- ### 1999/CVE 1999 0626 (1999/CVE-1999-0626.md) ### [CVE-1999-0626](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0626) ### Description A version of rusers is running that exposes valid user information to any entity on the network. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0626 --- ### 1999/CVE 1999 0629 (1999/CVE-1999-0629.md) ### [CVE-1999-0629](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0629) ### Description The ident/identd service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/gabodelmelo/SEC-Walkthrough-EscalateLinux --- ### 1999/CVE 1999 0635 (1999/CVE-1999-0635.md) ### [CVE-1999-0635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0635) ### Description The echo service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/muchdogesec/cve2stix --- ### 1999/CVE 1999 0637 (1999/CVE-1999-0637.md) ### [CVE-1999-0637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0637) ### Description The systat service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0637 --- ### 1999/CVE 1999 0639 (1999/CVE-1999-0639.md) ### [CVE-1999-0639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0639) ### Description The chargen service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0639 --- ### 1999/CVE 1999 0651 (1999/CVE-1999-0651.md) ### [CVE-1999-0651](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0651) ### Description The rsh/rlogin service is running. ### POC #### Reference No PoCs from references. #### Github - https://github.com/223suraj/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation. - https://github.com/ANUSHRIYA123/6604780_ANUSHRIYASAHU_G3 - https://github.com/ANUSHRIYA123/fxrtdrt - https://github.com/Aman0003sarkar/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation - https://github.com/Anshusharma1239/Simulating-Real-World-Network-Exploitation-and-Defense-Anshu.pdf - https://github.com/Bipin3214/Network-Penetration-Testing - https://github.com/Divakar12p/divakar-manda - https://github.com/Harsh-hub1234/Network_penetration_testing - https://github.com/It-iandeepak/CEH-Project - https://github.com/Minakshi1030/Network-Penetration-Testing- - https://github.com/Nohit594/CEH_Project - https://github.com/ParmatmaKumar/Ethical_hacking_project - https://github.com/ParmeshwarSao/Project-EH - https://github.com/Rahul-issar09/CEH-Project- - https://github.com/Raushan95-ui/Network-Penetration-Testing - https://github.com/Ritesh82-rs/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation. - https://github.com/Shivamkishor-123/Network_penetration_testing_projectNetwork_penetration_testing_project - https://github.com/Shivangi231104/MyProjectEH - https://github.com/Shivangi231104/mp - https://github.com/Shobit9431/CEH-Project - https://github.com/Shwetankkarn/Simulating-Real-World-Network-Exploitation-and-Defense. - https://github.com/Somil19-tech/ethical_hacking_project - https://github.com/abhishek-sharma1234/CEH-Final-Project - https://github.com/amphib24/nessus_scan_cysa-_book - https://github.com/bongguy09/Simulating-Real-World-Network-Exploitation-and-Defenses - https://github.com/coolsikandarakr/CEH-Training-Project - https://github.com/devendranirmalkar/Network_penetration_testing_project - https://github.com/dr3amz23/CEH-Project-PiyushVerma - https://github.com/enoughdurgesh/CEH-Project - https://github.com/itsmeanuj311/Ethical-Hacking-Projects - https://github.com/kamleshkumar9931/CEH-College-Project - https://github.com/online122004/Network_penetration_testing_project_2 - https://github.com/tirath08/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation - https://github.com/vinamradutta/Ethical-Hacking-Project- - https://github.com/vinamradutta/vinamradutta-Ethical-Hacking-Project- - https://github.com/vipinkumar62/CEH-Final-Project - https://github.com/yesh2312/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation. --- ### 1999/CVE 1999 0657 (1999/CVE-1999-0657.md) ### [CVE-1999-0657](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0657) ### Description WinGate is being used. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0657 --- ### 1999/CVE 1999 0661 (1999/CVE-1999-0661.md) ### [CVE-1999-0661](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0661) ### Description A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan --- ### 1999/CVE 1999 0663 (1999/CVE-1999-0663.md) ### [CVE-1999-0663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0663) ### Description A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0663 --- ### 1999/CVE 1999 0664 (1999/CVE-1999-0664.md) ### [CVE-1999-0664](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0664) ### Description An application-critical Windows NT registry key has inappropriate permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0664 --- ### 1999/CVE 1999 0665 (1999/CVE-1999-0665.md) ### [CVE-1999-0665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0665) ### Description An application-critical Windows NT registry key has an inappropriate value. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0665 --- ### 1999/CVE 1999 0678 (1999/CVE-1999-0678.md) ### [CVE-1999-0678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0678) ### Description A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/archerysec/archerysec-api-doc - https://github.com/starnightcyber/vul-info-collect --- ### 1999/CVE 1999 0691 (1999/CVE-1999-0691.md) ### [CVE-1999-0691](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0691) ### Description Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3078 #### Github - https://github.com/truefinder/truefinder --- ### 1999/CVE 1999 0710 (1999/CVE-1999-0710.md) ### [CVE-1999-0710](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0710) ### Description The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SplashFan/parsers_3rd_year --- ### 1999/CVE 1999 0716 (1999/CVE-1999-0716.md) ### [CVE-1999-0716](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0716) ### Description Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0736 (1999/CVE-1999-0736.md) ### [CVE-1999-0736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0736) ### Description The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A932 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0749 (1999/CVE-1999-0749.md) ### [CVE-1999-0749](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0749) ### Description Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0754 (1999/CVE-1999-0754.md) ### [CVE-1999-0754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0754) ### Description The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. ### POC #### Reference - http://www.redhat.com/corp/support/errata/inn99_05_22.html #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0755 (1999/CVE-1999-0755.md) ### [CVE-1999-0755](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0755) ### Description Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0789 (1999/CVE-1999-0789.md) ### [CVE-1999-0789](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0789) ### Description Buffer overflow in AIX ftpd in the libc library. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0793 (1999/CVE-1999-0793.md) ### [CVE-1999-0793](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0793) ### Description Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0802 (1999/CVE-1999-0802.md) ### [CVE-1999-0802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0802) ### Description Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0815 (1999/CVE-1999-0815.md) ### [CVE-1999-0815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0815) ### Description Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A952 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0819 (1999/CVE-1999-0819.md) ### [CVE-1999-0819](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0819) ### Description NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0840 (1999/CVE-1999-0840.md) ### [CVE-1999-0840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0840) ### Description Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option. ### POC #### Reference - http://www.securityfocus.com/bid/832 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0841 (1999/CVE-1999-0841.md) ### [CVE-1999-0841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0841) ### Description Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type. ### POC #### Reference - http://www.securityfocus.com/bid/832 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0867 (1999/CVE-1999-0867.md) ### [CVE-1999-0867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0867) ### Description Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0869 (1999/CVE-1999-0869.md) ### [CVE-1999-0869](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0869) ### Description Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-020 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 0874 (1999/CVE-1999-0874.md) ### [CVE-1999-0874](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0874) ### Description Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A915 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0875 (1999/CVE-1999-0875.md) ### [CVE-1999-0875](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0875) ### Description DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0876 (1999/CVE-1999-0876.md) ### [CVE-1999-0876](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0876) ### Description Buffer overflow in Internet Explorer 4.0 via EMBED tag. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0886 (1999/CVE-1999-0886.md) ### [CVE-1999-0886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0886) ### Description The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0892 (1999/CVE-1999-0892.md) ### [CVE-1999-0892](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0892) ### Description Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0892 --- ### 1999/CVE 1999 0893 (1999/CVE-1999-0893.md) ### [CVE-1999-0893](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0893) ### Description userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0893 --- ### 1999/CVE 1999 0894 (1999/CVE-1999-0894.md) ### [CVE-1999-0894](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0894) ### Description Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0894 --- ### 1999/CVE 1999 0898 (1999/CVE-1999-0898.md) ### [CVE-1999-0898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0898) ### Description Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/clearbluejar/cve-markdown-charts --- ### 1999/CVE 1999 0899 (1999/CVE-1999-0899.md) ### [CVE-1999-0899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0899) ### Description The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. ### POC #### Reference No PoCs from references. #### Github - https://github.com/clearbluejar/cve-markdown-charts --- ### 1999/CVE 1999 0901 (1999/CVE-1999-0901.md) ### [CVE-1999-0901](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0901) ### Description ypserv allows a local user to modify the GECOS and login shells of other users. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0901 --- ### 1999/CVE 1999 0906 (1999/CVE-1999-0906.md) ### [CVE-1999-0906](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0906) ### Description Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/OWASP/pytm - https://github.com/RachidaSK/pytm-hardware - https://github.com/croates23/pytm-hardware - https://github.com/huhu1235/pytm - https://github.com/izar/pytm - https://github.com/moonlight2566/fghth - https://github.com/royhutw/pytm01 --- ### 1999/CVE 1999 0910 (1999/CVE-1999-0910.md) ### [CVE-1999-0910](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0910) ### Description Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0918 (1999/CVE-1999-0918.md) ### [CVE-1999-0918](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0918) ### Description Denial of service in various Windows systems via malformed, fragmented IGMP packets. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0920 (1999/CVE-1999-0920.md) ### [CVE-1999-0920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0920) ### Description Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0937 (1999/CVE-1999-0937.md) ### [CVE-1999-0937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0937) ### Description BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0937 --- ### 1999/CVE 1999 0940 (1999/CVE-1999-0940.md) ### [CVE-1999-0940](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0940) ### Description Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0940 --- ### 1999/CVE 1999 0942 (1999/CVE-1999-0942.md) ### [CVE-1999-0942](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0942) ### Description UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0942 --- ### 1999/CVE 1999 0955 (1999/CVE-1999-0955.md) ### [CVE-1999-0955](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0955) ### Description Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0955 --- ### 1999/CVE 1999 0957 (1999/CVE-1999-0957.md) ### [CVE-1999-0957](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0957) ### Description MajorCool mj_key_cache program allows local users to modify files via a symlink attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0957 - https://github.com/Rahu1Singh/securin --- ### 1999/CVE 1999 0958 (1999/CVE-1999-0958.md) ### [CVE-1999-0958](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0958) ### Description sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Ryscith/sudo_ctf_challenge --- ### 1999/CVE 1999 0967 (1999/CVE-1999-0967.md) ### [CVE-1999-0967](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0967) ### Description Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/Live-Hack-CVE/CVE-1999-0967 - https://github.com/xaitax/SploitScan --- ### 1999/CVE 1999 0982 (1999/CVE-1999-0982.md) ### [CVE-1999-0982](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0982) ### Description The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0982 --- ### 1999/CVE 1999 0983 (1999/CVE-1999-0983.md) ### [CVE-1999-0983](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0983) ### Description Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0983 --- ### 1999/CVE 1999 0985 (1999/CVE-1999-0985.md) ### [CVE-1999-0985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0985) ### Description CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0985 --- ### 1999/CVE 1999 0988 (1999/CVE-1999-0988.md) ### [CVE-1999-0988](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0988) ### Description UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0988 --- ### 1999/CVE 1999 0990 (1999/CVE-1999-0990.md) ### [CVE-1999-0990](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0990) ### Description Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0990 --- ### 1999/CVE 1999 0993 (1999/CVE-1999-0993.md) ### [CVE-1999-0993](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0993) ### Description Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0993 --- ### 1999/CVE 1999 0994 (1999/CVE-1999-0994.md) ### [CVE-1999-0994](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0994) ### Description Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0995 (1999/CVE-1999-0995.md) ### [CVE-1999-0995](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0995) ### Description Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 0998 (1999/CVE-1999-0998.md) ### [CVE-1999-0998](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0998) ### Description Cisco Cache Engine allows an attacker to replace content in the cache. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-0998 --- ### 1999/CVE 1999 0999 (1999/CVE-1999-0999.md) ### [CVE-1999-0999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0999) ### Description Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ChaoticWagon/Llama3.2_CVE - https://github.com/morpheuslord/CVE-llm_dataset - https://github.com/nzelyn/CVE-llm_dataset-main --- ### 1999/CVE 1999 1000 (1999/CVE-1999-1000.md) ### [CVE-1999-1000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1000) ### Description The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ChaoticWagon/Llama3.2_CVE - https://github.com/GiovanniMenon/llm4cve - https://github.com/NickP3lle/llm4cve - https://github.com/morpheuslord/CVE-llm_dataset - https://github.com/nzelyn/CVE-llm_dataset-main --- ### 1999/CVE 1999 1001 (1999/CVE-1999-1001.md) ### [CVE-1999-1001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1001) ### Description Cisco Cache Engine allows a remote attacker to gain access via a null username and password. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-1999-1001 --- ### 1999/CVE 1999 1010 (1999/CVE-1999-1010.md) ### [CVE-1999-1010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1010) ### Description An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy. ### POC #### Reference No PoCs from references. #### Github - https://github.com/3lackrush/Evilsays_bot - https://github.com/phx/cvescan --- ### 1999/CVE 1999 1016 (1999/CVE-1999-1016.md) ### [CVE-1999-1016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1016) ### Description Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. ### POC #### Reference - http://www.securityfocus.com/bid/606 #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 1999/CVE 1999 1033 (1999/CVE-1999-1033.md) ### [CVE-1999-1033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1033) ### Description Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 1999/CVE 1999 1035 (1999/CVE-1999-1035.md) ### [CVE-1999-1035](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1035) ### Description IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1052 (1999/CVE-1999-1052.md) ### [CVE-1999-1052](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1052) ### Description Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1053 (1999/CVE-1999-1053.md) ### [CVE-1999-1053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1053) ### Description guestbook.pl cleanses user-inserted SSI commands by removing text between "" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/siunam321/CVE-1999-1053-PoC - https://github.com/siunam321/ysoserial-automate --- ### 1999/CVE 1999 1056 (1999/CVE-1999-1056.md) ### [CVE-1999-1056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1056) ### Description ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1395. Reason: This candidate is a duplicate of CVE-1999-1395. Notes: All CVE users should reference CVE-1999-1395 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/pandatix/nvdapi --- ### 1999/CVE 1999 1057 (1999/CVE-1999-1057.md) ### [CVE-1999-1057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1057) ### Description VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1060 (1999/CVE-1999-1060.md) ### [CVE-1999-1060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1060) ### Description Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SeriouslyCoder/docker-tetrinetx - https://github.com/cmilanf/docker-tetrinetx --- ### 1999/CVE 1999 1079 (1999/CVE-1999-1079.md) ### [CVE-1999-1079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1079) ### Description Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. ### POC #### Reference - http://www-1.ibm.com/servlet/support/manager?rs=0&rt=0&org=apars&doc=08E0B1A1B85472A1852567C90031BB36 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1083 (1999/CVE-1999-1083.md) ### [CVE-1999-1083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1083) ### Description Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1098 (1999/CVE-1999-1098.md) ### [CVE-1999-1098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1098) ### Description Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 1999/CVE 1999 1100 (1999/CVE-1999-1100.md) ### [CVE-1999-1100](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1100) ### Description Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack. ### POC #### Reference - http://www.cisco.com/warp/public/770/pixkey-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1104 (1999/CVE-1999-1104.md) ### [CVE-1999-1104](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1104) ### Description Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords. ### POC #### Reference - http://marc.info/?l=bugtraq&m=88536273725787&w=2 - http://marc.info/?l=ntbugtraq&m=88540877601866&w=2 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1105 (1999/CVE-1999-1105.md) ### [CVE-1999-1105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1105) ### Description Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive. ### POC #### Reference - http://www.zdnet.com/eweek/reviews/1016/tr42bug.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1106 (1999/CVE-1999-1106.md) ### [CVE-1999-1106](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1106) ### Description Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument. ### POC #### Reference - http://www.securityfocus.com/bid/92 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1110 (1999/CVE-1999-1110.md) ### [CVE-1999-1110](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1110) ### Description Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1115 (1999/CVE-1999-1115.md) ### [CVE-1999-1115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1115) ### Description Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh). ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1122 (1999/CVE-1999-1122.md) ### [CVE-1999-1122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1122) ### Description Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Alman368/MNDefender - https://github.com/CamiloEscobar98/DjangoProject - https://github.com/CyberSecAI/cve_dedup - https://github.com/Rahu1Singh/securin - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1123 (1999/CVE-1999-1123.md) ### [CVE-1999-1123](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1123) ### Description The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall. ### POC #### Reference - http://www.cert.org/advisories/CA-1991-07.html #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1125 (1999/CVE-1999-1125.md) ### [CVE-1999-1125](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1125) ### Description Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/RedLotusIV/AutomatedVulnerabilityScanner --- ### 1999/CVE 1999 1132 (1999/CVE-1999-1132.md) ### [CVE-1999-1132](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1132) ### Description Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1157 (1999/CVE-1999-1157.md) ### [CVE-1999-1157](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1157) ### Description Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1175 (1999/CVE-1999-1175.md) ### [CVE-1999-1175](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1175) ### Description Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048. ### POC #### Reference - http://www.cisco.com/warp/public/770/wccpauth-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1177 (1999/CVE-1999-1177.md) ### [CVE-1999-1177](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1177) ### Description Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Alman368/MNDefender --- ### 1999/CVE 1999 1190 (1999/CVE-1999-1190.md) ### [CVE-1999-1190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1190) ### Description Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message. ### POC #### Reference - http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1197 (1999/CVE-1999-1197.md) ### [CVE-1999-1197](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1197) ### Description TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1198 (1999/CVE-1999-1198.md) ### [CVE-1999-1198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1198) ### Description BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1201 (1999/CVE-1999-1201.md) ### [CVE-1999-1201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1201) ### Description Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1205 (1999/CVE-1999-1205.md) ### [CVE-1999-1205](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1205) ### Description nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information. ### POC #### Reference - http://packetstormsecurity.org/advisories/ibm-ers/96-08 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1211 (1999/CVE-1999-1211.md) ### [CVE-1999-1211](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1211) ### Description Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1212 (1999/CVE-1999-1212.md) ### [CVE-1999-1212](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1212) ### Description Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1223 (1999/CVE-1999-1223.md) ### [CVE-1999-1223](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1223) ### Description IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1224 (1999/CVE-1999-1224.md) ### [CVE-1999-1224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1224) ### Description IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information. ### POC #### Reference - http://marc.info/?l=bugtraq&m=87635124302928&w=2 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1234 (1999/CVE-1999-1234.md) ### [CVE-1999-1234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1234) ### Description LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1241 (1999/CVE-1999-1241.md) ### [CVE-1999-1241](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1241) ### Description Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1242 (1999/CVE-1999-1242.md) ### [CVE-1999-1242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1242) ### Description Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges. ### POC #### Reference - http://packetstormsecurity.org/advisories/hpalert/003 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1247 (1999/CVE-1999-1247.md) ### [CVE-1999-1247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1247) ### Description Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges. ### POC #### Reference - http://packetstormsecurity.org/advisories/hpalert/006 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1248 (1999/CVE-1999-1248.md) ### [CVE-1999-1248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1248) ### Description Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges. ### POC #### Reference - http://packetstormsecurity.org/advisories/hpalert/019 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1251 (1999/CVE-1999-1251.md) ### [CVE-1999-1251](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1251) ### Description Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service. ### POC #### Reference - http://packetstormsecurity.org/advisories/hpalert/043 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1258 (1999/CVE-1999-1258.md) ### [CVE-1999-1258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1258) ### Description rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1322 (1999/CVE-1999-1322.md) ### [CVE-1999-1322](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1322) ### Description The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Leonardo-hf/nvd-cli - https://github.com/righel/ms-exchange-version-nse --- ### 1999/CVE 1999 1324 (1999/CVE-1999-1324.md) ### [CVE-1999-1324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1324) ### Description VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing. ### POC #### Reference No PoCs from references. #### Github - https://github.com/jhswartz/cvrfdb --- ### 1999/CVE 1999 1329 (1999/CVE-1999-1329.md) ### [CVE-1999-1329](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1329) ### Description Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges. ### POC #### Reference - http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1332 (1999/CVE-1999-1332.md) ### [CVE-1999-1332](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1332) ### Description gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SplashFan/parsers_3rd_year --- ### 1999/CVE 1999 1334 (1999/CVE-1999-1334.md) ### [CVE-1999-1334](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1334) ### Description Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument. ### POC #### Reference - http://www.redhat.com/support/errata/rh50-errata-general.html#elm #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1376 (1999/CVE-1999-1376.md) ### [CVE-1999-1376](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1376) ### Description Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/notsag-dev/hacking-tools-for-web-developers --- ### 1999/CVE 1999 1391 (1999/CVE-1999-1391.md) ### [CVE-1999-1391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1391) ### Description Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1392 (1999/CVE-1999-1392.md) ### [CVE-1999-1392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1392) ### Description Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges. ### POC #### Reference - http://www.securityfocus.com/bid/9 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1412 (1999/CVE-1999-1412.md) ### [CVE-1999-1412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1412) ### Description A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. ### POC #### Reference No PoCs from references. #### Github - https://github.com/starnightcyber/vul-info-collect --- ### 1999/CVE 1999 1438 (1999/CVE-1999-1438.md) ### [CVE-1999-1438](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1438) ### Description Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1464 (1999/CVE-1999-1464.md) ### [CVE-1999-1464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1464) ### Description Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564. ### POC #### Reference - http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1465 (1999/CVE-1999-1465.md) ### [CVE-1999-1465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1465) ### Description Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862. ### POC #### Reference - http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1467 (1999/CVE-1999-1467.md) ### [CVE-1999-1467](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1467) ### Description Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CyberSecAI/cve_dedup - https://github.com/Sivashankari25/NVD_CVE_API_Securin - https://github.com/joscanoga/Reto-python-CRM - https://github.com/mohitrajsinghit/securin_assignment1 --- ### 1999/CVE 1999 1471 (1999/CVE-1999-1471.md) ### [CVE-1999-1471](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1471) ### Description Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CyberSecAI/cve_dedup - https://github.com/eliasgranderubio/bidDB_downloader - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1485 (1999/CVE-1999-1485.md) ### [CVE-1999-1485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1485) ### Description nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/arunthunderfrost27/CVE-Analayser - https://github.com/arunthunderfrost27/cve_analyzer --- ### 1999/CVE 1999 1506 (1999/CVE-1999-1506.md) ### [CVE-1999-1506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1506) ### Description Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1554 (1999/CVE-1999-1554.md) ### [CVE-1999-1554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1554) ### Description /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/dev-elliotesco/security-cve-mr - https://github.com/joscanoga/Reto-python-CRM --- ### 1999/CVE 1999 1568 (1999/CVE-1999-1568.md) ### [CVE-1999-1568](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1568) ### Description Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. ### POC #### Reference - http://marc.info/?l=bugtraq&m=91981352617720&w=2 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1572 (1999/CVE-1999-1572.md) ### [CVE-1999-1572](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1572) ### Description cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SplashFan/parsers_3rd_year --- ### 1999/CVE 1999 1579 (1999/CVE-1999-1579.md) ### [CVE-1999-1579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1579) ### Description The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1582 (1999/CVE-1999-1582.md) ### [CVE-1999-1582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1582) ### Description By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality. ### POC #### Reference - http://www.cisco.com/warp/public/707/pixest-pub.shtml - http://www.kb.cert.org/vuls/id/6733 #### Github No PoCs found on GitHub currently. --- ### 1999/CVE 1999 1587 (1999/CVE-1999-1587.md) ### [CVE-1999-1587](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1587) ### Description /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xdea/exploits --- ### 1999/CVE 1999 1588 (1999/CVE-1999-1588.md) ### [CVE-1999-1588](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1588) ### Description Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766. ### POC #### Reference - http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 1999/CVE 1999 1598 (1999/CVE-1999-1598.md) ### [CVE-1999-1598](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1598) ### Description ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ChaoticWagon/Llama3.2_CVE - https://github.com/morpheuslord/CVE-llm_dataset - https://github.com/nzelyn/CVE-llm_dataset-main --- ### 2000/CVE 2000 0001 (2000/CVE-2000-0001.md) ### [CVE-2000-0001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0001) ### Description RealMedia server allows remote attackers to cause a denial of service via a long ramgen request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/joocer/ytf --- ### 2000/CVE 2000 0002 (2000/CVE-2000-0002.md) ### [CVE-2000-0002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0002) ### Description Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/dogasantos/msfcve --- ### 2000/CVE 2000 0008 (2000/CVE-2000-0008.md) ### [CVE-2000-0008](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0008) ### Description FTPPro allows local users to read sensitive information, which is stored in plain text. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0008 --- ### 2000/CVE 2000 0010 (2000/CVE-2000-0010.md) ### [CVE-2000-0010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0010) ### Description WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0010 --- ### 2000/CVE 2000 0019 (2000/CVE-2000-0019.md) ### [CVE-2000-0019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0019) ### Description IMail POP3 daemon uses weak encryption, which allows local users to read files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0019 --- ### 2000/CVE 2000 0020 (2000/CVE-2000-0020.md) ### [CVE-2000-0020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0020) ### Description DNS PRO allows remote attackers to conduct a denial of service via a large number of connections. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0020 --- ### 2000/CVE 2000 0028 (2000/CVE-2000-0028.md) ### [CVE-2000-0028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0028) ### Description Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0028 --- ### 2000/CVE 2000 0031 (2000/CVE-2000-0031.md) ### [CVE-2000-0031](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0031) ### Description The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0031 --- ### 2000/CVE 2000 0036 (2000/CVE-2000-0036.md) ### [CVE-2000-0036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0036) ### Description Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0038 (2000/CVE-2000-0038.md) ### [CVE-2000-0038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0038) ### Description glFtpD includes a default glftpd user account with a default password and a UID of 0. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0038 --- ### 2000/CVE 2000 0040 (2000/CVE-2000-0040.md) ### [CVE-2000-0040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0040) ### Description glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0040 --- ### 2000/CVE 2000 0042 (2000/CVE-2000-0042.md) ### [CVE-2000-0042](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0042) ### Description Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/siegfried415/smtp-nel-filter --- ### 2000/CVE 2000 0045 (2000/CVE-2000-0045.md) ### [CVE-2000-0045](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0045) ### Description MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. ### POC #### Reference - http://www.securityfocus.com/bid/926 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0047 (2000/CVE-2000-0047.md) ### [CVE-2000-0047](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0047) ### Description Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0047 --- ### 2000/CVE 2000 0052 (2000/CVE-2000-0052.md) ### [CVE-2000-0052](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0052) ### Description Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack. ### POC #### Reference - http://www.l0pht.com/advisories/pam_advisory #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0053 (2000/CVE-2000-0053.md) ### [CVE-2000-0053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0053) ### Description Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/EdoWhite/CVEtoMS --- ### 2000/CVE 2000 0065 (2000/CVE-2000-0065.md) ### [CVE-2000-0065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0065) ### Description Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0065 --- ### 2000/CVE 2000 0066 (2000/CVE-2000-0066.md) ### [CVE-2000-0066](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0066) ### Description WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0066 --- ### 2000/CVE 2000 0073 (2000/CVE-2000-0073.md) ### [CVE-2000-0073](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0073) ### Description Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0081 (2000/CVE-2000-0081.md) ### [CVE-2000-0081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0081) ### Description Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0081 --- ### 2000/CVE 2000 0089 (2000/CVE-2000-0089.md) ### [CVE-2000-0089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0089) ### Description The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2000/CVE 2000 0098 (2000/CVE-2000-0098.md) ### [CVE-2000-0098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0098) ### Description Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/EdoWhite/CVEtoMS --- ### 2000/CVE 2000 0101 (2000/CVE-2000-0101.md) ### [CVE-2000-0101](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0101) ### Description The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0101 --- ### 2000/CVE 2000 0102 (2000/CVE-2000-0102.md) ### [CVE-2000-0102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0102) ### Description The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0102 --- ### 2000/CVE 2000 0105 (2000/CVE-2000-0105.md) ### [CVE-2000-0105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0105) ### Description Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0109 (2000/CVE-2000-0109.md) ### [CVE-2000-0109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0109) ### Description The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0109 --- ### 2000/CVE 2000 0114 (2000/CVE-2000-0114.md) ### [CVE-2000-0114](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0114) ### Description Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xMe5war/CVE-2000-0114 - https://github.com/0xPugal/One-Liners - https://github.com/0xPugazh/One-Liners - https://github.com/0xfoysal/Tools - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/CVEDB/awesome-cve-repo - https://github.com/Cappricio-Securities/CVE-2000-0114 - https://github.com/Josekutty-K/Josekutty-K - https://github.com/Josekutty-K/frontpage-server-extensions-vulnerability-scanner - https://github.com/Live-Hack-CVE/CVE-2000-0114 - https://github.com/POORVAJA-195/Nuclei-Analysis-main - https://github.com/adhamelhansye/CVE-2000-0114 - https://github.com/bhavesh-pardhi/One-Liner --- ### 2000/CVE 2000 0119 (2000/CVE-2000-0119.md) ### [CVE-2000-0119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0119) ### Description The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection. ### POC #### Reference - http://marc.info/?l=bugtraq&m=94936267131123&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0126 (2000/CVE-2000-0126.md) ### [CVE-2000-0126](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0126) ### Description Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0126 --- ### 2000/CVE 2000 0129 (2000/CVE-2000-0129.md) ### [CVE-2000-0129](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0129) ### Description Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0129 --- ### 2000/CVE 2000 0131 (2000/CVE-2000-0131.md) ### [CVE-2000-0131](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0131) ### Description Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/iricartb/buffer-overflow-warftp-1.65 --- ### 2000/CVE 2000 0134 (2000/CVE-2000-0134.md) ### [CVE-2000-0134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0134) ### Description The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0134 --- ### 2000/CVE 2000 0135 (2000/CVE-2000-0135.md) ### [CVE-2000-0135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0135) ### Description The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0135 --- ### 2000/CVE 2000 0137 (2000/CVE-2000-0137.md) ### [CVE-2000-0137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0137) ### Description The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0137 --- ### 2000/CVE 2000 0142 (2000/CVE-2000-0142.md) ### [CVE-2000-0142](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0142) ### Description The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0142 --- ### 2000/CVE 2000 0143 (2000/CVE-2000-0143.md) ### [CVE-2000-0143](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0143) ### Description The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0143 --- ### 2000/CVE 2000 0170 (2000/CVE-2000-0170.md) ### [CVE-2000-0170](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0170) ### Description Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/mike182/exploit --- ### 2000/CVE 2000 0182 (2000/CVE-2000-0182.md) ### [CVE-2000-0182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0182) ### Description iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2000-0182 --- ### 2000/CVE 2000 0219 (2000/CVE-2000-0219.md) ### [CVE-2000-0219](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0219) ### Description Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt. ### POC #### Reference - https://kc.mcafee.com/corporate/index?page=content&id=SB10053 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0267 (2000/CVE-2000-0267.md) ### [CVE-2000-0267](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0267) ### Description Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. ### POC #### Reference - http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0268 (2000/CVE-2000-0268.md) ### [CVE-2000-0268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0268) ### Description Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot. ### POC #### Reference - http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0275 (2000/CVE-2000-0275.md) ### [CVE-2000-0275](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0275) ### Description CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN. ### POC #### Reference - http://www.l0pht.com/advisories/cc-pinextract.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0296 (2000/CVE-2000-0296.md) ### [CVE-2000-0296](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0296) ### Description fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck. ### POC #### Reference No PoCs from references. #### Github - https://github.com/arunthunderfrost27/CVE-Analayser - https://github.com/arunthunderfrost27/cve_analyzer --- ### 2000/CVE 2000 0298 (2000/CVE-2000-0298.md) ### [CVE-2000-0298](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0298) ### Description The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. ### POC #### Reference No PoCs from references. #### Github - https://github.com/arunthunderfrost27/CVE-Analayser - https://github.com/arunthunderfrost27/cve_analyzer --- ### 2000/CVE 2000 0302 (2000/CVE-2000-0302.md) ### [CVE-2000-0302](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0302) ### Description Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/arunthunderfrost27/CVE-Analayser - https://github.com/arunthunderfrost27/cve_analyzer --- ### 2000/CVE 2000 0304 (2000/CVE-2000-0304.md) ### [CVE-2000-0304](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0304) ### Description Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0325 (2000/CVE-2000-0325.md) ### [CVE-2000-0325](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0325) ### Description The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0342 (2000/CVE-2000-0342.md) ### [CVE-2000-0342](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0342) ### Description Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment." ### POC #### Reference - http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0356 (2000/CVE-2000-0356.md) ### [CVE-2000-0356](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0356) ### Description Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Rahu1Singh/securin --- ### 2000/CVE 2000 0359 (2000/CVE-2000-0359.md) ### [CVE-2000-0359](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0359) ### Description Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. ### POC #### Reference - http://www.securityfocus.com/bid/1248 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0368 (2000/CVE-2000-0368.md) ### [CVE-2000-0368](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0368) ### Description Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. ### POC #### Reference - http://www.cisco.com/warp/public/770/ioshist-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0380 (2000/CVE-2000-0380.md) ### [CVE-2000-0380](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0380) ### Description The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. ### POC #### Reference - http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0384 (2000/CVE-2000-0384.md) ### [CVE-2000-0384](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0384) ### Description NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access. ### POC #### Reference - http://www.l0pht.com/advisories/ipivot7180.html #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0388 (2000/CVE-2000-0388.md) ### [CVE-2000-0388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0388) ### Description Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/joscanoga/Reto-python-CRM - https://github.com/riik-db/cc_hw --- ### 2000/CVE 2000 0405 (2000/CVE-2000-0405.md) ### [CVE-2000-0405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0405) ### Description Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet. ### POC #### Reference - http://www.l0pht.com/advisories/asniff_advisory.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0408 (2000/CVE-2000-0408.md) ### [CVE-2000-0408](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0408) ### Description IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0413 (2000/CVE-2000-0413.md) ### [CVE-2000-0413](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0413) ### Description The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path. ### POC #### Reference No PoCs from references. #### Github - https://github.com/adavarski/DevSecOps-pipeline-python - https://github.com/carlregencia/DevSecOps-pipeline-python --- ### 2000/CVE 2000 0415 (2000/CVE-2000-0415.md) ### [CVE-2000-0415](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0415) ### Description Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0427 (2000/CVE-2000-0427.md) ### [CVE-2000-0427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0427) ### Description The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM. ### POC #### Reference - http://www.l0pht.com/advisories/etoken-piepa.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0428 (2000/CVE-2000-0428.md) ### [CVE-2000-0428](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0428) ### Description Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/39_Trend.asp #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0431 (2000/CVE-2000-0431.md) ### [CVE-2000-0431](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0431) ### Description Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Andreslruiz/prueba-tecnica-emtelco --- ### 2000/CVE 2000 0455 (2000/CVE-2000-0455.md) ### [CVE-2000-0455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0455) ### Description Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/41initialized.asp #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0457 (2000/CVE-2000-0457.md) ### [CVE-2000-0457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0457) ### Description ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0461 (2000/CVE-2000-0461.md) ### [CVE-2000-0461](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0461) ### Description The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Andreslruiz/prueba-tecnica-emtelco --- ### 2000/CVE 2000 0465 (2000/CVE-2000-0465.md) ### [CVE-2000-0465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0465) ### Description Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0488 (2000/CVE-2000-0488.md) ### [CVE-2000-0488](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0488) ### Description Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/siegfried415/smtp-nel-filter --- ### 2000/CVE 2000 0497 (2000/CVE-2000-0497.md) ### [CVE-2000-0497](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0497) ### Description IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. ### POC #### Reference - http://www-4.ibm.com/software/webservers/appserv/efix.html #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0500 (2000/CVE-2000-0500.md) ### [CVE-2000-0500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0500) ### Description The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing. ### POC #### Reference - http://marc.info/?l=bugtraq&m=96161462915381&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0505 (2000/CVE-2000-0505.md) ### [CVE-2000-0505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0505) ### Description The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/LyticOnaope/ZHVA --- ### 2000/CVE 2000 0507 (2000/CVE-2000-0507.md) ### [CVE-2000-0507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0507) ### Description Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/siegfried415/smtp-nel-filter --- ### 2000/CVE 2000 0524 (2000/CVE-2000-0524.md) ### [CVE-2000-0524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0524) ### Description Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0535 (2000/CVE-2000-0535.md) ### [CVE-2000-0535](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0535) ### Description OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2000/CVE 2000 0538 (2000/CVE-2000-0538.md) ### [CVE-2000-0538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0538) ### Description ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password. ### POC #### Reference - http://marc.info/?l=bugtraq&m=96045469627806&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0564 (2000/CVE-2000-0564.md) ### [CVE-2000-0564](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0564) ### Description The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/CamiloEscobar98/DjangoProject - https://github.com/jairoCO10/security_management --- ### 2000/CVE 2000 0567 (2000/CVE-2000-0567.md) ### [CVE-2000-0567](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0567) ### Description Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0573 (2000/CVE-2000-0573.md) ### [CVE-2000-0573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0573) ### Description The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/AtokTajuddin/BOAR_Project --- ### 2000/CVE 2000 0580 (2000/CVE-2000-0580.md) ### [CVE-2000-0580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0580) ### Description Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0613 (2000/CVE-2000-0613.md) ### [CVE-2000-0613](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0613) ### Description Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections. ### POC #### Reference - http://www.cisco.com/warp/public/707/pixtcpreset-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0621 (2000/CVE-2000-0621.md) ### [CVE-2000-0621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0621) ### Description Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0622 (2000/CVE-2000-0622.md) ### [CVE-2000-0622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0622) ### Description Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter. ### POC #### Reference - http://www.nai.com/research/covert/advisories/043.asp #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0625 (2000/CVE-2000-0625.md) ### [CVE-2000-0625](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0625) ### Description NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password. ### POC #### Reference - http://www.l0pht.com/advisories/netzero.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0631 (2000/CVE-2000-0631.md) ### [CVE-2000-0631](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0631) ### Description An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0632 (2000/CVE-2000-0632.md) ### [CVE-2000-0632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0632) ### Description Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string. ### POC #### Reference - http://www.nai.com/nai_labs/asp_set/advisory/43_Advisory.asp #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0635 (2000/CVE-2000-0635.md) ### [CVE-2000-0635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0635) ### Description The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters. ### POC #### Reference - http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0649 (2000/CVE-2000-0649.md) ### [CVE-2000-0649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0649) ### Description IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xNVAN/win-iisadmin - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/Downgraderz/PoC-CVE-2000-0649 - https://github.com/JimboJimbabwe/HackGPTV2 - https://github.com/amtzespinosa/lord-of-the-root-walkthrough - https://github.com/hanmin0512/Web-hacking-LAB - https://github.com/kaif9711/Comprehensive-Penetration-Testing-on-Publisher-Linux-System- - https://github.com/n-ventory/win-iisadmin - https://github.com/rafaelh/CVE-2000-0649 - https://github.com/stevenvegar/cve-2000-0649 --- ### 2000/CVE 2000 0653 (2000/CVE-2000-0653.md) ### [CVE-2000-0653](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0653) ### Description Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2000/CVE 2000 0660 (2000/CVE-2000-0660.md) ### [CVE-2000-0660](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0660) ### Description The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. ### POC #### Reference - http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0672 (2000/CVE-2000-0672.md) ### [CVE-2000-0672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0672) ### Description The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2000/CVE 2000 0673 (2000/CVE-2000-0673.md) ### [CVE-2000-0673](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0673) ### Description The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability. ### POC #### Reference - http://www.nai.com/research/covert/advisories/044.asp #### Github - https://github.com/beniah2/Nmap-scanning-project --- ### 2000/CVE 2000 0678 (2000/CVE-2000-0678.md) ### [CVE-2000-0678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0678) ### Description PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate. ### POC #### Reference No PoCs from references. #### Github - https://github.com/hannob/pgpbugs --- ### 2000/CVE 2000 0681 (2000/CVE-2000-0681.md) ### [CVE-2000-0681](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0681) ### Description Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0697 (2000/CVE-2000-0697.md) ### [CVE-2000-0697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0697) ### Description The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0700 (2000/CVE-2000-0700.md) ### [CVE-2000-0700](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0700) ### Description Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets. ### POC #### Reference - http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0703 (2000/CVE-2000-0703.md) ### [CVE-2000-0703](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0703) ### Description suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence. ### POC #### Reference No PoCs from references. #### Github - https://github.com/c-skills/CVEs --- ### 2000/CVE 2000 0709 (2000/CVE-2000-0709.md) ### [CVE-2000-0709](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0709) ### Description The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name. ### POC #### Reference No PoCs from references. #### Github - https://github.com/adavarski/DevSecOps-pipeline-python - https://github.com/carlregencia/DevSecOps-pipeline-python --- ### 2000/CVE 2000 0710 (2000/CVE-2000-0710.md) ### [CVE-2000-0710](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0710) ### Description The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. ### POC #### Reference No PoCs from references. #### Github - https://github.com/adavarski/DevSecOps-pipeline-python - https://github.com/carlregencia/DevSecOps-pipeline-python --- ### 2000/CVE 2000 0759 (2000/CVE-2000-0759.md) ### [CVE-2000-0759](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0759) ### Description Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2000/CVE 2000 0760 (2000/CVE-2000-0760.md) ### [CVE-2000-0760](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0760) ### Description The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/cve-scores - https://github.com/cyb3r-w0lf/nuclei-template-collection - https://github.com/m3n0sd0n4ld/uCVE --- ### 2000/CVE 2000 0778 (2000/CVE-2000-0778.md) ### [CVE-2000-0778](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0778) ### Description IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A927 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0825 (2000/CVE-2000-0825.md) ### [CVE-2000-0825](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0825) ### Description Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0834 (2000/CVE-2000-0834.md) ### [CVE-2000-0834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0834) ### Description The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Cruxer8Mech/Idk - https://github.com/ycdxsb/WindowsPrivilegeEscalation --- ### 2000/CVE 2000 0839 (2000/CVE-2000-0839.md) ### [CVE-2000-0839](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0839) ### Description WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515). ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0848 (2000/CVE-2000-0848.md) ### [CVE-2000-0848](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0848) ### Description Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. ### POC #### Reference - http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0854 (2000/CVE-2000-0854.md) ### [CVE-2000-0854](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0854) ### Description When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0867 (2000/CVE-2000-0867.md) ### [CVE-2000-0867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0867) ### Description Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2000-061.html #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0884 (2000/CVE-2000-0884.md) ### [CVE-2000-0884](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0884) ### Description IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/mokrani-zahir/stock --- ### 2000/CVE 2000 0885 (2000/CVE-2000-0885.md) ### [CVE-2000-0885](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0885) ### Description Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0886 (2000/CVE-2000-0886.md) ### [CVE-2000-0886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0886) ### Description IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0892 (2000/CVE-2000-0892.md) ### [CVE-2000-0892](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0892) ### Description Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL. ### POC #### Reference - http://www.kb.cert.org/vuls/id/22404 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 0917 (2000/CVE-2000-0917.md) ### [CVE-2000-0917](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0917) ### Description Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/LEXUEYE/oinkmaster - https://github.com/davidliu88/oinkmaster - https://github.com/zer0duck/oinkmaster --- ### 2000/CVE 2000 0920 (2000/CVE-2000-0920.md) ### [CVE-2000-0920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0920) ### Description Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "." ### POC #### Reference No PoCs from references. #### Github - https://github.com/Knighthana/YABWF --- ### 2000/CVE 2000 0935 (2000/CVE-2000-0935.md) ### [CVE-2000-0935](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0935) ### Description Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Parist0nH1ll/Vulnerabilities-Write-Ups --- ### 2000/CVE 2000 0936 (2000/CVE-2000-0936.md) ### [CVE-2000-0936](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0936) ### Description Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Parist0nH1ll/Vulnerabilities-Write-Ups --- ### 2000/CVE 2000 0942 (2000/CVE-2000-0942.md) ### [CVE-2000-0942](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0942) ### Description The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0975 (2000/CVE-2000-0975.md) ### [CVE-2000-0975](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0975) ### Description Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 0979 (2000/CVE-2000-0979.md) ### [CVE-2000-0979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0979) ### Description File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A996 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Ascotbe/Kernelhub - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/Cruxer8Mech/Idk - https://github.com/Z6543/CVE-2000-0979 - https://github.com/ycdxsb/WindowsPrivilegeEscalation --- ### 2000/CVE 2000 0984 (2000/CVE-2000-0984.md) ### [CVE-2000-0984](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0984) ### Description The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. ### POC #### Reference - http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/NCNU-OpenSource/Web-Vulnerability --- ### 2000/CVE 2000 0998 (2000/CVE-2000-0998.md) ### [CVE-2000-0998](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0998) ### Description Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/truefinder/truefinder --- ### 2000/CVE 2000 0999 (2000/CVE-2000-0999.md) ### [CVE-2000-0999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0999) ### Description Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan --- ### 2000/CVE 2000 1022 (2000/CVE-2000-1022.md) ### [CVE-2000-1022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1022) ### Description The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands. ### POC #### Reference - http://www.cisco.com/warp/public/707/PIXfirewallSMTPfilter-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1033 (2000/CVE-2000-1033.md) ### [CVE-2000-1033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1033) ### Description Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users. ### POC #### Reference No PoCs from references. #### Github - https://github.com/RJSOG/cve-scrapper --- ### 2000/CVE 2000 1034 (2000/CVE-2000-1034.md) ### [CVE-2000-1034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1034) ### Description Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. ### POC #### Reference - http://www.securityfocus.com/bid/1899 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1038 (2000/CVE-2000-1038.md) ### [CVE-2000-1038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1038) ### Description The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request. ### POC #### Reference - http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1039 (2000/CVE-2000-1039.md) ### [CVE-2000-1039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1039) ### Description Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Eplox/TCP-Starvation --- ### 2000/CVE 2000 1049 (2000/CVE-2000-1049.md) ### [CVE-2000-1049](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1049) ### Description Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97310314724964&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1050 (2000/CVE-2000-1050.md) ### [CVE-2000-1050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1050) ### Description Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash"). ### POC #### Reference - http://marc.info/?l=bugtraq&m=97236316510117&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1053 (2000/CVE-2000-1053.md) ### [CVE-2000-1053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1053) ### Description Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97236125107957&w=2 #### Github - https://github.com/octane23/CASE-STUDY-1 --- ### 2000/CVE 2000 1054 (2000/CVE-2000-1054.md) ### [CVE-2000-1054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1054) ### Description Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet. ### POC #### Reference - http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1055 (2000/CVE-2000-1055.md) ### [CVE-2000-1055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1055) ### Description Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. ### POC #### Reference - http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1056 (2000/CVE-2000-1056.md) ### [CVE-2000-1056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1056) ### Description CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords. ### POC #### Reference - http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1079 (2000/CVE-2000-1079.md) ### [CVE-2000-1079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1079) ### Description Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. ### POC #### Reference - http://www.nai.com/research/covert/advisories/045.asp #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1081 (2000/CVE-2000-1081.md) ### [CVE-2000-1081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1081) ### Description The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570878710037&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1082 (2000/CVE-2000-1082.md) ### [CVE-2000-1082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1082) ### Description The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570878710037&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1083 (2000/CVE-2000-1083.md) ### [CVE-2000-1083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1083) ### Description The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570878710037&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1084 (2000/CVE-2000-1084.md) ### [CVE-2000-1084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1084) ### Description The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570878710037&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1085 (2000/CVE-2000-1085.md) ### [CVE-2000-1085](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1085) ### Description The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570884410184&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1086 (2000/CVE-2000-1086.md) ### [CVE-2000-1086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1086) ### Description The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570884410184&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1087 (2000/CVE-2000-1087.md) ### [CVE-2000-1087](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1087) ### Description The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570884410184&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1088 (2000/CVE-2000-1088.md) ### [CVE-2000-1088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1088) ### Description The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97570884410184&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1089 (2000/CVE-2000-1089.md) ### [CVE-2000-1089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1089) ### Description Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 1094 (2000/CVE-2000-1094.md) ### [CVE-2000-1094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1094) ### Description Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument. ### POC #### Reference No PoCs from references. #### Github - https://github.com/RealVulnerabilityEdu/webvulmap - https://github.com/huichen-cs/seceduknwlmap4900 - https://github.com/jeffreyz69/CISC4900 - https://github.com/mrgzf233/4900Project - https://github.com/mrgzf233/CISC-4900 --- ### 2000/CVE 2000 1095 (2000/CVE-2000-1095.md) ### [CVE-2000-1095](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1095) ### Description modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/c-skills/CVEs --- ### 2000/CVE 2000 1103 (2000/CVE-2000-1103.md) ### [CVE-2000-1103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1103) ### Description rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line. ### POC #### Reference - http://www.securityfocus.com/archive/1/147120 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1105 (2000/CVE-2000-1105.md) ### [CVE-2000-1105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1105) ### Description The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 1134 (2000/CVE-2000-1134.md) ### [CVE-2000-1134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1134) ### Description Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/lucassbeiler/linux_hardening_arsenal --- ### 2000/CVE 2000 1196 (2000/CVE-2000-1196.md) ### [CVE-2000-1196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1196) ### Description PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter. ### POC #### Reference - http://packetstormsecurity.org/0004-exploits/ooo1.txt #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1207 (2000/CVE-2000-1207.md) ### [CVE-2000-1207](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1207) ### Description userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844). ### POC #### Reference - http://marc.info/?l=bugtraq&m=97034397026473&w=2 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1209 (2000/CVE-2000-1209.md) ### [CVE-2000-1209](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1209) ### Description The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2000/CVE 2000 1210 (2000/CVE-2000-1210.md) ### [CVE-2000-1210](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1210) ### Description Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2000/CVE 2000 1216 (2000/CVE-2000-1216.md) ### [CVE-2000-1216](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1216) ### Description Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine. ### POC #### Reference - http://www.kb.cert.org/vuls/id/433499 #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1220 (2000/CVE-2000-1220.md) ### [CVE-2000-1220](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1220) ### Description The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file. ### POC #### Reference - http://www.l0pht.com/advisories/lpd_advisory #### Github - https://github.com/Live-Hack-CVE/CVE-2001-1583 --- ### 2000/CVE 2000 1221 (2000/CVE-2000-1221.md) ### [CVE-2000-1221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1221) ### Description The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP. ### POC #### Reference - http://www.l0pht.com/advisories/lpd_advisory #### Github No PoCs found on GitHub currently. --- ### 2000/CVE 2000 1233 (2000/CVE-2000-1233.md) ### [CVE-2000-1233](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1233) ### Description SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Alman368/MNDefender --- ### 2000/CVE 2000 1234 (2000/CVE-2000-1234.md) ### [CVE-2000-1234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1234) ### Description violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SarahX/DWF-Documentation - https://github.com/kurtseifried/gsd-data-enrichment --- ### 2000/CVE 2000 1236 (2000/CVE-2000-1236.md) ### [CVE-2000-1236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1236) ### Description SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Alman368/MNDefender --- ### 2000/CVE 2000 1254 (2000/CVE-2000-1254.md) ### [CVE-2000-1254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1254) ### Description crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2001/CVE 2001 0002 (2001/CVE-2001-0002.md) ### [CVE-2001-0002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0002) ### Description Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/joocer/ytf --- ### 2001/CVE 2001 0004 (2001/CVE-2001-0004.md) ### [CVE-2001-0004](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0004) ### Description IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0010 (2001/CVE-2001-0010.md) ### [CVE-2001-0010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0010) ### Description Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. ### POC #### Reference - http://www.nai.com/research/covert/advisories/047.asp #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/krlabs/dnsbind-vulnerabilities --- ### 2001/CVE 2001 0011 (2001/CVE-2001-0011.md) ### [CVE-2001-0011](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0011) ### Description Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. ### POC #### Reference - http://www.nai.com/research/covert/advisories/047.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0012 (2001/CVE-2001-0012.md) ### [CVE-2001-0012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0012) ### Description BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables. ### POC #### Reference - http://www.nai.com/research/covert/advisories/047.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0013 (2001/CVE-2001-0013.md) ### [CVE-2001-0013](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0013) ### Description Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. ### POC #### Reference - http://www.nai.com/research/covert/advisories/047.asp #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0018 (2001/CVE-2001-0018.md) ### [CVE-2001-0018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0018) ### Description Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0019 (2001/CVE-2001-0019.md) ### [CVE-2001-0019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0019) ### Description Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. ### POC #### Reference - http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0020 (2001/CVE-2001-0020.md) ### [CVE-2001-0020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0020) ### Description Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. ### POC #### Reference - http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0041 (2001/CVE-2001-0041.md) ### [CVE-2001-0041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0041) ### Description Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. ### POC #### Reference - http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0055 (2001/CVE-2001-0055.md) ### [CVE-2001-0055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0055) ### Description CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0056 (2001/CVE-2001-0056.md) ### [CVE-2001-0056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0056) ### Description The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0057 (2001/CVE-2001-0057.md) ### [CVE-2001-0057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0057) ### Description Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0058 (2001/CVE-2001-0058.md) ### [CVE-2001-0058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0058) ### Description The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0060 (2001/CVE-2001-0060.md) ### [CVE-2001-0060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0060) ### Description Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2000-129.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0080 (2001/CVE-2001-0080.md) ### [CVE-2001-0080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0080) ### Description Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error. ### POC #### Reference - http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0096 (2001/CVE-2001-0096.md) ### [CVE-2001-0096](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0096) ### Description FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0103 (2001/CVE-2001-0103.md) ### [CVE-2001-0103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0103) ### Description CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SamanShafigh/vulBERT --- ### 2001/CVE 2001 0115 (2001/CVE-2001-0115.md) ### [CVE-2001-0115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0115) ### Description Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97934312727101&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0122 (2001/CVE-2001-0122.md) ### [CVE-2001-0122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0122) ### Description Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. ### POC #### Reference - http://www-4.ibm.com/software/webservers/security.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0134 (2001/CVE-2001-0134.md) ### [CVE-2001-0134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0134) ### Description Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97967435023835&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0136 (2001/CVE-2001-0136.md) ### [CVE-2001-0136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0136) ### Description Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SamanShafigh/vulBERT --- ### 2001/CVE 2001 0144 (2001/CVE-2001-0144.md) ### [CVE-2001-0144](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0144) ### Description CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- - https://github.com/phx/cvescan --- ### 2001/CVE 2001 0145 (2001/CVE-2001-0145.md) ### [CVE-2001-0145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0145) ### Description Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 0149 (2001/CVE-2001-0149.md) ### [CVE-2001-0149](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0149) ### Description Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 0151 (2001/CVE-2001-0151.md) ### [CVE-2001-0151](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0151) ### Description IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A90 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0154 (2001/CVE-2001-0154.md) ### [CVE-2001-0154](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0154) ### Description HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0167 (2001/CVE-2001-0167.md) ### [CVE-2001-0167](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0167) ### Description Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0228 (2001/CVE-2001-0228.md) ### [CVE-2001-0228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0228) ### Description Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request. ### POC #### Reference - http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0236 (2001/CVE-2001-0236.md) ### [CVE-2001-0236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0236) ### Description Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/AnyMaster/EQGRP - https://github.com/Badbug6/EQGRP - https://github.com/CKmaenn/EQGRP - https://github.com/CybernetiX-S3C/EQGRP_Linux - https://github.com/Drift-Security/Shadow_Brokers-Vs-NSA - https://github.com/IHA114/EQGRP - https://github.com/Mofty/EQGRP - https://github.com/MrAli-Code/EQGRP - https://github.com/Muhammd/EQGRP - https://github.com/Nekkidso/EQGRP - https://github.com/Ninja-Tw1sT/EQGRP - https://github.com/R3K1NG/ShadowBrokersFiles - https://github.com/Soldie/EQGRP-nasa - https://github.com/antiscammerarmy/ShadowBrokersFiles - https://github.com/bensongithub/EQGRP - https://github.com/bl4ck4t/Tools - https://github.com/cipherreborn/SB--.-HACK-the-EQGRP-1 - https://github.com/cyberheartmi9/EQGRP - https://github.com/hackcrypto/EQGRP - https://github.com/happysmack/x0rzEQGRP - https://github.com/kongjiexi/leaked2 - https://github.com/maxcvnd/bdhglopoj - https://github.com/namangangwar/EQGRP - https://github.com/r3p3r/x0rz-EQGRP - https://github.com/readloud/EQGRP - https://github.com/shakenetwork/shadowbrokerstuff - https://github.com/sinloss/EQGRP - https://github.com/thePevertedSpartan/EQ1 - https://github.com/thetrentus/EQGRP - https://github.com/thetrentus/ShadowBrokersStuff - https://github.com/thetrentusdev/shadowbrokerstuff - https://github.com/whoami-a51/secret-tools-nsa - https://github.com/wuvuw/EQGR - https://github.com/x0rz/EQGRP --- ### 2001/CVE 2001 0241 (2001/CVE-2001-0241.md) ### [CVE-2001-0241](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0241) ### Description Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0. ### POC #### Reference - http://marc.info/?l=bugtraq&m=98874912915948&w=2 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/ret2eax/exploits --- ### 2001/CVE 2001 0247 (2001/CVE-2001-0247.md) ### [CVE-2001-0247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0247) ### Description Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. ### POC #### Reference - http://www.nai.com/research/covert/advisories/048.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0248 (2001/CVE-2001-0248.md) ### [CVE-2001-0248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0248) ### Description Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings. ### POC #### Reference - http://www.nai.com/research/covert/advisories/048.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0249 (2001/CVE-2001-0249.md) ### [CVE-2001-0249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0249) ### Description Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. ### POC #### Reference - http://www.nai.com/research/covert/advisories/048.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0288 (2001/CVE-2001-0288.md) ### [CVE-2001-0288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0288) ### Description Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. ### POC #### Reference - http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0307 (2001/CVE-2001-0307.md) ### [CVE-2001-0307](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0307) ### Description Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. ### POC #### Reference - http://www.geocities.com/gzhangx/websrv/docs/security.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0308 (2001/CVE-2001-0308.md) ### [CVE-2001-0308](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0308) ### Description UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program. ### POC #### Reference - http://www.geocities.com/gzhangx/websrv/docs/security.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0319 (2001/CVE-2001-0319.md) ### [CVE-2001-0319](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0319) ### Description orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability. ### POC #### Reference - http://www-4.ibm.com/software/webservers/commerce/netcomletter.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0323 (2001/CVE-2001-0323.md) ### [CVE-2001-0323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0323) ### Description The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host. ### POC #### Reference - http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 - http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0328 (2001/CVE-2001-0328.md) ### [CVE-2001-0328](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0328) ### Description TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. ### POC #### Reference - http://securityreason.com/securityalert/57 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0341 (2001/CVE-2001-0341.md) ### [CVE-2001-0341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0341) ### Description Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. ### POC #### Reference - http://marc.info/?l=bugtraq&m=99348216322147&w=2 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0348 (2001/CVE-2001-0348.md) ### [CVE-2001-0348](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0348) ### Description Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0375 (2001/CVE-2001-0375.md) ### [CVE-2001-0375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0375) ### Description Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests. ### POC #### Reference - http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0385 (2001/CVE-2001-0385.md) ### [CVE-2001-0385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0385) ### Description GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. ### POC #### Reference - http://freecode.com/projects/embedthis-goahead-webserver/releases/343539 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0412 (2001/CVE-2001-0412.md) ### [CVE-2001-0412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0412) ### Description Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode. ### POC #### Reference - http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0414 (2001/CVE-2001-0414.md) ### [CVE-2001-0414](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0414) ### Description Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument. ### POC #### Reference - http://marc.info/?l=bugtraq&m=98642418618512&w=2 #### Github - https://github.com/KeerthiYasasvi/Honeypot-Data-Analysis-using-T-pot - https://github.com/fakowajo123/live-traffic-cyber-threat-analysis-using-honeypot-and-elk-stack --- ### 2001/CVE 2001 0427 (2001/CVE-2001-0427.md) ### [CVE-2001-0427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0427) ### Description Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts. ### POC #### Reference - http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0428 (2001/CVE-2001-0428.md) ### [CVE-2001-0428](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0428) ### Description Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option. ### POC #### Reference - http://www.cisco.com/warp/public/707/vpn3k-ipoptions-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0429 (2001/CVE-2001-0429.md) ### [CVE-2001-0429](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0429) ### Description Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service. ### POC #### Reference - http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0441 (2001/CVE-2001-0441.md) ### [CVE-2001-0441](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0441) ### Description Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-028.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0455 (2001/CVE-2001-0455.md) ### [CVE-2001-0455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0455) ### Description Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration. ### POC #### Reference - http://www.cisco.com/warp/public/707/Aironet340-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0457 (2001/CVE-2001-0457.md) ### [CVE-2001-0457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0457) ### Description man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion). ### POC #### Reference - https://exchange.xforce.ibmcloud.com/vulnerabilities/6211 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0464 (2001/CVE-2001-0464.md) ### [CVE-2001-0464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0464) ### Description Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter. ### POC #### Reference - http://marc.info/?l=bugtraq&m=98761402029302&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0465 (2001/CVE-2001-0465.md) ### [CVE-2001-0465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0465) ### Description TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information. ### POC #### Reference - http://www.turbotax.com/atr/update/ #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0486 (2001/CVE-2001-0486.md) ### [CVE-2001-0486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0486) ### Description Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353. ### POC #### Reference - http://marc.info/?l=bugtraq&m=98865027328391&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0498 (2001/CVE-2001-0498.md) ### [CVE-2001-0498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0498) ### Description Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension. ### POC #### Reference - http://www.nai.com/research/covert/advisories/049.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0499 (2001/CVE-2001-0499.md) ### [CVE-2001-0499](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0499) ### Description Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. ### POC #### Reference - http://www.nai.com/research/covert/advisories/050.asp #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0500 (2001/CVE-2001-0500.md) ### [CVE-2001-0500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0500) ### Description Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/mmpx12/netlas-go - https://github.com/ret2eax/exploits --- ### 2001/CVE 2001 0506 (2001/CVE-2001-0506.md) ### [CVE-2001-0506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0506) ### Description Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0507 (2001/CVE-2001-0507.md) ### [CVE-2001-0507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507) ### Description IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0515 (2001/CVE-2001-0515.md) ### [CVE-2001-0515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0515) ### Description Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. ### POC #### Reference - http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0516 (2001/CVE-2001-0516.md) ### [CVE-2001-0516](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0516) ### Description Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data. ### POC #### Reference - http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0517 (2001/CVE-2001-0517.md) ### [CVE-2001-0517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0517) ### Description Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0. ### POC #### Reference - http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0527 (2001/CVE-2001-0527.md) ### [CVE-2001-0527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0527) ### Description DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0533 (2001/CVE-2001-0533.md) ### [CVE-2001-0533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0533) ### Description Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable. ### POC #### Reference - http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/85256A3400529A8685256A8D00804A37/$file/oar271.txt #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0537 (2001/CVE-2001-0537.md) ### [CVE-2001-0537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0537) ### Description HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. ### POC #### Reference - http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/NCNU-OpenSource/Web-Vulnerability - https://github.com/POORVAJA-195/Nuclei-Analysis-main --- ### 2001/CVE 2001 0538 (2001/CVE-2001-0538.md) ### [CVE-2001-0538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0538) ### Description Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0540 (2001/CVE-2001-0540.md) ### [CVE-2001-0540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0540) ### Description Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389. ### POC #### Reference No PoCs from references. #### Github - https://github.com/nkemrex/My-Dissertation --- ### 2001/CVE 2001 0542 (2001/CVE-2001-0542.md) ### [CVE-2001-0542](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0542) ### Description Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0548 (2001/CVE-2001-0548.md) ### [CVE-2001-0548](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0548) ### Description Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable. ### POC #### Reference - http://marc.info/?l=bugtraq&m=99598918914068&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0550 (2001/CVE-2001-0550.md) ### [CVE-2001-0550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0550) ### Description wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). ### POC #### Reference - http://marc.info/?l=bugtraq&m=100700363414799&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/AnyMaster/EQGRP - https://github.com/Badbug6/EQGRP - https://github.com/CKmaenn/EQGRP - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/CybernetiX-S3C/EQGRP_Linux - https://github.com/Drift-Security/Shadow_Brokers-Vs-NSA - https://github.com/IHA114/EQGRP - https://github.com/Mofty/EQGRP - https://github.com/MrAli-Code/EQGRP - https://github.com/Muhammd/EQGRP - https://github.com/Nekkidso/EQGRP - https://github.com/Ninja-Tw1sT/EQGRP - https://github.com/R3K1NG/ShadowBrokersFiles - https://github.com/Soldie/EQGRP-nasa - https://github.com/antiscammerarmy/ShadowBrokersFiles - https://github.com/bensongithub/EQGRP - https://github.com/bl4ck4t/Tools - https://github.com/cipherreborn/SB--.-HACK-the-EQGRP-1 - https://github.com/cyberheartmi9/EQGRP - https://github.com/gilberto47831/Network-Filesystem-Forensics - https://github.com/hackcrypto/EQGRP - https://github.com/happysmack/x0rzEQGRP - https://github.com/kongjiexi/leaked2 - https://github.com/maxcvnd/bdhglopoj - https://github.com/mudongliang/LinuxFlaw - https://github.com/namangangwar/EQGRP - https://github.com/oneoy/cve- - https://github.com/r3p3r/x0rz-EQGRP - https://github.com/readloud/EQGRP - https://github.com/shakenetwork/shadowbrokerstuff - https://github.com/sinloss/EQGRP - https://github.com/thePevertedSpartan/EQ1 - https://github.com/thetrentus/EQGRP - https://github.com/thetrentus/ShadowBrokersStuff - https://github.com/thetrentusdev/shadowbrokerstuff - https://github.com/whoami-a51/secret-tools-nsa - https://github.com/wuvuw/EQGR - https://github.com/x0rz/EQGRP --- ### 2001/CVE 2001 0554 (2001/CVE-2001-0554.md) ### [CVE-2001-0554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0554) ### Description Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. ### POC #### Reference - http://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtml - http://www.redhat.com/support/errata/RHSA-2001-099.html #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Farrhouq/Inpt-report - https://github.com/kmukoo101/CVEye - https://github.com/siddicky/git-and-crumpets - https://github.com/vshaliii/Basic-Pentesting-2-Vulnhub-Walkthrough - https://github.com/vshaliii/DC-1-Vulnhub-Walkthrough - https://github.com/vshaliii/DC-2-Vulnhub-Walkthrough - https://github.com/vshaliii/DC-4-Vulnhub-Walkthrough --- ### 2001/CVE 2001 0557 (2001/CVE-2001-0557.md) ### [CVE-2001-0557](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0557) ### Description T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). ### POC #### Reference - https://exchange.xforce.ibmcloud.com/vulnerabilities/6513 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0559 (2001/CVE-2001-0559.md) ### [CVE-2001-0559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0559) ### Description crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. ### POC #### Reference No PoCs from references. #### Github - https://github.com/c-skills/CVEs --- ### 2001/CVE 2001 0561 (2001/CVE-2001-0561.md) ### [CVE-2001-0561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0561) ### Description Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. ### POC #### Reference No PoCs from references. #### Github - https://github.com/jubram/es_tpf --- ### 2001/CVE 2001 0572 (2001/CVE-2001-0572.md) ### [CVE-2001-0572](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0572) ### Description The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0590 (2001/CVE-2001-0590.md) ### [CVE-2001-0590](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0590) ### Description Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2001/CVE 2001 0593 (2001/CVE-2001-0593.md) ### [CVE-2001-0593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0593) ### Description Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0621 (2001/CVE-2001-0621.md) ### [CVE-2001-0621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0621) ### Description The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. ### POC #### Reference - http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0622 (2001/CVE-2001-0622.md) ### [CVE-2001-0622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0622) ### Description The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface. ### POC #### Reference - http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0650 (2001/CVE-2001-0650.md) ### [CVE-2001-0650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0650) ### Description Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute. ### POC #### Reference - http://www.cisco.com/warp/public/707/ios-bgp-attr-corruption-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0652 (2001/CVE-2001-0652.md) ### [CVE-2001-0652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0652) ### Description Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable. ### POC #### Reference - http://marc.info/?l=bugtraq&m=99745571104126&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0663 (2001/CVE-2001-0663.md) ### [CVE-2001-0663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0663) ### Description Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0669 (2001/CVE-2001-0669.md) ### [CVE-2001-0669](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0669) ### Description Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0680 (2001/CVE-2001-0680.md) ### [CVE-2001-0680](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0680) ### Description Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0685 (2001/CVE-2001-0685.md) ### [CVE-2001-0685](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0685) ### Description Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file. ### POC #### Reference - http://marc.info/?l=bugtraq&m=98339581702282&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0690 (2001/CVE-2001-0690.md) ### [CVE-2001-0690](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0690) ### Description Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/AnyMaster/EQGRP - https://github.com/Badbug6/EQGRP - https://github.com/CKmaenn/EQGRP - https://github.com/CybernetiX-S3C/EQGRP_Linux - https://github.com/Drift-Security/Shadow_Brokers-Vs-NSA - https://github.com/Farrhouq/Inpt-report - https://github.com/IHA114/EQGRP - https://github.com/Mofty/EQGRP - https://github.com/MrAli-Code/EQGRP - https://github.com/Muhammd/EQGRP - https://github.com/Nekkidso/EQGRP - https://github.com/Ninja-Tw1sT/EQGRP - https://github.com/R3K1NG/ShadowBrokersFiles - https://github.com/Soldie/EQGRP-nasa - https://github.com/antiscammerarmy/ShadowBrokersFiles - https://github.com/bensongithub/EQGRP - https://github.com/bl4ck4t/Tools - https://github.com/cipherreborn/SB--.-HACK-the-EQGRP-1 - https://github.com/cyberheartmi9/EQGRP - https://github.com/hackcrypto/EQGRP - https://github.com/happysmack/x0rzEQGRP - https://github.com/kongjiexi/leaked2 - https://github.com/maxcvnd/bdhglopoj - https://github.com/namangangwar/EQGRP - https://github.com/r3p3r/x0rz-EQGRP - https://github.com/readloud/EQGRP - https://github.com/shakenetwork/shadowbrokerstuff - https://github.com/sinloss/EQGRP - https://github.com/thePevertedSpartan/EQ1 - https://github.com/thetrentus/EQGRP - https://github.com/thetrentus/ShadowBrokersStuff - https://github.com/thetrentusdev/shadowbrokerstuff - https://github.com/whoami-a51/secret-tools-nsa - https://github.com/wuvuw/EQGR - https://github.com/x0rz/EQGRP --- ### 2001/CVE 2001 0711 (2001/CVE-2001-0711.md) ### [CVE-2001-0711](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0711) ### Description Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string. ### POC #### Reference - http://www.cisco.com/warp/public/707/ios-snmp-ilmi-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0717 (2001/CVE-2001-0717.md) ### [CVE-2001-0717](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0717) ### Description Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0722 (2001/CVE-2001-0722.md) ### [CVE-2001-0722](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0722) ### Description Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0727 (2001/CVE-2001-0727.md) ### [CVE-2001-0727](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0727) ### Description Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability." ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A921 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0730 (2001/CVE-2001-0730.md) ### [CVE-2001-0730](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0730) ### Description split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1649.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0739 (2001/CVE-2001-0739.md) ### [CVE-2001-0739](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0739) ### Description Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1404.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0740 (2001/CVE-2001-0740.md) ### [CVE-2001-0740](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0740) ### Description 3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100119572524232&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0746 (2001/CVE-2001-0746.md) ### [CVE-2001-0746](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0746) ### Description Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0748 (2001/CVE-2001-0748.md) ### [CVE-2001-0748](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0748) ### Description Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI. ### POC #### Reference - http://www.cisco.com/warp/public/707/acmeweb-acsunix-dirtravers-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0750 (2001/CVE-2001-0750.md) ### [CVE-2001-0750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0750) ### Description Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999. ### POC #### Reference - http://www.cisco.com/warp/public/707/ios-tcp-scanner-reload-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0751 (2001/CVE-2001-0751.md) ### [CVE-2001-0751](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0751) ### Description Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0752 (2001/CVE-2001-0752.md) ### [CVE-2001-0752](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0752) ### Description Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0753 (2001/CVE-2001-0753.md) ### [CVE-2001-0753](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0753) ### Description Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0754 (2001/CVE-2001-0754.md) ### [CVE-2001-0754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0754) ### Description Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets. ### POC #### Reference - http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0757 (2001/CVE-2001-0757.md) ### [CVE-2001-0757](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0757) ### Description Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet. ### POC #### Reference - http://www.cisco.com/warp/public/707/6400-nrp2-telnet-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0758 (2001/CVE-2001-0758.md) ### [CVE-2001-0758](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0758) ### Description Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. ### POC #### Reference - http://www.securiteam.com/windowsntfocus/5SP011P4KC.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0763 (2001/CVE-2001-0763.md) ### [CVE-2001-0763](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0763) ### Description Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1469.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0779 (2001/CVE-2001-0779.md) ### [CVE-2001-0779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0779) ### Description Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0797 (2001/CVE-2001-0797.md) ### [CVE-2001-0797](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0797) ### Description Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xdea/exploits - https://github.com/Kicksecure/security-misc - https://github.com/Whonix/security-misc --- ### 2001/CVE 2001 0803 (2001/CVE-2001-0803.md) ### [CVE-2001-0803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803) ### Description Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0815 (2001/CVE-2001-0815.md) ### [CVE-2001-0815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0815) ### Description Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0817 (2001/CVE-2001-0817.md) ### [CVE-2001-0817](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0817) ### Description Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/bigb0x/CVE-2024-6387 - https://github.com/bigb0x/OpenSSH-Scanner - https://github.com/edsonjt81/https-github.com-gotr00t0day-OpenSSH-Scanner - https://github.com/ryanalieh/openSSH-scanner --- ### 2001/CVE 2001 0819 (2001/CVE-2001-0819.md) ### [CVE-2001-0819](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0819) ### Description A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1451.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0820 (2001/CVE-2001-0820.md) ### [CVE-2001-0820](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0820) ### Description Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. ### POC #### Reference - http://marc.info/?l=bugtraq&m=99406263214417&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0829 (2001/CVE-2001-0829.md) ### [CVE-2001-0829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0829) ### Description A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2001/CVE 2001 0835 (2001/CVE-2001-0835.md) ### [CVE-2001-0835](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0835) ### Description Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1677.html #### Github - https://github.com/TheWatchDog13/OIBSIP_domain_taskno7 --- ### 2001/CVE 2001 0836 (2001/CVE-2001-0836.md) ### [CVE-2001-0836](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0836) ### Description Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100342151132277&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0845 (2001/CVE-2001-0845.md) ### [CVE-2001-0845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0845) ### Description Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. ### POC #### Reference No PoCs from references. #### Github - https://github.com/jhswartz/cvrfdb --- ### 2001/CVE 2001 0851 (2001/CVE-2001-0851.md) ### [CVE-2001-0851](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0851) ### Description Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1683.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0853 (2001/CVE-2001-0853.md) ### [CVE-2001-0853](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0853) ### Description Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100498111712723&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0861 (2001/CVE-2001-0861.md) ### [CVE-2001-0861](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0861) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-unreachables-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0862 (2001/CVE-2001-0862.md) ### [CVE-2001-0862](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0862) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0863 (2001/CVE-2001-0863.md) ### [CVE-2001-0863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0863) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0864 (2001/CVE-2001-0864.md) ### [CVE-2001-0864](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0864) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0865 (2001/CVE-2001-0865.md) ### [CVE-2001-0865](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0865) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0866 (2001/CVE-2001-0866.md) ### [CVE-2001-0866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0866) ### Description Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0867 (2001/CVE-2001-0867.md) ### [CVE-2001-0867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0867) ### Description Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls. ### POC #### Reference - http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0877 (2001/CVE-2001-0877.md) ### [CVE-2001-0877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0877) ### Description Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0879 (2001/CVE-2001-0879.md) ### [CVE-2001-0879](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0879) ### Description Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0886 (2001/CVE-2001-0886.md) ### [CVE-2001-0886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0886) ### Description Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1752.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0895 (2001/CVE-2001-0895.md) ### [CVE-2001-0895](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0895) ### Description Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table. ### POC #### Reference - http://www.cisco.com/warp/public/707/IOS-arp-overwrite-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0907 (2001/CVE-2001-0907.md) ### [CVE-2001-0907](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0907) ### Description Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1650.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0908 (2001/CVE-2001-0908.md) ### [CVE-2001-0908](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0908) ### Description CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT). ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2001/CVE 2001 0917 (2001/CVE-2001-0917.md) ### [CVE-2001-0917](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0917) ### Description Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2001/CVE 2001 0920 (2001/CVE-2001-0920.md) ### [CVE-2001-0920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0920) ### Description Format string vulnerability in auto nice daemon (AND) 1.0.4 and earlier allows a local user to possibly execute arbitrary code via a process name containing a format string. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100680319004162&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0925 (2001/CVE-2001-0925.md) ### [CVE-2001-0925](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0925) ### Description The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1452.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0927 (2001/CVE-2001-0927.md) ### [CVE-2001-0927](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0927) ### Description Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100689302316077&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0929 (2001/CVE-2001-0929.md) ### [CVE-2001-0929](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0929) ### Description Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists. ### POC #### Reference - http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0931 (2001/CVE-2001-0931.md) ### [CVE-2001-0931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0931) ### Description Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100698397818175&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0932 (2001/CVE-2001-0932.md) ### [CVE-2001-0932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0932) ### Description Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100698397818175&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0933 (2001/CVE-2001-0933.md) ### [CVE-2001-0933](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0933) ### Description Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:". ### POC #### Reference - http://marc.info/?l=bugtraq&m=100698397818175&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0934 (2001/CVE-2001-0934.md) ### [CVE-2001-0934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0934) ### Description Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100698397818175&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 0935 (2001/CVE-2001-0935.md) ### [CVE-2001-0935](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0935) ### Description Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0945 (2001/CVE-2001-0945.md) ### [CVE-2001-0945](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0945) ### Description Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 0946 (2001/CVE-2001-0946.md) ### [CVE-2001-0946](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0946) ### Description apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100743394701962&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0951 (2001/CVE-2001-0951.md) ### [CVE-2001-0951](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0951) ### Description Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 0998 (2001/CVE-2001-0998.md) ### [CVE-2001-0998](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0998) ### Description IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd. ### POC #### Reference - http://www-1.ibm.com/support/search.wss?rs=0&q=IY20943&apar=only #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 0999 (2001/CVE-2001-0999.md) ### [CVE-2001-0999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0999) ### Description Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 1002 (2001/CVE-2001-1002.md) ### [CVE-2001-1002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1002) ### Description The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands. ### POC #### Reference - http://marc.info/?l=bugtraq&m=99892644616749&w=2 #### Github - https://github.com/Xiol/CVEChecker - https://github.com/james-portman/CVEChecker --- ### 2001/CVE 2001 1009 (2001/CVE-2001-1009.md) ### [CVE-2001-1009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1009) ### Description Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1555.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1020 (2001/CVE-2001-1020.md) ### [CVE-2001-1020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1020) ### Description edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=51589 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1021 (2001/CVE-2001-1021.md) ### [CVE-2001-1021](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1021) ### Description Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1037 (2001/CVE-2001-1037.md) ### [CVE-2001-1037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1037) ### Description Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. ### POC #### Reference - http://www.cisco.com/warp/public/707/SN-kernel-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1038 (2001/CVE-2001-1038.md) ### [CVE-2001-1038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1038) ### Description Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023. ### POC #### Reference - http://www.cisco.com/warp/public/707/SN-kernel-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1051 (2001/CVE-2001-1051.md) ### [CVE-2001-1051](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1051) ### Description Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. ### POC #### Reference - http://sourceforge.net/tracker/index.php?func=detail&aid=440666&group_id=20971&atid=120971 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1054 (2001/CVE-2001-1054.md) ### [CVE-2001-1054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1054) ### Description PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. ### POC #### Reference - http://sourceforge.net/forum/forum.php?thread_id=148900&forum_id=117952 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1064 (2001/CVE-2001-1064.md) ### [CVE-2001-1064](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1064) ### Description Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1065 (2001/CVE-2001-1065.md) ### [CVE-2001-1065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1065) ### Description Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1080 (2001/CVE-2001-1080.md) ### [CVE-2001-1080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1080) ### Description diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program. ### POC #### Reference - http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2001.225.1/$file/oar225.txt #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1081 (2001/CVE-2001-1081.md) ### [CVE-2001-1081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1081) ### Description Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages. ### POC #### Reference - http://freshmeat.net/releases/52020/ #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1082 (2001/CVE-2001-1082.md) ### [CVE-2001-1082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1082) ### Description Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. ### POC #### Reference - http://freshmeat.net/releases/52020/ #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1088 (2001/CVE-2001-1088.md) ### [CVE-2001-1088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1088) ### Description Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 1092 (2001/CVE-2001-1092.md) ### [CVE-2001-1092](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1092) ### Description msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/truefinder/truefinder --- ### 2001/CVE 2001 1093 (2001/CVE-2001-1093.md) ### [CVE-2001-1093](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1093) ### Description Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument. ### POC #### Reference No PoCs from references. #### Github - https://github.com/truefinder/truefinder --- ### 2001/CVE 2001 1097 (2001/CVE-2001-1097.md) ### [CVE-2001-1097](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1097) ### Description Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1105 (2001/CVE-2001-1105.md) ### [CVE-2001-1105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1105) ### Description RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. ### POC #### Reference - http://www.cisco.com/warp/public/707/SSL-J-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1131 (2001/CVE-2001-1131.md) ### [CVE-2001-1131](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1131) ### Description Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command. ### POC #### Reference - http://www.securiteam.com/windowsntfocus/5RP0L0055O.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1141 (2001/CVE-2001-1141.md) ### [CVE-2001-1141](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1141) ### Description The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1483.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2001/CVE 2001 1146 (2001/CVE-2001-1146.md) ### [CVE-2001-1146](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1146) ### Description AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1492.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1162 (2001/CVE-2001-1162.md) ### [CVE-2001-1162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1162) ### Description Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1183 (2001/CVE-2001-1183.md) ### [CVE-2001-1183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1183) ### Description PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet. ### POC #### Reference - http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1184 (2001/CVE-2001-1184.md) ### [CVE-2001-1184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1184) ### Description wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1201 (2001/CVE-2001-1201.md) ### [CVE-2001-1201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1201) ### Description Buffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description file. ### POC #### Reference - http://marc.info/?l=bugtraq&m=100863301405266&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1224 (2001/CVE-2001-1224.md) ### [CVE-2001-1224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1224) ### Description get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Alman368/MNDefender --- ### 2001/CVE 2001 1228 (2001/CVE-2001-1228.md) ### [CVE-2001-1228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1228) ### Description Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/ethoxx/noninvasive-oobw-characterization - https://github.com/hafklin/noninvasive-oobw-characterization - https://github.com/utwente-scs/divak --- ### 2001/CVE 2001 1231 (2001/CVE-2001-1231.md) ### [CVE-2001-1231](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1231) ### Description GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix. ### POC #### Reference - http://support.novell.com/padlock/details.htm #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1240 (2001/CVE-2001-1240.md) ### [CVE-2001-1240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1240) ### Description The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1493.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1280 (2001/CVE-2001-1280.md) ### [CVE-2001-1280](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1280) ### Description POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1288 (2001/CVE-2001-1288.md) ### [CVE-2001-1288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1288) ### Description Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe. ### POC #### Reference - http://marc.info/?l=vuln-dev&m=99651044701417&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1295 (2001/CVE-2001-1295.md) ### [CVE-2001-1295](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1295) ### Description Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command. ### POC #### Reference - http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1322 (2001/CVE-2001-1322.md) ### [CVE-2001-1322](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1322) ### Description xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1469.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1325 (2001/CVE-2001-1325.md) ### [CVE-2001-1325](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1325) ### Description Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH). ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 1349 (2001/CVE-2001-1349.md) ### [CVE-2001-1349](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1349) ### Description Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/NSzolnoki/CVEPoisonKnowledgebase - https://github.com/szolnoki-szte-sed/swamp-dataset --- ### 2001/CVE 2001 1362 (2001/CVE-2001-1362.md) ### [CVE-2001-1362](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1362) ### Description Vulnerability in the server for nPULSE before 0.53p4. ### POC #### Reference - http://freshmeat.net/releases/51981/ #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1374 (2001/CVE-2001-1374.md) ### [CVE-2001-1374](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1374) ### Description expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2002-148.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1375 (2001/CVE-2001-1375.md) ### [CVE-2001-1375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1375) ### Description tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2002-148.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1382 (2001/CVE-2001-1382.md) ### [CVE-2001-1382](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1382) ### Description The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan --- ### 2001/CVE 2001 1384 (2001/CVE-2001-1384.md) ### [CVE-2001-1384](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1384) ### Description ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1650.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1390 (2001/CVE-2001-1390.md) ### [CVE-2001-1390](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1390) ### Description Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1391 (2001/CVE-2001-1391.md) ### [CVE-2001-1391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1391) ### Description Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1392 (2001/CVE-2001-1392.md) ### [CVE-2001-1392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1392) ### Description The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1393 (2001/CVE-2001-1393.md) ### [CVE-2001-1393](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1393) ### Description Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang). ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1394 (2001/CVE-2001-1394.md) ### [CVE-2001-1394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1394) ### Description Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1395 (2001/CVE-2001-1395.md) ### [CVE-2001-1395](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1395) ### Description Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1396 (2001/CVE-2001-1396.md) ### [CVE-2001-1396](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1396) ### Description Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1397 (2001/CVE-2001-1397.md) ### [CVE-2001-1397](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1397) ### Description The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1398 (2001/CVE-2001-1398.md) ### [CVE-2001-1398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1398) ### Description Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1399 (2001/CVE-2001-1399.md) ### [CVE-2001-1399](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1399) ### Description Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86." ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1400 (2001/CVE-2001-1400.md) ### [CVE-2001-1400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1400) ### Description Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock). ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2001-047.html #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1410 (2001/CVE-2001-1410.md) ### [CVE-2001-1410](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1410) ### Description Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering. ### POC #### Reference - http://marc.info/?l=bugtraq&m=105829174431769&w=2 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1416 (2001/CVE-2001-1416.md) ### [CVE-2001-1416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1416) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags. ### POC #### Reference - http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&DisplayTab=Article #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1432 (2001/CVE-2001-1432.md) ### [CVE-2001-1432](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1432) ### Description Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/SamanShafigh/vulBERT --- ### 2001/CVE 2001 1434 (2001/CVE-2001-1434.md) ### [CVE-2001-1434](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1434) ### Description Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created. ### POC #### Reference - http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1442 (2001/CVE-2001-1442.md) ### [CVE-2001-1442](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1442) ### Description Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2001/CVE 2001 1451 (2001/CVE-2001-1451.md) ### [CVE-2001-1451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1451) ### Description Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests. ### POC #### Reference No PoCs from references. #### Github - https://github.com/clearbluejar/cve-markdown-charts --- ### 2001/CVE 2001 1455 (2001/CVE-2001-1455.md) ### [CVE-2001-1455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1455) ### Description Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters. ### POC #### Reference - http://www.securityfocus.com/bid/6060 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1458 (2001/CVE-2001-1458.md) ### [CVE-2001-1458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1458) ### Description Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character. ### POC #### Reference - http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/advisories_template.htm%3Findexid%3D12 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1473 (2001/CVE-2001-1473.md) ### [CVE-2001-1473](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1473) ### Description The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xget/cve-2001-1473 - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/CVEDB/awesome-cve-repo - https://github.com/PuddinCat/GithubRepoSpider - https://github.com/alexandermoro/cve-2001-1473 - https://github.com/bash3rt3am/poc-cve - https://github.com/codine7/Hacking_Automated - https://github.com/codine7/fox - https://github.com/codine7/jungle - https://github.com/m00n3rrr/poc-CVE-2001-1473 - https://github.com/masm3264/poc-CVE-2001-1473 - https://github.com/p1ton3rr/poc-cve-2001-1473 - https://github.com/s1mpl3c0d3/cvepoc --- ### 2001/CVE 2001 1483 (2001/CVE-2001-1483.md) ### [CVE-2001-1483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1483) ### Description One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist. ### POC #### Reference No PoCs from references. #### Github - https://github.com/krlabs/openssh-vulnerabilities --- ### 2001/CVE 2001 1494 (2001/CVE-2001-1494.md) ### [CVE-2001-1494](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1494) ### Description script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Shubhamthakur1997/CICD-Demo - https://github.com/dcambronero/CloudGuard-ShiftLeft-CICD-AWS - https://github.com/jaydenaung/CloudGuard-ShiftLeft-CICD-AWS - https://github.com/tp1-SpZIaPvBD/testprojekt --- ### 2001/CVE 2001 1499 (2001/CVE-2001-1499.md) ### [CVE-2001-1499](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1499) ### Description Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks. ### POC #### Reference - http://www.osvdb.org/20210 #### Github No PoCs found on GitHub currently. --- ### 2001/CVE 2001 1517 (2001/CVE-2001-1517.md) ### [CVE-2001-1517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1517) ### Description RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds --- ### 2001/CVE 2001 1519 (2001/CVE-2001-1519.md) ### [CVE-2001-1519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1519) ### Description RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds --- ### 2001/CVE 2001 1533 (2001/CVE-2001-1533.md) ### [CVE-2001-1533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1533) ### Description Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds --- ### 2001/CVE 2001 1547 (2001/CVE-2001-1547.md) ### [CVE-2001-1547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1547) ### Description Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2001/CVE 2001 1563 (2001/CVE-2001-1563.md) ### [CVE-2001-1563](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1563) ### Description Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2001/CVE 2001 1580 (2001/CVE-2001-1580.md) ### [CVE-2001-1580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1580) ### Description Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2001/CVE 2001 1583 (2001/CVE-2001-1583.md) ### [CVE-2001-1583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1583) ### Description lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-2001-1583 --- ### 2001/CVE 2001 1594 (2001/CVE-2001-1594.md) ### [CVE-2001-1594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1594) ### Description GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics printer FTP service, (4) eNTEGRA for the eNTEGRA P&R user account, (5) insite for the WinVNC Login, and possibly other accounts, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. ### POC #### Reference - http://apps.gehealthcare.com/servlet/ClientServlet/2263784.pdf?DOCCLASS=A&REQ=RAC&DIRECTION=2263784-100&FILENAME=2263784.pdf&FILEREV=5&DOCREV_ORG=5&SUBMIT=+ACCEPT+ - http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/ #### Github - https://github.com/wsbespalov/vmengine --- ### 2002/CVE 2002 0012 (2002/CVE-2002-0012.md) ### [CVE-2002-0012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012) ### Description Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available. ### POC #### Reference No PoCs from references. #### Github - https://github.com/KeerthiYasasvi/Honeypot-Data-Analysis-using-T-pot --- ### 2002/CVE 2002 0013 (2002/CVE-2002-0013.md) ### [CVE-2002-0013](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013) ### Description Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/KeerthiYasasvi/Honeypot-Data-Analysis-using-T-pot - https://github.com/Linathimqalo/cloud-honeypot-analysis - https://github.com/alanshlam/HoneyNet - https://github.com/fakowajo123/live-traffic-cyber-threat-analysis-using-honeypot-and-elk-stack --- ### 2002/CVE 2002 0022 (2002/CVE-2002-0022.md) ### [CVE-2002-0022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0022) ### Description Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101362984930597&w=2 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A925 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0027 (2002/CVE-2002-0027.md) ### [CVE-2002-0027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0027) ### Description Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A974 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0029 (2002/CVE-2002-0029.md) ### [CVE-2002-0029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0029) ### Description Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684. ### POC #### Reference No PoCs from references. #### Github - https://github.com/C4ssif3r/nmap-scripts - https://github.com/stran0s/stran0s --- ### 2002/CVE 2002 0043 (2002/CVE-2002-0043.md) ### [CVE-2002-0043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0043) ### Description sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked. ### POC #### Reference No PoCs from references. #### Github - https://github.com/c-skills/CVEs --- ### 2002/CVE 2002 0048 (2002/CVE-2002-0048.md) ### [CVE-2002-0048](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0048) ### Description Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1853.html #### Github - https://github.com/c-skills/CVEs --- ### 2002/CVE 2002 0053 (2002/CVE-2002-0053.md) ### [CVE-2002-0053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0053) ### Description Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0055 (2002/CVE-2002-0055.md) ### [CVE-2002-0055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0055) ### Description SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A30 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0056 (2002/CVE-2002-0056.md) ### [CVE-2002-0056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0056) ### Description Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0057 (2002/CVE-2002-0057.md) ### [CVE-2002-0057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0057) ### Description XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0058 (2002/CVE-2002-0058.md) ### [CVE-2002-0058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0058) ### Description Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101534535304228&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0063 (2002/CVE-2002-0063.md) ### [CVE-2002-0063](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0063) ### Description Buffer overflow in ippRead function of CUPS before 1.1.14 may allow attackers to execute arbitrary code via long attribute names or language values. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0071 (2002/CVE-2002-0071.md) ### [CVE-2002-0071](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0071) ### Description Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0072 (2002/CVE-2002-0072.md) ### [CVE-2002-0072](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0072) ### Description The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0073 (2002/CVE-2002-0073.md) ### [CVE-2002-0073](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0073) ### Description The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101901273810598&w=2 - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0074 (2002/CVE-2002-0074.md) ### [CVE-2002-0074](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0074) ### Description Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0075 (2002/CVE-2002-0075.md) ### [CVE-2002-0075](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075) ### Description Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0078 (2002/CVE-2002-0078.md) ### [CVE-2002-0078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0078) ### Description The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A96 #### Github - https://github.com/andrewd-sysdig/nodejs-helloworld --- ### 2002/CVE 2002 0079 (2002/CVE-2002-0079.md) ### [CVE-2002-0079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0079) ### Description Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0081 (2002/CVE-2002-0081.md) ### [CVE-2002-0081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0081) ### Description Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101484705523351&w=2 - http://marc.info/?l=bugtraq&m=101537076619812&w=2 - http://marc.info/?l=ntbugtraq&m=101484975231922&w=2 - http://security.e-matters.de/advisories/012002.html - http://www.linuxsecurity.com/advisories/other_advisory-1924.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0082 (2002/CVE-2002-0082.md) ### [CVE-2002-0082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0082) ### Description The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session. ### POC #### Reference - http://packetstormsecurity.com/files/153567/Apache-mod_ssl-OpenSSL-Remote-Buffer-Overflow.html - http://www.linuxsecurity.com/advisories/other_advisory-1923.html #### Github - https://github.com/0xcybermonk/Kioptrix-Pentest-Report - https://github.com/Abdibimantara/Vulnerability-Asessment-Kioptrix-Level-1-Vulnhub - https://github.com/Dekiridi/ZeroHealth-Corp-Vulnerability-Assessment-Project - https://github.com/Nishant-Pall/Kioptrix-exploit - https://github.com/davincico/ChatGPT-2-HACKER - https://github.com/piyush-saurabh/exploits - https://github.com/ratiros01/CVE-2002-0082 - https://github.com/rosonsec/Exploits --- ### 2002/CVE 2002 0083 (2002/CVE-2002-0083.md) ### [CVE-2002-0083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0083) ### Description Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-1937.html #### Github - https://github.com/bigb0x/CVE-2024-6387 - https://github.com/bigb0x/OpenSSH-Scanner - https://github.com/edsonjt81/https-github.com-gotr00t0day-OpenSSH-Scanner - https://github.com/ryanalieh/openSSH-scanner --- ### 2002/CVE 2002 0084 (2002/CVE-2002-0084.md) ### [CVE-2002-0084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084) ### Description Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A97 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0098 (2002/CVE-2002-0098.md) ### [CVE-2002-0098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0098) ### Description Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner. ### POC #### Reference - http://www.boozt.com/news_detail.php?id=3 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0133 (2002/CVE-2002-0133.md) ### [CVE-2002-0133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0133) ### Description Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string to the telnet proxy. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101366658112809&w=2 - http://marc.info/?l=bugtraq&m=101424723728817&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0134 (2002/CVE-2002-0134.md) ### [CVE-2002-0134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0134) ### Description Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a "dos" command. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101424723728817&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0137 (2002/CVE-2002-0137.md) ### [CVE-2002-0137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0137) ### Description CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101102759631000&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0138 (2002/CVE-2002-0138.md) ### [CVE-2002-0138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0138) ### Description CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101102759631000&w=2 - http://marc.info/?l=bugtraq&m=101111688819855&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0147 (2002/CVE-2002-0147.md) ### [CVE-2002-0147](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147) ### Description Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun." ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0148 (2002/CVE-2002-0148.md) ### [CVE-2002-0148](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148) ### Description Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A92 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0149 (2002/CVE-2002-0149.md) ### [CVE-2002-0149](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149) ### Description Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A95 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0150 (2002/CVE-2002-0150.md) ### [CVE-2002-0150](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0150) ### Description Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values. ### POC #### Reference - http://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0152 (2002/CVE-2002-0152.md) ### [CVE-2002-0152](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0152) ### Description Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2002/CVE 2002 0159 (2002/CVE-2002-0159.md) ### [CVE-2002-0159](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0159) ### Description Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002. ### POC #### Reference - http://www.cisco.com/warp/public/707/ACS-Win-Web.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0160 (2002/CVE-2002-0160.md) ### [CVE-2002-0160](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0160) ### Description The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002. ### POC #### Reference - http://www.cisco.com/warp/public/707/ACS-Win-Web.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0162 (2002/CVE-2002-0162.md) ### [CVE-2002-0162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0162) ### Description LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101724766216872 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0164 (2002/CVE-2002-0164.md) ### [CVE-2002-0164](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0164) ### Description Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges. ### POC #### Reference - http://www.linuxsecurity.com/advisories/caldera_advisory-2006.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0184 (2002/CVE-2002-0184.md) ### [CVE-2002-0184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0184) ### Description Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101974610509912&w=2 - http://www.linuxsecurity.com/advisories/other_advisory-2040.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0190 (2002/CVE-2002-0190.md) ### [CVE-2002-0190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0190) ### Description Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A923 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0191 (2002/CVE-2002-0191.md) ### [CVE-2002-0191](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0191) ### Description Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101778302030981&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0193 (2002/CVE-2002-0193.md) ### [CVE-2002-0193](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193) ### Description Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A99 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0200 (2002/CVE-2002-0200.md) ### [CVE-2002-0200](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0200) ### Description Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101174569103289&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0201 (2002/CVE-2002-0201.md) ### [CVE-2002-0201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0201) ### Description Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101174569103289&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0224 (2002/CVE-2002-0224.md) ### [CVE-2002-0224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0224) ### Description The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0231 (2002/CVE-2002-0231.md) ### [CVE-2002-0231](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0231) ### Description Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101286747013955&w=2 - http://www.uuuppz.com/research/adv-001-mirc.htm #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0241 (2002/CVE-2002-0241.md) ### [CVE-2002-0241](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0241) ### Description NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server. ### POC #### Reference - http://www.cisco.com/warp/public/707/ciscosecure-acs-nds-authentication-vuln-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0244 (2002/CVE-2002-0244.md) ### [CVE-2002-0244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0244) ### Description Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101310622531303&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0252 (2002/CVE-2002-0252.md) ### [CVE-2002-0252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0252) ### Description Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header. ### POC #### Reference - https://www.exploit-db.com/exploits/4673 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0280 (2002/CVE-2002-0280.md) ### [CVE-2002-0280](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0280) ### Description Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply. ### POC #### Reference - http://freshmeat.net/releases/71514/ #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0283 (2002/CVE-2002-0283.md) ### [CVE-2002-0283](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0283) ### Description Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101408718030099&w=2 #### Github - https://github.com/tmac997/tmac997 --- ### 2002/CVE 2002 0285 (2002/CVE-2002-0285.md) ### [CVE-2002-0285](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0285) ### Description Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2002/CVE 2002 0287 (2002/CVE-2002-0287.md) ### [CVE-2002-0287](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0287) ### Description pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101389284625019&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0288 (2002/CVE-2002-0288.md) ### [CVE-2002-0288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0288) ### Description Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101408906001958&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0289 (2002/CVE-2002-0289.md) ### [CVE-2002-0289](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0289) ### Description Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101408906001958&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0292 (2002/CVE-2002-0292.md) ### [CVE-2002-0292](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0292) ### Description Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101414005501708&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0309 (2002/CVE-2002-0309.md) ### [CVE-2002-0309](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0309) ### Description SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101424307617060&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0314 (2002/CVE-2002-0314.md) ### [CVE-2002-0314](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0314) ### Description fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101441689224760&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0315 (2002/CVE-2002-0315.md) ### [CVE-2002-0315](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0315) ### Description fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101441689224760&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0319 (2002/CVE-2002-0319.md) ### [CVE-2002-0319](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0319) ### Description Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101446366708757&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0326 (2002/CVE-2002-0326.md) ### [CVE-2002-0326](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0326) ### Description Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101474387016066&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0339 (2002/CVE-2002-0339.md) ### [CVE-2002-0339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0339) ### Description Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length. ### POC #### Reference - http://www.cisco.com/warp/public/707/IOS-CEF-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0346 (2002/CVE-2002-0346.md) ### [CVE-2002-0346](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0346) ### Description Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101495944202452&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0347 (2002/CVE-2002-0347.md) ### [CVE-2002-0347](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0347) ### Description Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101495944202452&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0348 (2002/CVE-2002-0348.md) ### [CVE-2002-0348](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0348) ### Description service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument. ### POC #### Reference - http://marc.info/?l=bugtraq&m=101495944202452&w=2 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0354 (2002/CVE-2002-0354.md) ### [CVE-2002-0354](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0354) ### Description The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. ### POC #### Reference - http://marc.info/?l=bugtraq&m=102017952204097&w=2 - http://marc.info/?l=ntbugtraq&m=102020343728766&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0359 (2002/CVE-2002-0359.md) ### [CVE-2002-0359](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0359) ### Description xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges. ### POC #### Reference - http://marc.info/?l=bugtraq&m=102459162909825&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0364 (2002/CVE-2002-0364.md) ### [CVE-2002-0364](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0364) ### Description Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0367 (2002/CVE-2002-0367.md) ### [CVE-2002-0367](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0367) ### Description smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/todb-cisa/kev-cwes --- ### 2002/CVE 2002 0370 (2002/CVE-2002-0370.md) ### [CVE-2002-0370](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0370) ### Description Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0. ### POC #### Reference - http://securityreason.com/securityalert/587 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0371 (2002/CVE-2002-0371.md) ### [CVE-2002-0371](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0371) ### Description Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A98 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0378 (2002/CVE-2002-0378.md) ### [CVE-2002-0378](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0378) ### Description The default configuration of LPRng print spooler in Red Hat Linux 7.0 through 7.3, Mandrake 8.1 and 8.2, and other operating systems, accepts print jobs from arbitrary remote hosts. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2002-089.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0379 (2002/CVE-2002-0379.md) ### [CVE-2002-0379](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0379) ### Description Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2120.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0386 (2002/CVE-2002-0386.md) ### [CVE-2002-0386](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0386) ### Description The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0391 (2002/CVE-2002-0391.md) ### [CVE-2002-0391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391) ### Description Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2399.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0392 (2002/CVE-2002-0392.md) ### [CVE-2002-0392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392) ### Description Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2137.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/attwad/gocvss - https://github.com/goark/go-cvss - https://github.com/rebstan97/AttackGraphGeneration --- ### 2002/CVE 2002 0399 (2002/CVE-2002-0399.md) ### [CVE-2002-0399](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0399) ### Description Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2400.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0409 (2002/CVE-2002-0409.md) ### [CVE-2002-0409](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0409) ### Description orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0419 (2002/CVE-2002-0419.md) ### [CVE-2002-0419](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0419) ### Description Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0422 (2002/CVE-2002-0422.md) ### [CVE-2002-0422](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0422) ### Description IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/k0pak4/k0pak4 --- ### 2002/CVE 2002 0440 (2002/CVE-2002-0440.md) ### [CVE-2002-0440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0440) ### Description Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients. ### POC #### Reference - http://seclists.org/lists/bugtraq/2002/Mar/0162.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0444 (2002/CVE-2002-0444.md) ### [CVE-2002-0444](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0444) ### Description Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2002/CVE 2002 0448 (2002/CVE-2002-0448.md) ### [CVE-2002-0448](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0448) ### Description Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2002/CVE 2002 0470 (2002/CVE-2002-0470.md) ### [CVE-2002-0470](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0470) ### Description PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path. ### POC #### Reference - http://seclists.org/bugtraq/2002/Mar/0263.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0471 (2002/CVE-2002-0471.md) ### [CVE-2002-0471](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0471) ### Description PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable. ### POC #### Reference - http://seclists.org/bugtraq/2002/Mar/0263.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0473 (2002/CVE-2002-0473.md) ### [CVE-2002-0473](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0473) ### Description db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter. ### POC #### Reference - http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.1.zip #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0493 (2002/CVE-2002-0493.md) ### [CVE-2002-0493](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0493) ### Description Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/m3n0sd0n4ld/uCVE --- ### 2002/CVE 2002 0500 (2002/CVE-2002-0500.md) ### [CVE-2002-0500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0500) ### Description Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0505 (2002/CVE-2002-0505.md) ### [CVE-2002-0505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0505) ### Description Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords. ### POC #### Reference - http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0526 (2002/CVE-2002-0526.md) ### [CVE-2002-0526](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0526) ### Description Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls. ### POC #### Reference No PoCs from references. #### Github - https://github.com/bcoles/local-exploits --- ### 2002/CVE 2002 0541 (2002/CVE-2002-0541.md) ### [CVE-2002-0541](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0541) ### Description Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581. ### POC #### Reference - http://www.tivoli.com/support/storage_mgr/flash_httpport.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0545 (2002/CVE-2002-0545.md) ### [CVE-2002-0545](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0545) ### Description Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords. ### POC #### Reference - http://www.cisco.com/warp/public/707/Aironet-Telnet.shtml #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0575 (2002/CVE-2002-0575.md) ### [CVE-2002-0575](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0575) ### Description Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Dekiridi/ZeroHealth-Corp-Vulnerability-Assessment-Project - https://github.com/LyticOnaope/ZHVA --- ### 2002/CVE 2002 0597 (2002/CVE-2002-0597.md) ### [CVE-2002-0597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0597) ### Description LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/vishnuvrj7/VulnHunt --- ### 2002/CVE 2002 0598 (2002/CVE-2002-0598.md) ### [CVE-2002-0598](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0598) ### Description Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server banner. ### POC #### Reference - http://www.foundstone.com/knowledge/fscan112_advisory.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0619 (2002/CVE-2002-0619.md) ### [CVE-2002-0619](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0619) ### Description The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788). ### POC #### Reference - http://marc.info/?l=bugtraq&m=102139136019862&w=2 #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0637 (2002/CVE-2002-0637.md) ### [CVE-2002-0637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0637) ### Description InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express. ### POC #### Reference No PoCs from references. #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2002/CVE 2002 0639 (2002/CVE-2002-0639.md) ### [CVE-2002-0639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0639) ### Description Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2177.html #### Github No PoCs found on GitHub currently. --- ### 2002/CVE 2002 0640 (2002/CVE-2002-0640.md) ### [CVE-2002-0640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0640) ### Description Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt). ### POC #### Reference - http://www.linuxsecurity.com/advisories/other_advisory-2177.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2002/CVE 2002 0648 (2002/CVE-2002-0648.md) ### [CVE-2002-0648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648) ### Description The legacy end tag, which bypasses the protection against lowercase . ### POC #### Reference - http://securityreason.com/securityalert/2402 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1397 (2007/CVE-2007-1397.md) ### [CVE-2007-1397](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1397) ### Description Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings. ### POC #### Reference - http://securityreason.com/securityalert/8216 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1398 (2007/CVE-2007-1398.md) ### [CVE-2007-1398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1398) ### Description The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet. ### POC #### Reference - https://www.exploit-db.com/exploits/3434 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1400 (2007/CVE-2007-1400.md) ### [CVE-2007-1400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1400) ### Description Plash permits sandboxed processes to open /dev/tty, which allows local users to escape sandbox restrictions and execute arbitrary commands by sending characters to a shell process on the same termimal via the TIOCSTI ioctl. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/hartwork/antijack --- ### 2007/CVE 2007 1401 (2007/CVE-2007-1401.md) ### [CVE-2007-1401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1401) ### Description Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function. ### POC #### Reference - http://securityreason.com/securityalert/2405 - https://www.exploit-db.com/exploits/3431 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1403 (2007/CVE-2007-1403.md) ### [CVE-2007-1403](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1403) ### Description Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885. ### POC #### Reference - https://www.exploit-db.com/exploits/3421 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1404 (2007/CVE-2007-1404.md) ### [CVE-2007-1404](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1404) ### Description tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. ### POC #### Reference - https://www.exploit-db.com/exploits/3432 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1408 (2007/CVE-2007-1408.md) ### [CVE-2007-1408](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1408) ### Description Multiple vulnerabilities in (1) bank.php, (2) landfill.php, (3) outposts.php, (4) tribes.php, (5) house.php, (6) tribearmor.php, (7) tribeastral.php, (8) tribeware.php, and (9) includes/head.php in Bartek Jasicki Vallheru before 1.3 beta have unknown impact and remote attack vectors, probably related to large integer values containing more than 15 digits. NOTE: the original vendor report is for integer overflows, but this is probably an incorrect usage of the term. ### POC #### Reference - http://vallheru.svn.sourceforge.net/viewvc/vallheru/vallheru2/bank.php?r1=910&r2=918 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1410 (2007/CVE-2007-1410.md) ### [CVE-2007-1410](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1410) ### Description SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3437 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1411 (2007/CVE-2007-1411.md) ### [CVE-2007-1411](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1411) ### Description Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions. ### POC #### Reference - http://securityreason.com/securityalert/2407 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1412 (2007/CVE-2007-1412.md) ### [CVE-2007-1412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1412) ### Description The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument. ### POC #### Reference - https://www.exploit-db.com/exploits/3442 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1413 (2007/CVE-2007-1413.md) ### [CVE-2007-1413](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1413) ### Description Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id). ### POC #### Reference - https://www.exploit-db.com/exploits/3439 - https://www.exploit-db.com/exploits/4204 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1415 (2007/CVE-2007-1415.md) ### [CVE-2007-1415](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1415) ### Description Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3443 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1417 (2007/CVE-2007-1417.md) ### [CVE-2007-1417](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1417) ### Description SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion. ### POC #### Reference - https://www.exploit-db.com/exploits/3449 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1420 (2007/CVE-2007-1420.md) ### [CVE-2007-1420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1420) ### Description MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function. ### POC #### Reference - http://securityreason.com/securityalert/2413 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9530 #### Github - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 1423 (2007/CVE-2007-1423.md) ### [CVE-2007-1423](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1423) ### Description Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts. ### POC #### Reference - https://www.exploit-db.com/exploits/3448 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1425 (2007/CVE-2007-1425.md) ### [CVE-2007-1425](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1425) ### Description SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action. ### POC #### Reference - https://www.exploit-db.com/exploits/3457 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1426 (2007/CVE-2007-1426.md) ### [CVE-2007-1426](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1426) ### Description The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue." ### POC #### Reference - http://astrocam.svn.sourceforge.net/viewvc/astrocam/BUGS?view=markup #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1427 (2007/CVE-2007-1427.md) ### [CVE-2007-1427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1427) ### Description Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3458 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1428 (2007/CVE-2007-1428.md) ### [CVE-2007-1428](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1428) ### Description SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3455 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1436 (2007/CVE-2007-1436.md) ### [CVE-2007-1436](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1436) ### Description Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring. ### POC #### Reference - http://securityreason.com/securityalert/2436 - http://sourceforge.net/project/shownotes.php?release_id=494462&group_id=175965 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1437 (2007/CVE-2007-1437.md) ### [CVE-2007-1437](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1437) ### Description Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution. ### POC #### Reference - http://securityreason.com/securityalert/2435 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1438 (2007/CVE-2007-1438.md) ### [CVE-2007-1438](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1438) ### Description SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3469 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1439 (2007/CVE-2007-1439.md) ### [CVE-2007-1439](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1439) ### Description PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter. ### POC #### Reference - http://securityreason.com/securityalert/2423 - https://www.exploit-db.com/exploits/3468 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1440 (2007/CVE-2007-1440.md) ### [CVE-2007-1440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1440) ### Description SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter. ### POC #### Reference - http://securityreason.com/securityalert/2431 - https://www.exploit-db.com/exploits/3470 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1441 (2007/CVE-2007-1441.md) ### [CVE-2007-1441](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1441) ### Description The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page. ### POC #### Reference - http://securityreason.com/securityalert/2434 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1445 (2007/CVE-2007-1445.md) ### [CVE-2007-1445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1445) ### Description SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3466 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1446 (2007/CVE-2007-1446.md) ### [CVE-2007-1446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1446) ### Description Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/. ### POC #### Reference - http://securityreason.com/securityalert/2421 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1451 (2007/CVE-2007-1451.md) ### [CVE-2007-1451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1451) ### Description GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php). ### POC #### Reference - http://securityreason.com/securityalert/2433 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1454 (2007/CVE-2007-1454.md) ### [CVE-2007-1454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1454) ### Description ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b. ### POC #### Reference - http://www.securityfocus.com/bid/22914 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1457 (2007/CVE-2007-1457.md) ### [CVE-2007-1457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1457) ### Description Buffer overflow in the urarlib_get function in Christian Scheurer UniquE RAR File Library (unrarlib, aka URARFileLib) 0.4 allows context-dependent attackers to execute arbitrary code via a long (1) filename, (2) rarfile, or (3) libpassword argument. ### POC #### Reference - http://unrarlib.svn.sourceforge.net/viewvc/unrarlib/tags/unrarlib040/unrarlib/unrarlib.c?revision=3&view=markup #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1458 (2007/CVE-2007-1458.md) ### [CVE-2007-1458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1458) ### Description Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1459 (2007/CVE-2007-1459.md) ### [CVE-2007-1459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1459) ### Description Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files. ### POC #### Reference - https://www.exploit-db.com/exploits/3473 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1465 (2007/CVE-2007-1465.md) ### [CVE-2007-1465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1465) ### Description Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 1466 (2007/CVE-2007-1466.md) ### [CVE-2007-1466](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1466) ### Description Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than CVE-2007-0002. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10862 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1467 (2007/CVE-2007-1467.md) ### [CVE-2007-1467](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1467) ### Description Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form. ### POC #### Reference - http://securityreason.com/securityalert/2437 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1468 (2007/CVE-2007-1468.md) ### [CVE-2007-1468](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1468) ### Description Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry. ### POC #### Reference - http://securityreason.com/securityalert/2442 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1470 (2007/CVE-2007-1470.md) ### [CVE-2007-1470](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1470) ### Description Multiple buffer overflows in LIBFtp 5.0 allow user-assisted remote attackers to execute arbitrary code via certain long arguments to the (1) FtpArchie, (2) FtpDebugDebug, (3) FtpOpenDir, (4) FtpSize, or (5) FtpChmod function. ### POC #### Reference - http://securityreason.com/securityalert/2441 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1471 (2007/CVE-2007-1471.md) ### [CVE-2007-1471](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1471) ### Description admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp. ### POC #### Reference - http://securityreason.com/securityalert/2440 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1472 (2007/CVE-2007-1472.md) ### [CVE-2007-1472](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1472) ### Description Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files. ### POC #### Reference - http://securityreason.com/securityalert/2428 - https://www.exploit-db.com/exploits/3486 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1475 (2007/CVE-2007-1475.md) ### [CVE-2007-1475](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1475) ### Description Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument. ### POC #### Reference - http://securityreason.com/securityalert/2439 - https://www.exploit-db.com/exploits/3488 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1476 (2007/CVE-2007-1476.md) ### [CVE-2007-1476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1476) ### Description The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=117396596027148&w=2 - http://securityreason.com/securityalert/2438 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1478 (2007/CVE-2007-1478.md) ### [CVE-2007-1478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1478) ### Description download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3494 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1479 (2007/CVE-2007-1479.md) ### [CVE-2007-1479](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1479) ### Description Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3489 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1480 (2007/CVE-2007-1480.md) ### [CVE-2007-1480](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1480) ### Description Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set. ### POC #### Reference - https://www.exploit-db.com/exploits/3489 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1481 (2007/CVE-2007-1481.md) ### [CVE-2007-1481](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1481) ### Description SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd. ### POC #### Reference - https://www.exploit-db.com/exploits/3490 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1482 (2007/CVE-2007-1482.md) ### [CVE-2007-1482](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1482) ### Description Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd. ### POC #### Reference - https://www.exploit-db.com/exploits/3490 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1483 (2007/CVE-2007-1483.md) ### [CVE-2007-1483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1483) ### Description Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3492 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1485 (2007/CVE-2007-1485.md) ### [CVE-2007-1485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1485) ### Description Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments ### POC #### Reference - http://securityreason.com/securityalert/2443 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1486 (2007/CVE-2007-1486.md) ### [CVE-2007-1486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1486) ### Description PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability. ### POC #### Reference - http://securityreason.com/securityalert/2432 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1487 (2007/CVE-2007-1487.md) ### [CVE-2007-1487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1487) ### Description Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action. ### POC #### Reference - https://www.exploit-db.com/exploits/3484 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1493 (2007/CVE-2007-1493.md) ### [CVE-2007-1493](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1493) ### Description nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172. ### POC #### Reference - http://securityreason.com/securityalert/2430 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1495 (2007/CVE-2007-1495.md) ### [CVE-2007-1495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1495) ### Description The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855. ### POC #### Reference - http://securityreason.com/securityalert/2445 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1496 (2007/CVE-2007-1496.md) ### [CVE-2007-1496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1496) ### Description nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9831 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1498 (2007/CVE-2007-1498.md) ### [CVE-2007-1498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1498) ### Description Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call. ### POC #### Reference - http://securityreason.com/securityalert/2444 - https://knowledge.mcafee.com/article/25/612495_f.SAL_Public.html - https://knowledge.mcafee.com/article/26/612496_f.SAL_Public.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1499 (2007/CVE-2007-1499.md) ### [CVE-2007-1499](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1499) ### Description Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability." ### POC #### Reference - http://securityreason.com/securityalert/2448 - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1501 (2007/CVE-2007-1501.md) ### [CVE-2007-1501](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1501) ### Description Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/3514 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1502 (2007/CVE-2007-1502.md) ### [CVE-2007-1502](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1502) ### Description Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands. ### POC #### Reference - http://securityreason.com/securityalert/2447 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1503 (2007/CVE-2007-1503.md) ### [CVE-2007-1503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1503) ### Description Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands. ### POC #### Reference - http://securityreason.com/securityalert/2447 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1510 (2007/CVE-2007-1510.md) ### [CVE-2007-1510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1510) ### Description SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3500 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1511 (2007/CVE-2007-1511.md) ### [CVE-2007-1511](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1511) ### Description Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name. ### POC #### Reference - http://securityreason.com/securityalert/2470 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1513 (2007/CVE-2007-1513.md) ### [CVE-2007-1513](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1513) ### Description PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter. ### POC #### Reference - http://securityreason.com/securityalert/2452 - https://www.exploit-db.com/exploits/3485 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1514 (2007/CVE-2007-1514.md) ### [CVE-2007-1514](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1514) ### Description PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter. ### POC #### Reference - http://securityreason.com/securityalert/2449 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1516 (2007/CVE-2007-1516.md) ### [CVE-2007-1516](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1516) ### Description PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3487 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1517 (2007/CVE-2007-1517.md) ### [CVE-2007-1517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1517) ### Description SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3477 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1519 (2007/CVE-2007-1519.md) ### [CVE-2007-1519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1519) ### Description Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948. ### POC #### Reference - http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1520 (2007/CVE-2007-1520.md) ### [CVE-2007-1520](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1520) ### Description The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks. ### POC #### Reference - http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1523 (2007/CVE-2007-1523.md) ### [CVE-2007-1523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1523) ### Description Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329. ### POC #### Reference - http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1524 (2007/CVE-2007-1524.md) ### [CVE-2007-1524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1524) ### Description Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/. ### POC #### Reference - https://www.exploit-db.com/exploits/3476/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1525 (2007/CVE-2007-1525.md) ### [CVE-2007-1525](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1525) ### Description Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3478 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1536 (2007/CVE-2007-1536.md) ### [CVE-2007-1536](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1536) ### Description Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/lukeber4/usn-search --- ### 2007/CVE 2007 1539 (2007/CVE-2007-1539.md) ### [CVE-2007-1539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1539) ### Description Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file. ### POC #### Reference - https://www.exploit-db.com/exploits/3521 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1540 (2007/CVE-2007-1540.md) ### [CVE-2007-1540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1540) ### Description Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter. NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=494462&group_id=175965 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1543 (2007/CVE-2007-1543.md) ### [CVE-2007-1543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1543) ### Description Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection. ### POC #### Reference - http://aluigi.altervista.org/adv/nasbugs-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1544 (2007/CVE-2007-1544.md) ### [CVE-2007-1544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1544) ### Description Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value. ### POC #### Reference - http://aluigi.altervista.org/adv/nasbugs-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1545 (2007/CVE-2007-1545.md) ### [CVE-2007-1545](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1545) ### Description The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID. ### POC #### Reference - http://aluigi.altervista.org/adv/nasbugs-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1546 (2007/CVE-2007-1546.md) ### [CVE-2007-1546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1546) ### Description Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c. ### POC #### Reference - http://aluigi.altervista.org/adv/nasbugs-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1547 (2007/CVE-2007-1547.md) ### [CVE-2007-1547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1547) ### Description The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference. ### POC #### Reference - http://aluigi.altervista.org/adv/nasbugs-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1552 (2007/CVE-2007-1552.md) ### [CVE-2007-1552](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1552) ### Description Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php. ### POC #### Reference - https://www.exploit-db.com/exploits/3516 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1553 (2007/CVE-2007-1553.md) ### [CVE-2007-1553](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1553) ### Description admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/3506 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1555 (2007/CVE-2007-1555.md) ### [CVE-2007-1555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1555) ### Description SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3519 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1556 (2007/CVE-2007-1556.md) ### [CVE-2007-1556](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1556) ### Description SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3498 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1558 (2007/CVE-2007-1558.md) ### [CVE-2007-1558](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558) ### Description The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9782 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1560 (2007/CVE-2007-1560.md) ### [CVE-2007-1560](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1560) ### Description The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10291 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1561 (2007/CVE-2007-1561.md) ### [CVE-2007-1561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1561) ### Description The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=117432783011737&w=2 - http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1566 (2007/CVE-2007-1566.md) ### [CVE-2007-1566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1566) ### Description SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954. ### POC #### Reference - https://www.exploit-db.com/exploits/3520 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1567 (2007/CVE-2007-1567.md) ### [CVE-2007-1567](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1567) ### Description Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/Creamy-Chicken-Soup/Exploit - https://github.com/Creamy-Chicken-Soup/My-Writeup - https://github.com/Creamy-Chicken-Soup/WindowsVulnAPP - https://github.com/iricartb/buffer-overflow-warftp-1.65 - https://github.com/war4uthor/CVE-2007-1567 --- ### 2007/CVE 2007 1568 (2007/CVE-2007-1568.md) ### [CVE-2007-1568](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1568) ### Description Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename. ### POC #### Reference - https://www.exploit-db.com/exploits/3462 - https://www.exploit-db.com/exploits/3463 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1569 (2007/CVE-2007-1569.md) ### [CVE-2007-1569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1569) ### Description Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3464 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1571 (2007/CVE-2007-1571.md) ### [CVE-2007-1571](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1571) ### Description PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3471 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1577 (2007/CVE-2007-1577.md) ### [CVE-2007-1577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1577) ### Description Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3522 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1578 (2007/CVE-2007-1578.md) ### [CVE-2007-1578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1578) ### Description Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow. ### POC #### Reference - https://www.exploit-db.com/exploits/3527 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1579 (2007/CVE-2007-1579.md) ### [CVE-2007-1579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1579) ### Description Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. ### POC #### Reference - https://www.exploit-db.com/exploits/3537 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1580 (2007/CVE-2007-1580.md) ### [CVE-2007-1580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1580) ### Description FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:". NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument. ### POC #### Reference - https://www.exploit-db.com/exploits/3523 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1581 (2007/CVE-2007-1581.md) ### [CVE-2007-1581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1581) ### Description The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/3529 #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2007/CVE 2007 1582 (2007/CVE-2007-1582.md) ### [CVE-2007-1582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1582) ### Description The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources. ### POC #### Reference - https://www.exploit-db.com/exploits/3525 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1584 (2007/CVE-2007-1584.md) ### [CVE-2007-1584](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1584) ### Description Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string. ### POC #### Reference - https://www.exploit-db.com/exploits/3517 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1592 (2007/CVE-2007-1592.md) ### [CVE-2007-1592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1592) ### Description net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_30_kernel.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1594 (2007/CVE-2007-1594.md) ### [CVE-2007-1594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1594) ### Description The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Response code 0 in a SIP packet. ### POC #### Reference - http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1596 (2007/CVE-2007-1596.md) ### [CVE-2007-1596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1596) ### Description Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3539 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1600 (2007/CVE-2007-1600.md) ### [CVE-2007-1600](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1600) ### Description PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3533 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1612 (2007/CVE-2007-1612.md) ### [CVE-2007-1612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1612) ### Description SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3513 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1613 (2007/CVE-2007-1613.md) ### [CVE-2007-1613](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1613) ### Description Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3503 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1615 (2007/CVE-2007-1615.md) ### [CVE-2007-1615](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1615) ### Description SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3509 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1616 (2007/CVE-2007-1616.md) ### [CVE-2007-1616](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1616) ### Description SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3515 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1617 (2007/CVE-2007-1617.md) ### [CVE-2007-1617](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1617) ### Description SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1618 (2007/CVE-2007-1618.md) ### [CVE-2007-1618](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1618) ### Description SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1619 (2007/CVE-2007-1619.md) ### [CVE-2007-1619](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1619) ### Description SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3511 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1620 (2007/CVE-2007-1620.md) ### [CVE-2007-1620](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1620) ### Description Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3501 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1621 (2007/CVE-2007-1621.md) ### [CVE-2007-1621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1621) ### Description PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter. NOTE: this issue might be related to CVE-2003-1254. ### POC #### Reference - https://www.exploit-db.com/exploits/3504 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1622 (2007/CVE-2007-1622.md) ### [CVE-2007-1622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1622) ### Description Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF. ### POC #### Reference - http://www.buayacorp.com/files/wordpress/wordpress-advisory.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1626 (2007/CVE-2007-1626.md) ### [CVE-2007-1626](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1626) ### Description PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3512 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1628 (2007/CVE-2007-1628.md) ### [CVE-2007-1628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1628) ### Description Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files. ### POC #### Reference - https://www.exploit-db.com/exploits/3532 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1629 (2007/CVE-2007-1629.md) ### [CVE-2007-1629](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1629) ### Description SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3536 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1630 (2007/CVE-2007-1630.md) ### [CVE-2007-1630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1630) ### Description SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3534 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1633 (2007/CVE-2007-1633.md) ### [CVE-2007-1633](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1633) ### Description Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3518 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1636 (2007/CVE-2007-1636.md) ### [CVE-2007-1636](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1636) ### Description Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/3548 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1640 (2007/CVE-2007-1640.md) ### [CVE-2007-1640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1640) ### Description Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3542 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1641 (2007/CVE-2007-1641.md) ### [CVE-2007-1641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1641) ### Description SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3543 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1643 (2007/CVE-2007-1643.md) ### [CVE-2007-1643](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1643) ### Description Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3545 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1644 (2007/CVE-2007-1644.md) ### [CVE-2007-1644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1644) ### Description The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution). ### POC #### Reference - https://www.exploit-db.com/exploits/3544 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1645 (2007/CVE-2007-1645.md) ### [CVE-2007-1645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1645) ### Description Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812. ### POC #### Reference - https://www.exploit-db.com/exploits/3541 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1646 (2007/CVE-2007-1646.md) ### [CVE-2007-1646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1646) ### Description Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the searchtext parameter to (a) /search, or the (2) message parameter to (b) /calendar or (c) /subscribe. ### POC #### Reference - http://securityreason.com/securityalert/2475 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1647 (2007/CVE-2007-1647.md) ### [CVE-2007-1647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1647) ### Description Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/. ### POC #### Reference - https://www.exploit-db.com/exploits/3508 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1648 (2007/CVE-2007-1648.md) ### [CVE-2007-1648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1648) ### Description 0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference. ### POC #### Reference - https://www.exploit-db.com/exploits/3547 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1658 (2007/CVE-2007-1658.md) ### [CVE-2007-1658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1658) ### Description Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe). ### POC #### Reference - http://isc.sans.org/diary.html?storyid=2507 - http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9014194 - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1659 (2007/CVE-2007-1659.md) ### [CVE-2007-1659](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1659) ### Description Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9725 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1660 (2007/CVE-2007-1660.md) ### [CVE-2007-1660](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1660) ### Description Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified "multiple forms of character class", which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0546.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1667 (2007/CVE-2007-1667.md) ### [CVE-2007-1667](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667) ### Description Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9776 #### Github - https://github.com/fkie-cad/nvd-json-data-feeds --- ### 2007/CVE 2007 1669 (2007/CVE-2007-1669.md) ### [CVE-2007-1669](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1669) ### Description zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1671 (2007/CVE-2007-1671.md) ### [CVE-2007-1671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1671) ### Description avpack32.dll before 7.3.0.6 in Avira AntiVir allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1672 (2007/CVE-2007-1672.md) ### [CVE-2007-1672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1672) ### Description avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1673 (2007/CVE-2007-1673.md) ### [CVE-2007-1673](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1673) ### Description unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1674 (2007/CVE-2007-1674.md) ### [CVE-2007-1674](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1674) ### Description Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1675 (2007/CVE-2007-1675.md) ### [CVE-2007-1675](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1675) ### Description Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1678 (2007/CVE-2007-1678.md) ### [CVE-2007-1678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1678) ### Description Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler. ### POC #### Reference - http://securityreason.com/securityalert/2480 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1679 (2007/CVE-2007-1679.md) ### [CVE-2007-1679](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1679) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages ### POC #### Reference - http://securityreason.com/securityalert/2487 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1680 (2007/CVE-2007-1680.md) ### [CVE-2007-1680](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1680) ### Description Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties. ### POC #### Reference - http://messenger.yahoo.com/security_update.php?id=031207 - http://securityreason.com/securityalert/2523 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1685 (2007/CVE-2007-1685.md) ### [CVE-2007-1685](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1685) ### Description Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1692 (2007/CVE-2007-1692.md) ### [CVE-2007-1692](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1692) ### Description The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer. NOTE: it could be argued that if an attacker already has control over WINS/DNS, then web traffic could already be intercepted by modifying WINS or DNS records, so this would not cross privilege boundaries and would not be a vulnerability. It has also been reported that DHCP is an alternate attack vector. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=2517 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1693 (2007/CVE-2007-1693.md) ### [CVE-2007-1693](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1693) ### Description The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter. ### POC #### Reference - http://securityreason.com/securityalert/2716 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1696 (2007/CVE-2007-1696.md) ### [CVE-2007-1696](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1696) ### Description SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3556 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1697 (2007/CVE-2007-1697.md) ### [CVE-2007-1697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1697) ### Description PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3552 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1698 (2007/CVE-2007-1698.md) ### [CVE-2007-1698](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1698) ### Description download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3552 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1699 (2007/CVE-2007-1699.md) ### [CVE-2007-1699](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1699) ### Description Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees. ### POC #### Reference - https://www.exploit-db.com/exploits/3557 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1701 (2007/CVE-2007-1701.md) ### [CVE-2007-1701](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1701) ### Description PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:". ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1702 (2007/CVE-2007-1702.md) ### [CVE-2007-1702](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1702) ### Description PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3567 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1703 (2007/CVE-2007-1703.md) ### [CVE-2007-1703](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1703) ### Description SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3565 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1704 (2007/CVE-2007-1704.md) ### [CVE-2007-1704](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1704) ### Description SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3564 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1705 (2007/CVE-2007-1705.md) ### [CVE-2007-1705](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1705) ### Description SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3549 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1706 (2007/CVE-2007-1706.md) ### [CVE-2007-1706](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1706) ### Description SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1707 (2007/CVE-2007-1707.md) ### [CVE-2007-1707](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1707) ### Description PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3562 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1708 (2007/CVE-2007-1708.md) ### [CVE-2007-1708](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1708) ### Description PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3563 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1709 (2007/CVE-2007-1709.md) ### [CVE-2007-1709](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1709) ### Description Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string. ### POC #### Reference - http://securityreason.com/securityalert/2512 - https://www.exploit-db.com/exploits/3576 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1710 (2007/CVE-2007-1710.md) ### [CVE-2007-1710](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1710) ### Description The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence. ### POC #### Reference - https://www.exploit-db.com/exploits/3573 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1712 (2007/CVE-2007-1712.md) ### [CVE-2007-1712](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1712) ### Description SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3551 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1714 (2007/CVE-2007-1714.md) ### [CVE-2007-1714](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1714) ### Description Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter. ### POC #### Reference - http://securityreason.com/securityalert/2481 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1715 (2007/CVE-2007-1715.md) ### [CVE-2007-1715](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1715) ### Description PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763. ### POC #### Reference - https://www.exploit-db.com/exploits/3568 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1719 (2007/CVE-2007-1719.md) ### [CVE-2007-1719](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1719) ### Description Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name. ### POC #### Reference - https://www.exploit-db.com/exploits/3578 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1720 (2007/CVE-2007-1720.md) ### [CVE-2007-1720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1720) ### Description Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file. ### POC #### Reference - https://www.exploit-db.com/exploits/3582 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1721 (2007/CVE-2007-1721.md) ### [CVE-2007-1721](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1721) ### Description Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php. ### POC #### Reference - http://securityreason.com/securityalert/2491 - https://www.exploit-db.com/exploits/3583 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1723 (2007/CVE-2007-1723.md) ### [CVE-2007-1723](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1723) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the administration console in Secure Computing CipherTrust IronMail 6.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) network, (2) defRouterIp, (3) hostName, (4) domainName, (5) ipAddress, (6) defaultRouter, (7) dns1, or (8) dns2 parameter to (a) admin/system_IronMail.do; the (9) ipAddress parameter to (b) admin/systemOutOfBand.do; the (10) password or (11) confirmPassword parameter to (c) admin/systemBackup.do; the (12) Klicense parameter to (d) admin/systemLicenseManager.do; the (13) rows[1].attrValueStr or (14) rows[2].attrValueStr parameter to (e) admin/systemWebAdminConfig.do; the (15) rows[0].attrValueStr, rows[1].attrValueStr, (16) rows[2].attrValue, or (17) rows[2].attrValueStrClone parameter to (f) admin/ldap_ConfigureServiceProperties.do; the (18) input1 parameter to (g) admin/mailFirewall_MailRoutingInternal.do; or the (19) rows[2].attrValueStr, (20) rows[3].attrValueStr, (21) rows[5].attrValueStr, or (22) rows[6].attrValueStr parameter to (h) admin/mailIdsConfig.do. ### POC #### Reference - http://securityreason.com/securityalert/2484 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1725 (2007/CVE-2007-1725.md) ### [CVE-2007-1725](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1725) ### Description SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges. ### POC #### Reference - https://www.exploit-db.com/exploits/3580 - https://www.exploit-db.com/exploits/3581 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1726 (2007/CVE-2007-1726.md) ### [CVE-2007-1726](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1726) ### Description Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/. ### POC #### Reference - https://www.exploit-db.com/exploits/3581 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1728 (2007/CVE-2007-1728.md) ### [CVE-2007-1728](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1728) ### Description The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets. ### POC #### Reference - http://securityreason.com/securityalert/2485 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1729 (2007/CVE-2007-1729.md) ### [CVE-2007-1729](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1729) ### Description SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php. ### POC #### Reference - http://securityreason.com/securityalert/2486 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1730 (2007/CVE-2007-1730.md) ### [CVE-2007-1730](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1730) ### Description Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value. ### POC #### Reference - http://securityreason.com/securityalert/2482 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1732 (2007/CVE-2007-1732.md) ### [CVE-2007-1732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1732) ### Description Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor ### POC #### Reference - http://marc.info/?l=bugtraq&m=117319839710382&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1733 (2007/CVE-2007-1733.md) ### [CVE-2007-1733](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1733) ### Description Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112. ### POC #### Reference - http://securityreason.com/securityalert/2483 - https://www.exploit-db.com/exploits/3589 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1734 (2007/CVE-2007-1734.md) ### [CVE-2007-1734](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1734) ### Description The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730. ### POC #### Reference - http://securityreason.com/securityalert/2511 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1735 (2007/CVE-2007-1735.md) ### [CVE-2007-1735](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1735) ### Description Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document. ### POC #### Reference - http://securityreason.com/securityalert/2489 - https://www.exploit-db.com/exploits/3593 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1736 (2007/CVE-2007-1736.md) ### [CVE-2007-1736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1736) ### Description Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection. ### POC #### Reference - http://securityreason.com/securityalert/2488 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1737 (2007/CVE-2007-1737.md) ### [CVE-2007-1737](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1737) ### Description Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection. ### POC #### Reference - http://securityreason.com/securityalert/2488 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1738 (2007/CVE-2007-1738.md) ### [CVE-2007-1738](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1738) ### Description TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xdea/exploits --- ### 2007/CVE 2007 1741 (2007/CVE-2007-1741.md) ### [CVE-2007-1741](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1741) ### Description Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 1742 (2007/CVE-2007-1742.md) ### [CVE-2007-1742](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1742) ### Description suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 1743 (2007/CVE-2007-1743.md) ### [CVE-2007-1743](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1743) ### Description suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 1744 (2007/CVE-2007-1744.md) ### [CVE-2007-1744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1744) ### Description Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface. ### POC #### Reference - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1747 (2007/CVE-2007-1747.md) ### [CVE-2007-1747](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1747) ### Description Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-025 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1749 (2007/CVE-2007-1749.md) ### [CVE-2007-1749](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1749) ### Description Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-050 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1750 (2007/CVE-2007-1750.md) ### [CVE-2007-1750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1750) ### Description Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1751 (2007/CVE-2007-1751.md) ### [CVE-2007-1751](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1751) ### Description Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1754 (2007/CVE-2007-1754.md) ### [CVE-2007-1754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1754) ### Description PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability". ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-037 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1756 (2007/CVE-2007-1756.md) ### [CVE-2007-1756](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1756) ### Description Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability". ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1764 (2007/CVE-2007-1764.md) ### [CVE-2007-1764](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1764) ### Description Stack-based buffer overflow in FastStone Image Viewer 2.8 allows user-assisted remote attackers to execute arbitrary code via a crafted JPG image. ### POC #### Reference - http://securityreason.com/securityalert/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1765 (2007/CVE-2007-1765.md) ### [CVE-2007-1765](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1765) ### Description Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Cruxer8Mech/Idk - https://github.com/ycdxsb/WindowsPrivilegeEscalation --- ### 2007/CVE 2007 1766 (2007/CVE-2007-1766.md) ### [CVE-2007-1766](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1766) ### Description PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. ### POC #### Reference - http://securityreason.com/securityalert/2508 - https://www.exploit-db.com/exploits/3608 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1770 (2007/CVE-2007-1770.md) ### [CVE-2007-1770](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1770) ### Description Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1771 (2007/CVE-2007-1771.md) ### [CVE-2007-1771](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1771) ### Description PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3592 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1776 (2007/CVE-2007-1776.md) ### [CVE-2007-1776](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1776) ### Description SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action. ### POC #### Reference - https://www.exploit-db.com/exploits/3590 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1777 (2007/CVE-2007-1777.md) ### [CVE-2007-1777](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1777) ### Description Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 1778 (2007/CVE-2007-1778.md) ### [CVE-2007-1778](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1778) ### Description PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3591 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1785 (2007/CVE-2007-1785.md) ### [CVE-2007-1785](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1785) ### Description The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request. ### POC #### Reference - http://securityreason.com/securityalert/2509 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/shirkdog/exploits --- ### 2007/CVE 2007 1787 (2007/CVE-2007-1787.md) ### [CVE-2007-1787](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1787) ### Description Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3600 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1790 (2007/CVE-2007-1790.md) ### [CVE-2007-1790](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1790) ### Description Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/. ### POC #### Reference - https://www.exploit-db.com/exploits/3607 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1791 (2007/CVE-2007-1791.md) ### [CVE-2007-1791](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1791) ### Description SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3605 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1797 (2007/CVE-2007-1797.md) ### [CVE-2007-1797](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1797) ### Description Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667. ### POC #### Reference - http://www.imagemagick.org/script/changelog.php - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9254 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1800 (2007/CVE-2007-1800.md) ### [CVE-2007-1800](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1800) ### Description Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might be limited to authenticated users and devices. ### POC #### Reference - http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Dror #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1801 (2007/CVE-2007-1801.md) ### [CVE-2007-1801](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1801) ### Description Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3601 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1804 (2007/CVE-2007-1804.md) ### [CVE-2007-1804](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1804) ### Description PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file. ### POC #### Reference - http://aluigi.altervista.org/adv/pulsex-adv.txt - http://aluigi.org/poc/pulsex.zip - http://www.mandriva.com/security/advisories?name=MDVSA-2008:065 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1805 (2007/CVE-2007-1805.md) ### [CVE-2007-1805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1805) ### Description SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the genreid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3630 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1806 (2007/CVE-2007-1806.md) ### [CVE-2007-1806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1806) ### Description SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3633 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1807 (2007/CVE-2007-1807.md) ### [CVE-2007-1807](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1807) ### Description SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3632 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1808 (2007/CVE-2007-1808.md) ### [CVE-2007-1808](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1808) ### Description SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the camid parameter in a showcam action. ### POC #### Reference - https://www.exploit-db.com/exploits/3629 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1809 (2007/CVE-2007-1809.md) ### [CVE-2007-1809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1809) ### Description Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513. ### POC #### Reference - https://www.exploit-db.com/exploits/3628 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1810 (2007/CVE-2007-1810.md) ### [CVE-2007-1810](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1810) ### Description SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3626 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1811 (2007/CVE-2007-1811.md) ### [CVE-2007-1811](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1811) ### Description SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. ### POC #### Reference - https://www.exploit-db.com/exploits/3625 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1812 (2007/CVE-2007-1812.md) ### [CVE-2007-1812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1812) ### Description PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire_visiteur parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3624 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1813 (2007/CVE-2007-1813.md) ### [CVE-2007-1813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1813) ### Description SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the katid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3623 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1814 (2007/CVE-2007-1814.md) ### [CVE-2007-1814](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1814) ### Description SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-0377. ### POC #### Reference - https://www.exploit-db.com/exploits/3620 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1815 (2007/CVE-2007-1815.md) ### [CVE-2007-1815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1815) ### Description SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3619 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1816 (2007/CVE-2007-1816.md) ### [CVE-2007-1816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1816) ### Description SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3621 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1817 (2007/CVE-2007-1817.md) ### [CVE-2007-1817](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1817) ### Description SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action. ### POC #### Reference - https://www.exploit-db.com/exploits/3618 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1818 (2007/CVE-2007-1818.md) ### [CVE-2007-1818](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1818) ### Description PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3613 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1825 (2007/CVE-2007-1825.md) ### [CVE-2007-1825](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1825) ### Description Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 1826 (2007/CVE-2007-1826.md) ### [CVE-2007-1826](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1826) ### Description Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a "specific UDP packet" to UDP port 8500, aka bug ID CSCsg60949. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1833 (2007/CVE-2007-1833.md) ### [CVE-2007-1833](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1833) ### Description The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or (2) SCCPS (2443/tcp) port. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1834 (2007/CVE-2007-1834.md) ### [CVE-2007-1834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1834) ### Description Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1836 (2007/CVE-2007-1836.md) ### [CVE-2007-1836](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1836) ### Description The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various commands, as demonstrated by the interface argument to the (1) ifconfig and (2) ping commands. ### POC #### Reference - http://securityreason.com/securityalert/2516 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1837 (2007/CVE-2007-1837.md) ### [CVE-2007-1837](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1837) ### Description Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3598 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1838 (2007/CVE-2007-1838.md) ### [CVE-2007-1838](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1838) ### Description SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3597 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1839 (2007/CVE-2007-1839.md) ### [CVE-2007-1839](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1839) ### Description Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select. ### POC #### Reference - https://www.exploit-db.com/exploits/3599 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1841 (2007/CVE-2007-1841.md) ### [CVE-2007-1841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1841) ### Description The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages. ### POC #### Reference - http://www.ubuntu.com/usn/usn-450-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1842 (2007/CVE-2007-1842.md) ### [CVE-2007-1842](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1842) ### Description Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019. ### POC #### Reference - https://www.exploit-db.com/exploits/3614 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1843 (2007/CVE-2007-1843.md) ### [CVE-2007-1843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1843) ### Description PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3638 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1844 (2007/CVE-2007-1844.md) ### [CVE-2007-1844](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1844) ### Description Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php. ### POC #### Reference - http://securityreason.com/securityalert/2515 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1845 (2007/CVE-2007-1845.md) ### [CVE-2007-1845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1845) ### Description SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter. ### POC #### Reference - http://securityreason.com/securityalert/2514 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1846 (2007/CVE-2007-1846.md) ### [CVE-2007-1846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1846) ### Description SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341. ### POC #### Reference - https://www.exploit-db.com/exploits/3603 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1847 (2007/CVE-2007-1847.md) ### [CVE-2007-1847](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1847) ### Description SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3612 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1848 (2007/CVE-2007-1848.md) ### [CVE-2007-1848](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1848) ### Description Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS." ### POC #### Reference - http://securityreason.com/securityalert/2522 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1850 (2007/CVE-2007-1850.md) ### [CVE-2007-1850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1850) ### Description Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS." ### POC #### Reference - http://securityreason.com/securityalert/2522 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1851 (2007/CVE-2007-1851.md) ### [CVE-2007-1851](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1851) ### Description Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3641 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1852 (2007/CVE-2007-1852.md) ### [CVE-2007-1852](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1852) ### Description Multiple PHP remote file inclusion vulnerabilities in 2BGal 3.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the lang_filename parameter to (1) index.php or (2) backupdb.inc.php in admin/, or other unspecified files, different vectors than CVE-2006-5505. NOTE: this issue has been disputed by CVE, since the lang_filename variable is defined before it is used ### POC #### Reference - http://securityreason.com/securityalert/2517 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1855 (2007/CVE-2007-1855.md) ### [CVE-2007-1855](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1855) ### Description Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters. NOTE: this issue might be related to CVE-2006-7105. ### POC #### Reference - http://securityreason.com/securityalert/2520 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1858 (2007/CVE-2007-1858.md) ### [CVE-2007-1858](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1858) ### Description The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx - http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html #### Github - https://github.com/84KaliPleXon3/a2sv - https://github.com/ARPSyndicate/cvemon - https://github.com/F4RM0X/script_a2sv - https://github.com/H4CK3RT3CH/a2sv - https://github.com/Liber-Primus/ARC_Vulnerability_Scanner - https://github.com/MrE-Fog/a2sv - https://github.com/Mre11i0t/a2sv - https://github.com/Pytools786/website-vulnerability-scanner- - https://github.com/Ruzi79/CyberSecurityLab4 - https://github.com/Sailakshmangoud/Web-Application-Vulnerability-Scanner - https://github.com/TheRipperJhon/a2sv - https://github.com/a-s-aromal/ARC_Vulnerability_Scanner - https://github.com/anthophilee/A2SV--SSL-VUL-Scan - https://github.com/clic-kbait/A2SV--SSL-VUL-Scan - https://github.com/clino-mania/A2SV--SSL-VUL-Scan - https://github.com/coldorb0/SSL-Scanner - https://github.com/elptakeover/action - https://github.com/emarexteam/Projes - https://github.com/emarexteam/WebsiteScannerVulnerability - https://github.com/fireorb/SSL-Scanner - https://github.com/fireorb/sslscanner - https://github.com/hahwul/a2sv - https://github.com/hashbrown1013/Spaghetti - https://github.com/mohitrex7/Wap-Recon - https://github.com/paroteen/SecurEagle - https://github.com/shenril/Sitadel - https://github.com/tag888/tag123 - https://github.com/waseemasmaeel/A2sv_Tools --- ### 2007/CVE 2007 1859 (2007/CVE-2007-1859.md) ### [CVE-2007-1859](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1859) ### Description XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11459 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1860 (2007/CVE-2007-1860.md) ### [CVE-2007-1860](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860) ### Description mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450. ### POC #### Reference No PoCs from references. #### Github - https://github.com/RedisMadani/cyber-vault - https://github.com/dxktw/cyber-vault - https://github.com/mgeeky/tomcatWarDeployer - https://github.com/nemocyberworld/Captain-Nemo - https://github.com/nemocyberworld/captain-nemo - https://github.com/paulveillard/cybersecurity-infosec - https://github.com/sagardevopss/sample_web_app - https://github.com/sagardevopss/simple-maker - https://github.com/yingshang/sturoad --- ### 2007/CVE 2007 1862 (2007/CVE-2007-1862.md) ### [CVE-2007-1862](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1862) ### Description The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information. ### POC #### Reference - http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 - http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1863 (2007/CVE-2007-1863.md) ### [CVE-2007-1863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863) ### Description cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1697 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1866 (2007/CVE-2007-1866.md) ### [CVE-2007-1866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1866) ### Description Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465. ### POC #### Reference - http://dproxy.cvs.sourceforge.net/dproxy/dproxy-nexgen/dns_decode.c?revision=1.10&view=markup - http://securityreason.com/securityalert/2518 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1867 (2007/CVE-2007-1867.md) ### [CVE-2007-1867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1867) ### Description Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. ### POC #### Reference - https://www.exploit-db.com/exploits/3648 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 1871 (2007/CVE-2007-1871.md) ### [CVE-2007-1871](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1871) ### Description Cross-site scripting (XSS) vulnerability in chcounter 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the login_name parameter to /stats/. ### POC #### Reference - http://securityreason.com/securityalert/2569 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1872 (2007/CVE-2007-1872.md) ### [CVE-2007-1872](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1872) ### Description Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search id. ### POC #### Reference - http://securityreason.com/securityalert/2568 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1876 (2007/CVE-2007-1876.md) ### [CVE-2007-1876](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1876) ### Description VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction." ### POC #### Reference - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1877 (2007/CVE-2007-1877.md) ### [CVE-2007-1877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1877) ### Description VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information. ### POC #### Reference - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1878 (2007/CVE-2007-1878.md) ### [CVE-2007-1878](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1878) ### Description Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name. ### POC #### Reference - http://securityreason.com/securityalert/2525 - http://www.gnucitizen.org/blog/firebug-goes-evil #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1882 (2007/CVE-2007-1882.md) ### [CVE-2007-1882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1882) ### Description qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method. ### POC #### Reference - http://securityreason.com/securityalert/2527 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1894 (2007/CVE-2007-1894.md) ### [CVE-2007-1894](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1894) ### Description Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function. ### POC #### Reference - http://chxsecurity.org/advisories/adv-1-mid.txt - http://securityreason.com/securityalert/2526 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1895 (2007/CVE-2007-1895.md) ### [CVE-2007-1895](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1895) ### Description PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630. ### POC #### Reference - https://www.exploit-db.com/exploits/3657 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1896 (2007/CVE-2007-1896.md) ### [CVE-2007-1896](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1896) ### Description Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/3657 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1897 (2007/CVE-2007-1897.md) ### [CVE-2007-1897](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1897) ### Description SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable. ### POC #### Reference - https://www.exploit-db.com/exploits/3656 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1898 (2007/CVE-2007-1898.md) ### [CVE-2007-1898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1898) ### Description formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters. ### POC #### Reference - http://securityreason.com/securityalert/2710 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1899 (2007/CVE-2007-1899.md) ### [CVE-2007-1899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1899) ### Description Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php. ### POC #### Reference - https://www.exploit-db.com/exploits/5975 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1905 (2007/CVE-2007-1905.md) ### [CVE-2007-1905](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1905) ### Description Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<". ### POC #### Reference - http://securityreason.com/securityalert/2554 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1906 (2007/CVE-2007-1906.md) ### [CVE-2007-1906](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1906) ### Description Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter. ### POC #### Reference - http://securityreason.com/securityalert/2533 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1907 (2007/CVE-2007-1907.md) ### [CVE-2007-1907](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1907) ### Description PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3696 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1908 (2007/CVE-2007-1908.md) ### [CVE-2007-1908](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1908) ### Description PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function. ### POC #### Reference - https://www.exploit-db.com/exploits/3694 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1909 (2007/CVE-2007-1909.md) ### [CVE-2007-1909](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1909) ### Description SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3691 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1910 (2007/CVE-2007-1910.md) ### [CVE-2007-1910](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1910) ### Description Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc. ### POC #### Reference - https://www.exploit-db.com/exploits/3690 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1911 (2007/CVE-2007-1911.md) ### [CVE-2007-1911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1911) ### Description Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow. ### POC #### Reference - https://www.exploit-db.com/exploits/3690 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1912 (2007/CVE-2007-1912.md) ### [CVE-2007-1912](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1912) ### Description Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. ### POC #### Reference - https://www.exploit-db.com/exploits/3693 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1913 (2007/CVE-2007-1913.md) ### [CVE-2007-1913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1913) ### Description The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2535 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1914 (2007/CVE-2007-1914.md) ### [CVE-2007-1914](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1914) ### Description The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2538 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1915 (2007/CVE-2007-1915.md) ### [CVE-2007-1915](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1915) ### Description Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2538 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1916 (2007/CVE-2007-1916.md) ### [CVE-2007-1916](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1916) ### Description Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2537 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1917 (2007/CVE-2007-1917.md) ### [CVE-2007-1917](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1917) ### Description Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2536 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1918 (2007/CVE-2007-1918.md) ### [CVE-2007-1918](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1918) ### Description The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. ### POC #### Reference - http://securityreason.com/securityalert/2540 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1920 (2007/CVE-2007-1920.md) ### [CVE-2007-1920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1920) ### Description SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3678 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1921 (2007/CVE-2007-1921.md) ### [CVE-2007-1921](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1921) ### Description LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT file that contains a value that is used as an offset, which triggers memory corruption. ### POC #### Reference - http://securityreason.com/securityalert/2541 - http://www.piotrbania.com/all/adv/nullsoft-winamp-libsndfile-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1922 (2007/CVE-2007-1922.md) ### [CVE-2007-1922](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1922) ### Description The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption. ### POC #### Reference - http://securityreason.com/securityalert/2532 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1923 (2007/CVE-2007-1923.md) ### [CVE-2007-1923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1923) ### Description (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0. ### POC #### Reference - http://securityreason.com/securityalert/2552 - https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1924 (2007/CVE-2007-1924.md) ### [CVE-2007-1924](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1924) ### Description Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php. NOTE: this issue is disputed by CVE and a reliable third party, because include_path is initialized to a fixed value before use ### POC #### Reference - http://securityreason.com/securityalert/2528 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1926 (2007/CVE-2007-1926.md) ### [CVE-2007-1926](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1926) ### Description Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files. ### POC #### Reference - http://securityreason.com/securityalert/2534 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1927 (2007/CVE-2007-1927.md) ### [CVE-2007-1927](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1927) ### Description Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter. ### POC #### Reference - http://securityreason.com/securityalert/2529 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1928 (2007/CVE-2007-1928.md) ### [CVE-2007-1928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1928) ### Description Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter. ### POC #### Reference - http://securityreason.com/securityalert/2539 - http://www.vupen.com/english/advisories/2007/1303 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1929 (2007/CVE-2007-1929.md) ### [CVE-2007-1929](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1929) ### Description Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3676 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1930 (2007/CVE-2007-1930.md) ### [CVE-2007-1930](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1930) ### Description Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3677 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1931 (2007/CVE-2007-1931.md) ### [CVE-2007-1931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1931) ### Description SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3679 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1932 (2007/CVE-2007-1932.md) ### [CVE-2007-1932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1932) ### Description Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3687 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1933 (2007/CVE-2007-1933.md) ### [CVE-2007-1933](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1933) ### Description Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3689 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1934 (2007/CVE-2007-1934.md) ### [CVE-2007-1934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1934) ### Description Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3683 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1935 (2007/CVE-2007-1935.md) ### [CVE-2007-1935](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1935) ### Description PHP file inclusion vulnerability in admin/index.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the site parameter, which is accessed by the file_exists function. ### POC #### Reference - https://www.exploit-db.com/exploits/3682 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1936 (2007/CVE-2007-1936.md) ### [CVE-2007-1936](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1936) ### Description PHP remote file inclusion vulnerability in scaradcontrol.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sac_config_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3682 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1937 (2007/CVE-2007-1937.md) ### [CVE-2007-1937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1937) ### Description PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3681 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1942 (2007/CVE-2007-1942.md) ### [CVE-2007-1942](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1942) ### Description Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp. ### POC #### Reference - http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html - http://securityreason.com/securityalert/2558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1943 (2007/CVE-2007-1943.md) ### [CVE-2007-1943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1943) ### Description Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp. ### POC #### Reference - http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html - http://securityreason.com/securityalert/2558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1946 (2007/CVE-2007-1946.md) ### [CVE-2007-1946](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1946) ### Description Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp. ### POC #### Reference - http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html - http://securityreason.com/securityalert/2558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1948 (2007/CVE-2007-1948.md) ### [CVE-2007-1948](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1948) ### Description Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp. ### POC #### Reference - http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html - http://securityreason.com/securityalert/2558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1949 (2007/CVE-2007-1949.md) ### [CVE-2007-1949](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1949) ### Description Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. ### POC #### Reference - http://securityreason.com/securityalert/2557 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1950 (2007/CVE-2007-1950.md) ### [CVE-2007-1950](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1950) ### Description Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter. ### POC #### Reference - http://securityreason.com/securityalert/2557 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1952 (2007/CVE-2007-1952.md) ### [CVE-2007-1952](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1952) ### Description Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. ### POC #### Reference - http://securityreason.com/securityalert/2546 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1956 (2007/CVE-2007-1956.md) ### [CVE-2007-1956](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1956) ### Description SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter. ### POC #### Reference - http://securityreason.com/securityalert/2545 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1957 (2007/CVE-2007-1957.md) ### [CVE-2007-1957](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1957) ### Description Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/. ### POC #### Reference - http://securityreason.com/securityalert/2543 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1960 (2007/CVE-2007-1960.md) ### [CVE-2007-1960](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1960) ### Description SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3666 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1961 (2007/CVE-2007-1961.md) ### [CVE-2007-1961](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1961) ### Description PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3665 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1962 (2007/CVE-2007-1962.md) ### [CVE-2007-1962](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1962) ### Description SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action. ### POC #### Reference - https://www.exploit-db.com/exploits/3663 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1963 (2007/CVE-2007-1963.md) ### [CVE-2007-1963](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1963) ### Description SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775. ### POC #### Reference - https://www.exploit-db.com/exploits/3653 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1964 (2007/CVE-2007-1964.md) ### [CVE-2007-1964](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1964) ### Description member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output. ### POC #### Reference - http://securityreason.com/securityalert/2544 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1967 (2007/CVE-2007-1967.md) ### [CVE-2007-1967](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1967) ### Description PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party ### POC #### Reference - http://securityreason.com/securityalert/2555 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1968 (2007/CVE-2007-1968.md) ### [CVE-2007-1968](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1968) ### Description PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter. ### POC #### Reference - http://securityreason.com/securityalert/2548 - https://www.exploit-db.com/exploits/3685 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1969 (2007/CVE-2007-1969.md) ### [CVE-2007-1969](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1969) ### Description Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2549 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1971 (2007/CVE-2007-1971.md) ### [CVE-2007-1971](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1971) ### Description SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string. ### POC #### Reference - http://securityreason.com/securityalert/2547 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1972 (2007/CVE-2007-1972.md) ### [CVE-2007-1972](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1972) ### Description PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured ### POC #### Reference - http://securityreason.com/securityalert/2599 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1973 (2007/CVE-2007-1973.md) ### [CVE-2007-1973](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1973) ### Description Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206. ### POC #### Reference - http://securityreason.com/securityalert/2563 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1974 (2007/CVE-2007-1974.md) ### [CVE-2007-1974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1974) ### Description SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3644 - https://www.exploit-db.com/exploits/3645 - https://www.exploit-db.com/exploits/3646 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1975 (2007/CVE-2007-1975.md) ### [CVE-2007-1975](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1975) ### Description Multiple PHP remote file inclusion vulnerabilities in SLAED CMS 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path parameter to admin/admin.php or the (2) modpath parameter to index.php. ### POC #### Reference - http://securityreason.com/securityalert/2567 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1976 (2007/CVE-2007-1976.md) ### [CVE-2007-1976](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1976) ### Description PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application's checkSuperglobals function defends against the attack ### POC #### Reference - https://www.exploit-db.com/exploits/3642 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1978 (2007/CVE-2007-1978.md) ### [CVE-2007-1978](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1978) ### Description SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action. ### POC #### Reference - https://www.exploit-db.com/exploits/3640 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1979 (2007/CVE-2007-1979.md) ### [CVE-2007-1979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1979) ### Description SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected. ### POC #### Reference - https://www.exploit-db.com/exploits/3655 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1980 (2007/CVE-2007-1980.md) ### [CVE-2007-1980](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1980) ### Description SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3639 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1981 (2007/CVE-2007-1981.md) ### [CVE-2007-1981](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1981) ### Description The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=498782 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1982 (2007/CVE-2007-1982.md) ### [CVE-2007-1982](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1982) ### Description Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3641 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1983 (2007/CVE-2007-1983.md) ### [CVE-2007-1983](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1983) ### Description PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871. ### POC #### Reference - https://www.exploit-db.com/exploits/3660 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1984 (2007/CVE-2007-1984.md) ### [CVE-2007-1984](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1984) ### Description PHP remote file inclusion vulnerability in index.php in lite-cms 0.2.1 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter. ### POC #### Reference - http://securityreason.com/securityalert/2559 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1985 (2007/CVE-2007-1985.md) ### [CVE-2007-1985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1985) ### Description Multiple PHP remote file inclusion vulnerabilities in phpexplorator.php in phpexplorator 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd or (2) lang_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2564 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1986 (2007/CVE-2007-1986.md) ### [CVE-2007-1986](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1986) ### Description Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533. ### POC #### Reference - https://www.exploit-db.com/exploits/3659 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1987 (2007/CVE-2007-1987.md) ### [CVE-2007-1987](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1987) ### Description Multiple PHP remote file inclusion vulnerabilities in PHPEcho CMS 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _plugin_file parameter to smarty/internals/core.load_pulgins.php or the (2) root_path parameter to index.php. NOTE: CVE disputes (1) because the inclusion occurs within a function that is not called during a direct request. CVE disputes (2) because root_path is defined in config.php before use ### POC #### Reference - http://securityreason.com/securityalert/2551 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1988 (2007/CVE-2007-1988.md) ### [CVE-2007-1988](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1988) ### Description Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2550 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1992 (2007/CVE-2007-1992.md) ### [CVE-2007-1992](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1992) ### Description Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/. ### POC #### Reference - https://www.exploit-db.com/exploits/3706 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1994 (2007/CVE-2007-1994.md) ### [CVE-2007-1994](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1994) ### Description Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5624 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1996 (2007/CVE-2007-1996.md) ### [CVE-2007-1996](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1996) ### Description PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter. ### POC #### Reference - http://securityreason.com/securityalert/2562 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1998 (2007/CVE-2007-1998.md) ### [CVE-2007-1998](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1998) ### Description Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 1999 (2007/CVE-2007-1999.md) ### [CVE-2007-1999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1999) ### Description PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1335 - https://www.exploit-db.com/exploits/3700 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2000 (2007/CVE-2007-2000.md) ### [CVE-2007-2000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2000) ### Description Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3701 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 20001 (2007/CVE-2007-20001.md) ### [CVE-2007-20001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-20001) ### Description A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could lead to denial of service. This affects iSCSI SAN (Windows Native) Version 3.2.2 build 2007-02-20. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2007-20001 --- ### 2007/CVE 2007 2001 (2007/CVE-2007-2001.md) ### [CVE-2007-2001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2001) ### Description Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3. ### POC #### Reference - https://www.exploit-db.com/exploits/3701 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2002 (2007/CVE-2007-2002.md) ### [CVE-2007-2002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2002) ### Description InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/3702 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2003 (2007/CVE-2007-2003.md) ### [CVE-2007-2003](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2003) ### Description InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect. ### POC #### Reference - https://www.exploit-db.com/exploits/3702 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2004 (2007/CVE-2007-2004.md) ### [CVE-2007-2004](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2004) ### Description Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/3702 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2005 (2007/CVE-2007-2005.md) ### [CVE-2007-2005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2005) ### Description Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/. ### POC #### Reference - https://www.exploit-db.com/exploits/3703 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2006 (2007/CVE-2007-2006.md) ### [CVE-2007-2006](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2006) ### Description Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3704 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2007 (2007/CVE-2007-2007.md) ### [CVE-2007-2007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2007) ### Description admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1. ### POC #### Reference - https://www.exploit-db.com/exploits/3704 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2008 (2007/CVE-2007-2008.md) ### [CVE-2007-2008](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2008) ### Description Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3704 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2009 (2007/CVE-2007-2009.md) ### [CVE-2007-2009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2009) ### Description PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2010 (2007/CVE-2007-2010.md) ### [CVE-2007-2010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2010) ### Description Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command. ### POC #### Reference - http://bftpd.sourceforge.net/ - http://bftpd.sourceforge.net/downloads/CHANGELOG #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2011 (2007/CVE-2007-2011.md) ### [CVE-2007-2011](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2011) ### Description Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. ### POC #### Reference - http://securityreason.com/securityalert/2556 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2015 (2007/CVE-2007-2015.md) ### [CVE-2007-2015](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2015) ### Description PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2553 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2016 (2007/CVE-2007-2016.md) ### [CVE-2007-2016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2016) ### Description Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2560 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2017 (2007/CVE-2007-2017.md) ### [CVE-2007-2017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2017) ### Description siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request. ### POC #### Reference - http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2018 (2007/CVE-2007-2018.md) ### [CVE-2007-2018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2018) ### Description SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2019 (2007/CVE-2007-2019.md) ### [CVE-2007-2019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2019) ### Description PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter. ### POC #### Reference - http://securityreason.com/securityalert/2566 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2020 (2007/CVE-2007-2020.md) ### [CVE-2007-2020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2020) ### Description Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion ### POC #### Reference - http://securityreason.com/securityalert/2561 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2021 (2007/CVE-2007-2021.md) ### [CVE-2007-2021](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2021) ### Description Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4. ### POC #### Reference - http://securityreason.com/securityalert/2565 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2022 (2007/CVE-2007-2022.md) ### [CVE-2007-2022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2022) ### Description Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9332 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2024 (2007/CVE-2007-2024.md) ### [CVE-2007-2024](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2024) ### Description Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5 extension. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2026 (2007/CVE-2007-2026.md) ### [CVE-2007-2026](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2026) ### Description The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS. ### POC #### Reference - http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&forum_name=amavis-user #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2027 (2007/CVE-2007-2027.md) ### [CVE-2007-2027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2027) ### Description Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9741 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2029 (2007/CVE-2007-2029.md) ### [CVE-2007-2029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2029) ### Description File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 2032 (2007/CVE-2007-2032.md) ### [CVE-2007-2032](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2032) ### Description Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2033 (2007/CVE-2007-2033.md) ### [CVE-2007-2033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2033) ### Description Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by changing the group membership of user accounts, aka Bug ID CSCse78596. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2034 (2007/CVE-2007-2034.md) ### [CVE-2007-2034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2034) ### Description Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the SuperUsers group, and manage the application and its networks, related to the group membership of user accounts, aka Bug ID CSCsg05190. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2035 (2007/CVE-2007-2035.md) ### [CVE-2007-2035](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2035) ### Description Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2036 (2007/CVE-2007-2036.md) ### [CVE-2007-2036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2036) ### Description The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2037 (2007/CVE-2007-2037.md) ### [CVE-2007-2037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2037) ### Description Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2038 (2007/CVE-2007-2038.md) ### [CVE-2007-2038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2038) ### Description The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2039 (2007/CVE-2007-2039.md) ### [CVE-2007-2039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2039) ### Description The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2040 (2007/CVE-2007-2040.md) ### [CVE-2007-2040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2040) ### Description Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2041 (2007/CVE-2007-2041.md) ### [CVE-2007-2041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2041) ### Description Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves the WLAN ACL configuration with an invalid checksum, which prevents WLAN ACLs from being loaded at boot time, and might allow remote attackers to bypass intended access restrictions, aka Bug ID CSCse58195. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2043 (2007/CVE-2007-2043.md) ### [CVE-2007-2043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2043) ### Description Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3714 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2044 (2007/CVE-2007-2044.md) ### [CVE-2007-2044](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2044) ### Description PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3712 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2045 (2007/CVE-2007-2045.md) ### [CVE-2007-2045](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2045) ### Description Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9127 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2048 (2007/CVE-2007-2048.md) ### [CVE-2007-2048](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2048) ### Description Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter. ### POC #### Reference - http://securityreason.com/securityalert/2589 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2049 (2007/CVE-2007-2049.md) ### [CVE-2007-2049](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2049) ### Description Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3713 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2050 (2007/CVE-2007-2050.md) ### [CVE-2007-2050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2050) ### Description Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3718 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2052 (2007/CVE-2007-2052.md) ### [CVE-2007-2052](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2052) ### Description Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2009-0016.html - https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235093 #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 2053 (2007/CVE-2007-2053.md) ### [CVE-2007-2053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2053) ### Description Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path. NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB. ### POC #### Reference - http://securityreason.com/securityalert/2655 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2054 (2007/CVE-2007-2054.md) ### [CVE-2007-2054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2054) ### Description Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp. NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB. ### POC #### Reference - http://securityreason.com/securityalert/2657 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2055 (2007/CVE-2007-2055.md) ### [CVE-2007-2055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2055) ### Description AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain command line parameters in tools/afconvert.cpp and (2) arguments to the get_parameter function in aimage/ident.cpp. NOTE: it is unknown if the get_parameter vector (2) is ever called. ### POC #### Reference - http://securityreason.com/securityalert/2656 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2057 (2007/CVE-2007-2057.md) ### [CVE-2007-2057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2057) ### Description Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets. ### POC #### Reference - http://securityreason.com/securityalert/2584 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2060 (2007/CVE-2007-2060.md) ### [CVE-2007-2060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2060) ### Description Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM. ### POC #### Reference - http://www.kb.cert.org/vuls/id/319464 - http://www.kb.cert.org/vuls/id/MIMG-6ZKP4T #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2061 (2007/CVE-2007-2061.md) ### [CVE-2007-2061](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2061) ### Description Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter. ### POC #### Reference - http://securityreason.com/securityalert/2572 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2062 (2007/CVE-2007-2062.md) ### [CVE-2007-2062](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2062) ### Description Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file. ### POC #### Reference - https://www.exploit-db.com/exploits/3727 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2064 (2007/CVE-2007-2064.md) ### [CVE-2007-2064](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2064) ### Description Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297. ### POC #### Reference - http://securityreason.com/securityalert/2587 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2067 (2007/CVE-2007-2067.md) ### [CVE-2007-2067](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2067) ### Description Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3745 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2068 (2007/CVE-2007-2068.md) ### [CVE-2007-2068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2068) ### Description Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3749 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2069 (2007/CVE-2007-2069.md) ### [CVE-2007-2069](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2069) ### Description Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dsn[phptype] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3747 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2070 (2007/CVE-2007-2070.md) ### [CVE-2007-2070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2070) ### Description Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3748 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2072 (2007/CVE-2007-2072.md) ### [CVE-2007-2072](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2072) ### Description PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue has been disputed by third party researchers for 0.3, stating that the dir variable is properly initialized before use ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001534.html - http://securityreason.com/securityalert/2580 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2073 (2007/CVE-2007-2073.md) ### [CVE-2007-2073](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2073) ### Description PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the gallery parameter in a new session. ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001534.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2075 (2007/CVE-2007-2075.md) ### [CVE-2007-2075](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2075) ### Description ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container. ### POC #### Reference - http://sourceforge.net/tracker/index.php?func=detail&aid=1696780&group_id=101952&atid=630783 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2078 (2007/CVE-2007-2078.md) ### [CVE-2007-2078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2078) ### Description PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use ### POC #### Reference - http://securityreason.com/securityalert/2582 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2079 (2007/CVE-2007-2079.md) ### [CVE-2007-2079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2079) ### Description The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact. NOTE: it could be argued that this is an issue in mssql_connect (CVE-2007-1411.1) in PHP, or an issue in the ADOdb Library, and the proper fix should be in one of these products; if so, then this should not be treated as a vulnerability in XAMPP. ### POC #### Reference - https://www.exploit-db.com/exploits/3738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2080 (2007/CVE-2007-2080.md) ### [CVE-2007-2080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2080) ### Description Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts. ### POC #### Reference - https://www.exploit-db.com/exploits/3738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2081 (2007/CVE-2007-2081.md) ### [CVE-2007-2081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2081) ### Description MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php. ### POC #### Reference - http://securityreason.com/securityalert/2581 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2082 (2007/CVE-2007-2082.md) ### [CVE-2007-2082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2082) ### Description Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers. ### POC #### Reference - http://securityreason.com/securityalert/2581 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2083 (2007/CVE-2007-2083.md) ### [CVE-2007-2083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2083) ### Description vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions. ### POC #### Reference - http://securityreason.com/securityalert/2591 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2084 (2007/CVE-2007-2084.md) ### [CVE-2007-2084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2084) ### Description PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/. NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001523.html - http://securityreason.com/securityalert/2583 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2086 (2007/CVE-2007-2086.md) ### [CVE-2007-2086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2086) ### Description Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/. ### POC #### Reference - https://www.exploit-db.com/exploits/3741 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2088 (2007/CVE-2007-2088.md) ### [CVE-2007-2088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2088) ### Description Multiple PHP remote file inclusion vulnerabilities in Sitebar 3.3.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) writerFile parameter to index.php and the (2) file parameter to Integrator.php. ### POC #### Reference - http://securityreason.com/securityalert/2586 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2089 (2007/CVE-2007-2089.md) ### [CVE-2007-2089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2089) ### Description Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/. ### POC #### Reference - https://www.exploit-db.com/exploits/3736 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2090 (2007/CVE-2007-2090.md) ### [CVE-2007-2090](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2090) ### Description Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. ### POC #### Reference - http://securityreason.com/securityalert/2585 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2091 (2007/CVE-2007-2091.md) ### [CVE-2007-2091](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2091) ### Description PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3750 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2093 (2007/CVE-2007-2093.md) ### [CVE-2007-2093](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2093) ### Description Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter. ### POC #### Reference - http://securityreason.com/securityalert/2590 - https://www.exploit-db.com/exploits/3735 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2094 (2007/CVE-2007-2094.md) ### [CVE-2007-2094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2094) ### Description PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter. ### POC #### Reference - http://www.securityfocus.com/bid/23524 - https://www.exploit-db.com/exploits/3751 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2095 (2007/CVE-2007-2095.md) ### [CVE-2007-2095](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2095) ### Description PHP remote file inclusion vulnerability in chat.php in MySpeach 1.9 allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter, a different vector than CVE-2007-0498. ### POC #### Reference - http://securityreason.com/securityalert/2592 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2096 (2007/CVE-2007-2096.md) ### [CVE-2007-2096](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2096) ### Description PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote attackers to execute arbitrary PHP code via a URL in the phphd_real_path parameter. NOTE: this issue may be present in versions from 2006. ### POC #### Reference - http://securityreason.com/securityalert/2588 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2097 (2007/CVE-2007-2097.md) ### [CVE-2007-2097](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2097) ### Description Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7) articlesections.php, (8) createArticlesPage.php, (9) guestbook.php, (10) helpguide.php, (11) helpguideeditor.php, (12) links.php, (13) upload.php, (14) sitestatistics.php, (15) nav.php, (16) tpl_upload.php, (17) linksections, or (18) pophelp.php in htdocs/site-admin/; different vectors than CVE-2006-5076. NOTE: this issue is disputed by a third party, who states that $includes_path is defined before use ### POC #### Reference - http://securityreason.com/securityalert/2573 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2098 (2007/CVE-2007-2098.md) ### [CVE-2007-2098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2098) ### Description Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters. ### POC #### Reference - http://securityreason.com/securityalert/2574 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2099 (2007/CVE-2007-2099.md) ### [CVE-2007-2099](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2099) ### Description Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2575 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2100 (2007/CVE-2007-2100.md) ### [CVE-2007-2100](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2100) ### Description FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2570 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2102 (2007/CVE-2007-2102.md) ### [CVE-2007-2102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2102) ### Description Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vector than CVE-2006-6087. ### POC #### Reference - http://securityreason.com/securityalert/2571 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2103 (2007/CVE-2007-2103.md) ### [CVE-2007-2103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2103) ### Description Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php. ### POC #### Reference - http://securityreason.com/securityalert/2576 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2104 (2007/CVE-2007-2104.md) ### [CVE-2007-2104](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2104) ### Description Multiple directory traversal vulnerabilities in iXon CMS 0.30 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme_url parameter to (1) index.php, (2) page.php, (3) search.php, (4) single.php, and (5) archives.php. ### POC #### Reference - http://securityreason.com/securityalert/2577 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2105 (2007/CVE-2007-2105.md) ### [CVE-2007-2105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2105) ### Description Directory traversal vulnerability in admin/index.php in Monkey CMS 0.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the admin_skin parameter. ### POC #### Reference - http://securityreason.com/securityalert/2578 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2106 (2007/CVE-2007-2106.md) ### [CVE-2007-2106](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2106) ### Description Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter. ### POC #### Reference - http://securityreason.com/securityalert/2579 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2119 (2007/CVE-2007-2119.md) ### [CVE-2007-2119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2119) ### Description Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2135 (2007/CVE-2007-2135.md) ### [CVE-2007-2135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2135) ### Description The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128. ### POC #### Reference - http://securityreason.com/securityalert/2612 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2136 (2007/CVE-2007-2136.md) ### [CVE-2007-2136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2136) ### Description Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed. ### POC #### Reference - http://securityreason.com/securityalert/2598 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2137 (2007/CVE-2007-2137.md) ### [CVE-2007-2137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2137) ### Description Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port. ### POC #### Reference - http://securityreason.com/securityalert/2597 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2138 (2007/CVE-2007-2138.md) ### [CVE-2007-2138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2138) ### Description Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings." ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0337.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2139 (2007/CVE-2007-2139.md) ### [CVE-2007-2139](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2139) ### Description Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. ### POC #### Reference - http://securityreason.com/securityalert/2628 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2141 (2007/CVE-2007-2141.md) ### [CVE-2007-2141](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2141) ### Description Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter. ### POC #### Reference - http://securityreason.com/securityalert/2593 - https://www.exploit-db.com/exploits/3758 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2142 (2007/CVE-2007-2142.md) ### [CVE-2007-2142](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2142) ### Description Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/. ### POC #### Reference - https://www.exploit-db.com/exploits/3752 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2143 (2007/CVE-2007-2143.md) ### [CVE-2007-2143](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2143) ### Description PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3759 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2144 (2007/CVE-2007-2144.md) ### [CVE-2007-2144](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2144) ### Description PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3753 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2145 (2007/CVE-2007-2145.md) ### [CVE-2007-2145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2145) ### Description The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3754 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2147 (2007/CVE-2007-2147.md) ### [CVE-2007-2147](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2147) ### Description admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests. ### POC #### Reference - http://securityreason.com/securityalert/2595 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2148 (2007/CVE-2007-2148.md) ### [CVE-2007-2148](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2148) ### Description Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers. ### POC #### Reference - http://securityreason.com/securityalert/2595 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2149 (2007/CVE-2007-2149.md) ### [CVE-2007-2149](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2149) ### Description Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain privileges by reading the files, and allows remote attackers to obtain credentials via a direct request for admin/options.php. ### POC #### Reference - http://securityreason.com/securityalert/2595 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2151 (2007/CVE-2007-2151.md) ### [CVE-2007-2151](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2151) ### Description The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (service crash) via a large length value in a malformed authentication packet, which triggers a heap over-read. ### POC #### Reference - https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612751&command=show&forward=nonthreadedKC #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2152 (2007/CVE-2007-2152.md) ### [CVE-2007-2152](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2152) ### Description Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters. ### POC #### Reference - https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&command=show&forward=nonthreadedKC #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2153 (2007/CVE-2007-2153.md) ### [CVE-2007-2153](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2153) ### Description Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter. ### POC #### Reference - http://securityreason.com/securityalert/2594 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2154 (2007/CVE-2007-2154.md) ### [CVE-2007-2154](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2154) ### Description PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3756 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2156 (2007/CVE-2007-2156.md) ### [CVE-2007-2156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2156) ### Description Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/. ### POC #### Reference - https://www.exploit-db.com/exploits/3763 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2157 (2007/CVE-2007-2157.md) ### [CVE-2007-2157](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2157) ### Description Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3764 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2158 (2007/CVE-2007-2158.md) ### [CVE-2007-2158](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2158) ### Description PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3760 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2164 (2007/CVE-2007-2164.md) ### [CVE-2007-2164](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2164) ### Description Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/. ### POC #### Reference - http://securityreason.com/securityalert/2600 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2166 (2007/CVE-2007-2166.md) ### [CVE-2007-2166](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2166) ### Description PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3765 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2167 (2007/CVE-2007-2167.md) ### [CVE-2007-2167](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2167) ### Description Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action. ### POC #### Reference - https://www.exploit-db.com/exploits/3762 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2169 (2007/CVE-2007-2169.md) ### [CVE-2007-2169](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2169) ### Description Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field. NOTE: an earlier report indicated that the add action can be reached through a request to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3761 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2170 (2007/CVE-2007-2170.md) ### [CVE-2007-2170](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2170) ### Description The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128. ### POC #### Reference - http://securityreason.com/securityalert/2611 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2171 (2007/CVE-2007-2171.md) ### [CVE-2007-2171](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2171) ### Description Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request. ### POC #### Reference - http://securityreason.com/securityalert/2610 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2172 (2007/CVE-2007-2172.md) ### [CVE-2007-2172](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2172) ### Description A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2175 (2007/CVE-2007-2175.md) ### [CVE-2007-2175](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2175) ### Description Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007. ### POC #### Reference - http://www.theregister.co.uk/2007/04/20/pwn-2-own_winner/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2179 (2007/CVE-2007-2179.md) ### [CVE-2007-2179](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2179) ### Description Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference. ### POC #### Reference - http://securityreason.com/securityalert/2606 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2180 (2007/CVE-2007-2180.md) ### [CVE-2007-2180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2180) ### Description Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file. ### POC #### Reference - http://securityreason.com/securityalert/2601 - https://www.exploit-db.com/exploits/3768 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2181 (2007/CVE-2007-2181.md) ### [CVE-2007-2181](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2181) ### Description PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748. ### POC #### Reference - https://www.exploit-db.com/exploits/3778 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2182 (2007/CVE-2007-2182.md) ### [CVE-2007-2182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2182) ### Description Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3775 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2183 (2007/CVE-2007-2183.md) ### [CVE-2007-2183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2183) ### Description SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3774 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2184 (2007/CVE-2007-2184.md) ### [CVE-2007-2184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2184) ### Description Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3773 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2185 (2007/CVE-2007-2185.md) ### [CVE-2007-2185](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2185) ### Description Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3771 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2186 (2007/CVE-2007-2186.md) ### [CVE-2007-2186](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2186) ### Description Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. ### POC #### Reference - https://www.exploit-db.com/exploits/3770 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 2187 (2007/CVE-2007-2187.md) ### [CVE-2007-2187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2187) ### Description Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926. ### POC #### Reference - http://www.digit-labs.org/files/exploits/extremail-v9.c - https://www.exploit-db.com/exploits/3769 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2189 (2007/CVE-2007-2189.md) ### [CVE-2007-2189](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2189) ### Description PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3766 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2190 (2007/CVE-2007-2190.md) ### [CVE-2007-2190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2190) ### Description PHP remote file inclusion vulnerability in admin/public/webpages.php in Eba News 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. ### POC #### Reference - http://securityreason.com/securityalert/2607 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2191 (2007/CVE-2007-2191.md) ### [CVE-2007-2191](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2191) ### Description Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php. ### POC #### Reference - http://securityreason.com/securityalert/2627 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2192 (2007/CVE-2007-2192.md) ### [CVE-2007-2192](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2192) ### Description Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file. ### POC #### Reference - https://www.exploit-db.com/exploits/3772 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2193 (2007/CVE-2007-2193.md) ### [CVE-2007-2193](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2193) ### Description Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3776 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2194 (2007/CVE-2007-2194.md) ### [CVE-2007-2194](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2194) ### Description Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3777 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2196 (2007/CVE-2007-2196.md) ### [CVE-2007-2196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2196) ### Description PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a reliable third party because the jambook.php protects against direct request ### POC #### Reference - http://securityreason.com/securityalert/2603 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2199 (2007/CVE-2007-2199.md) ### [CVE-2007-2199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2199) ### Description PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3781 - https://www.exploit-db.com/exploits/3915 - https://www.exploit-db.com/exploits/4111 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2200 (2007/CVE-2007-2200.md) ### [CVE-2007-2200](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2200) ### Description Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3783 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2201 (2007/CVE-2007-2201.md) ### [CVE-2007-2201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2201) ### Description Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php. ### POC #### Reference - http://securityreason.com/securityalert/2653 - https://www.exploit-db.com/exploits/3785 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2202 (2007/CVE-2007-2202.md) ### [CVE-2007-2202](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2202) ### Description PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter. ### POC #### Reference - http://securityreason.com/securityalert/2609 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2204 (2007/CVE-2007-2204.md) ### [CVE-2007-2204](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2204) ### Description Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3786 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2205 (2007/CVE-2007-2205.md) ### [CVE-2007-2205](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2205) ### Description PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643. ### POC #### Reference - http://securityreason.com/securityalert/2630 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2206 (2007/CVE-2007-2206.md) ### [CVE-2007-2206](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2206) ### Description Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" in the ripeformpost parameter. ### POC #### Reference - http://securityreason.com/securityalert/2602 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2207 (2007/CVE-2007-2207.md) ### [CVE-2007-2207](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2207) ### Description SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter. ### POC #### Reference - http://securityreason.com/securityalert/2602 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2208 (2007/CVE-2007-2208.md) ### [CVE-2007-2208](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2208) ### Description Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/. ### POC #### Reference - http://securityreason.com/securityalert/2608 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2209 (2007/CVE-2007-2209.md) ### [CVE-2007-2209](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2209) ### Description Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources. ### POC #### Reference - https://www.exploit-db.com/exploits/3779 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2210 (2007/CVE-2007-2210.md) ### [CVE-2007-2210](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2210) ### Description A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to "improper memory handling," possibly a buffer overflow. ### POC #### Reference - http://securityreason.com/securityalert/2604 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2211 (2007/CVE-2007-2211.md) ### [CVE-2007-2211](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2211) ### Description SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action. ### POC #### Reference - https://www.exploit-db.com/exploits/3780 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2214 (2007/CVE-2007-2214.md) ### [CVE-2007-2214](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2214) ### Description Unrestricted file upload vulnerability in includes/upload_file.php in DmCMS allows remote attackers to upload arbitrary PHP scripts by placing a script's contents in both the File2 and File3 parameters, and sending a ok.php?do=act Referer. ### POC #### Reference - http://securityreason.com/securityalert/2605 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2216 (2007/CVE-2007-2216.md) ### [CVE-2007-2216](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2216) ### Description The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2217 (2007/CVE-2007-2217.md) ### [CVE-2007-2217](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2217) ### Description Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file. ### POC #### Reference - http://www.kb.cert.org/vuls/id/180345 - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-055 - https://www.exploit-db.com/exploits/4584 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2218 (2007/CVE-2007-2218.md) ### [CVE-2007-2218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2218) ### Description Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2219 (2007/CVE-2007-2219.md) ### [CVE-2007-2219](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2219) ### Description Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-035 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2221 (2007/CVE-2007-2221.md) ### [CVE-2007-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2221) ### Description Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the "Arbitrary File Rewrite Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2222 (2007/CVE-2007-2222.md) ### [CVE-2007-2222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2222) ### Description Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2223 (2007/CVE-2007-2223.md) ### [CVE-2007-2223](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2223) ### Description Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2224 (2007/CVE-2007-2224.md) ### [CVE-2007-2224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2224) ### Description Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-043 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2225 (2007/CVE-2007-2225.md) ### [CVE-2007-2225](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2225) ### Description A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034 #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2007/CVE 2007 2227 (2007/CVE-2007-2227.md) ### [CVE-2007-2227](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2227) ### Description The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034 #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2007/CVE 2007 2228 (2007/CVE-2007-2228.md) ### [CVE-2007-2228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2228) ### Description rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak. ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-058 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2229 (2007/CVE-2007-2229.md) ### [CVE-2007-2229](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2229) ### Description Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User Information Store ACLs Information Disclosure Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2230 (2007/CVE-2007-2230.md) ### [CVE-2007-2230](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2230) ### Description SQL injection vulnerability in CA Clever Path Portal allows remote authenticated users to execute limited SQL commands and retrieve arbitrary database contents via (1) the ofinterest parameter in a light search query, (2) description parameter in the advanced search query, and possibly other vectors. ### POC #### Reference - http://www.hacktics.com/AdvCleverPathApr07.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2234 (2007/CVE-2007-2234.md) ### [CVE-2007-2234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2234) ### Description include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php. ### POC #### Reference - http://securityreason.com/securityalert/2613 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2235 (2007/CVE-2007-2235.md) ### [CVE-2007-2235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2235) ### Description Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php. ### POC #### Reference - http://securityreason.com/securityalert/2613 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2236 (2007/CVE-2007-2236.md) ### [CVE-2007-2236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2236) ### Description footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or via the pun_include tag, as demonstrated by use of admin_options.php to execute PHP code from an uploaded avatar file. ### POC #### Reference - http://securityreason.com/securityalert/2613 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2237 (2007/CVE-2007-2237.md) ### [CVE-2007-2237](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2237) ### Description Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error. ### POC #### Reference - https://www.exploit-db.com/exploits/4044 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2240 (2007/CVE-2007-2240.md) ### [CVE-2007-2240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2240) ### Description The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2242 (2007/CVE-2007-2242.md) ### [CVE-2007-2242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2242) ### Description The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers. ### POC #### Reference - http://www.secdev.org/conf/IPv6_RH_security-csw07.pdf - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9574 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2243 (2007/CVE-2007-2243.md) ### [CVE-2007-2243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2243) ### Description OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483. ### POC #### Reference - http://securityreason.com/securityalert/2631 #### Github - https://github.com/krlabs/openssh-vulnerabilities --- ### 2007/CVE 2007 2244 (2007/CVE-2007-2244.md) ### [CVE-2007-2244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2244) ### Description Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file. ### POC #### Reference - https://www.exploit-db.com/exploits/3793 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2247 (2007/CVE-2007-2247.md) ### [CVE-2007-2247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2247) ### Description SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2616 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2248 (2007/CVE-2007-2248.md) ### [CVE-2007-2248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2248) ### Description Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module. ### POC #### Reference - http://securityreason.com/securityalert/2617 - http://www.waraxe.us/advisory-49.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2249 (2007/CVE-2007-2249.md) ### [CVE-2007-2249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2249) ### Description include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array. ### POC #### Reference - http://securityreason.com/securityalert/2617 - http://www.waraxe.us/advisory-49.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2250 (2007/CVE-2007-2250.md) ### [CVE-2007-2250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2250) ### Description admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2617 - http://www.waraxe.us/advisory-49.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2254 (2007/CVE-2007-2254.md) ### [CVE-2007-2254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2254) ### Description PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure. ### POC #### Reference - http://securityreason.com/securityalert/2618 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2255 (2007/CVE-2007-2255.md) ### [CVE-2007-2255](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2255) ### Description Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459. NOTE: vector 3 might be an issue in SPAW. ### POC #### Reference - http://securityreason.com/securityalert/2619 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2256 (2007/CVE-2007-2256.md) ### [CVE-2007-2256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2256) ### Description Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter. ### POC #### Reference - http://securityreason.com/securityalert/2620 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2257 (2007/CVE-2007-2257.md) ### [CVE-2007-2257](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2257) ### Description PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2621 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2258 (2007/CVE-2007-2258.md) ### [CVE-2007-2258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2258) ### Description PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2622 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2259 (2007/CVE-2007-2259.md) ### [CVE-2007-2259](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2259) ### Description SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter. ### POC #### Reference - http://securityreason.com/securityalert/2623 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2260 (2007/CVE-2007-2260.md) ### [CVE-2007-2260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2260) ### Description Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) source.php, (3) log.php, (4) latex.php, (5) indexinfo.php, (6) index.php, (7) importinfo.php, (8) import.php, (9) examplefile.php, (10) clearinfo.php, (11) clear.php, (12) aboutinfo.php, (13) about.php, and other unspecified files. ### POC #### Reference - http://securityreason.com/securityalert/2624 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2261 (2007/CVE-2007-2261.md) ### [CVE-2007-2261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2261) ### Description PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-1721. ### POC #### Reference - http://securityreason.com/securityalert/2625 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2262 (2007/CVE-2007-2262.md) ### [CVE-2007-2262](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2262) ### Description Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as "File117". ### POC #### Reference - http://securityreason.com/securityalert/2626 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2264 (2007/CVE-2007-2264.md) ### [CVE-2007-2264](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2264) ### Description Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9100 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2265 (2007/CVE-2007-2265.md) ### [CVE-2007-2265](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2265) ### Description Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php. ### POC #### Reference - http://securityreason.com/securityalert/2629 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2270 (2007/CVE-2007-2270.md) ### [CVE-2007-2270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2270) ### Description The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request. ### POC #### Reference - https://www.exploit-db.com/exploits/3791 - https://www.exploit-db.com/exploits/3792 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2271 (2007/CVE-2007-2271.md) ### [CVE-2007-2271](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2271) ### Description Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2272 (2007/CVE-2007-2272.md) ### [CVE-2007-2272](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2272) ### Description PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3795 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2273 (2007/CVE-2007-2273.md) ### [CVE-2007-2273](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2273) ### Description PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3796 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2274 (2007/CVE-2007-2274.md) ### [CVE-2007-2274](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2274) ### Description The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the original disclosure refers to this as a memory leak, but it is not certain. ### POC #### Reference - https://www.exploit-db.com/exploits/3784 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2277 (2007/CVE-2007-2277.md) ### [CVE-2007-2277](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2277) ### Description Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. ### POC #### Reference - http://securityreason.com/securityalert/2614 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2278 (2007/CVE-2007-2278.md) ### [CVE-2007-2278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2278) ### Description Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the abs_path_editor parameter to library/editor/editor.php, or (3) the cfgfile_to_load parameter to admin/phpMyAdmin/libraries/common.lib.php. ### POC #### Reference - http://securityreason.com/securityalert/2615 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2281 (2007/CVE-2007-2281.md) ### [CVE-2007-2281](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2281) ### Description Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2283 (2007/CVE-2007-2283.md) ### [CVE-2007-2283](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2283) ### Description Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. ### POC #### Reference - https://www.exploit-db.com/exploits/3798 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2284 (2007/CVE-2007-2284.md) ### [CVE-2007-2284](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2284) ### Description Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. ### POC #### Reference - https://www.exploit-db.com/exploits/3797 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2285 (2007/CVE-2007-2285.md) ### [CVE-2007-2285](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2285) ### Description Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent. ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001545.html - http://attrition.org/pipermail/vim/2007-April/001546.html - https://www.exploit-db.com/exploits/3800 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2290 (2007/CVE-2007-2290.md) ### [CVE-2007-2290](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2290) ### Description Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466. ### POC #### Reference - http://securityreason.com/securityalert/2632 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2291 (2007/CVE-2007-2291.md) ### [CVE-2007-2291](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2291) ### Description CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute. ### POC #### Reference - http://securityreason.com/securityalert/2654 - http://www.wisec.it/vulns.php?id=11 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2292 (2007/CVE-2007-2292.md) ### [CVE-2007-2292](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2292) ### Description CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute. ### POC #### Reference - http://securityreason.com/securityalert/2654 - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 - http://www.wisec.it/vulns.php?id=11 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2293 (2007/CVE-2007-2293.md) ### [CVE-2007-2293](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2293) ### Description Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE. ### POC #### Reference - http://securityreason.com/securityalert/2645 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2294 (2007/CVE-2007-2294.md) ### [CVE-2007-2294](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2294) ### Description The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference. ### POC #### Reference - http://securityreason.com/securityalert/2646 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2295 (2007/CVE-2007-2295.md) ### [CVE-2007-2295](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2295) ### Description Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file. ### POC #### Reference - http://security-protocols.com/sp-x45-advisory.php - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2296 (2007/CVE-2007-2296.md) ### [CVE-2007-2296](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2296) ### Description Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file. ### POC #### Reference - http://security-protocols.com/sp-x46-advisory.php - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2297 (2007/CVE-2007-2297.md) ### [CVE-2007-2297](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2297) ### Description The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash). ### POC #### Reference - http://securityreason.com/securityalert/2644 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2298 (2007/CVE-2007-2298.md) ### [CVE-2007-2298](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2298) ### Description Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/. ### POC #### Reference - https://www.exploit-db.com/exploits/3732 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2299 (2007/CVE-2007-2299.md) ### [CVE-2007-2299](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2299) ### Description Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536. ### POC #### Reference - https://www.exploit-db.com/exploits/3731 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2300 (2007/CVE-2007-2300.md) ### [CVE-2007-2300](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2300) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php. ### POC #### Reference - http://securityreason.com/securityalert/2643 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2301 (2007/CVE-2007-2301.md) ### [CVE-2007-2301](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2301) ### Description Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/. ### POC #### Reference - https://www.exploit-db.com/exploits/3744 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2302 (2007/CVE-2007-2302.md) ### [CVE-2007-2302](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2302) ### Description PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3722 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2303 (2007/CVE-2007-2303.md) ### [CVE-2007-2303](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2303) ### Description Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1395 - https://www.exploit-db.com/exploits/3742 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2304 (2007/CVE-2007-2304.md) ### [CVE-2007-2304](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2304) ### Description Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files. ### POC #### Reference - https://www.exploit-db.com/exploits/3729 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2305 (2007/CVE-2007-2305.md) ### [CVE-2007-2305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2305) ### Description Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/3729 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2306 (2007/CVE-2007-2306.md) ### [CVE-2007-2306](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2306) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php. ### POC #### Reference - http://securityreason.com/securityalert/2642 - http://www.waraxe.us/advisory-48.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2307 (2007/CVE-2007-2307.md) ### [CVE-2007-2307](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2307) ### Description PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3717 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2308 (2007/CVE-2007-2308.md) ### [CVE-2007-2308](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2308) ### Description Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter. ### POC #### Reference - http://securityreason.com/securityalert/2639 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2310 (2007/CVE-2007-2310.md) ### [CVE-2007-2310](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2310) ### Description Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. ### POC #### Reference - http://securityreason.com/securityalert/2640 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2311 (2007/CVE-2007-2311.md) ### [CVE-2007-2311](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2311) ### Description PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use ### POC #### Reference - http://securityreason.com/securityalert/2641 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2312 (2007/CVE-2007-2312.md) ### [CVE-2007-2312](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2312) ### Description Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/. NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement. ### POC #### Reference - http://securityreason.com/securityalert/2642 - http://www.waraxe.us/advisory-48.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2313 (2007/CVE-2007-2313.md) ### [CVE-2007-2313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2313) ### Description PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3716 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2315 (2007/CVE-2007-2315.md) ### [CVE-2007-2315](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2315) ### Description MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections. ### POC #### Reference - http://sourceforge.net/forum/forum.php?forum_id=685448 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2317 (2007/CVE-2007-2317.md) ### [CVE-2007-2317](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2317) ### Description Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690. ### POC #### Reference - https://www.exploit-db.com/exploits/3707 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2319 (2007/CVE-2007-2319.md) ### [CVE-2007-2319](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2319) ### Description PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/3734 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2320 (2007/CVE-2007-2320.md) ### [CVE-2007-2320](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2320) ### Description SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478. ### POC #### Reference - https://www.exploit-db.com/exploits/3739 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2324 (2007/CVE-2007-2324.md) ### [CVE-2007-2324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2324) ### Description Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3799 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2326 (2007/CVE-2007-2326.md) ### [CVE-2007-2326](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2326) ### Description Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty. ### POC #### Reference - http://securityreason.com/securityalert/2634 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2327 (2007/CVE-2007-2327.md) ### [CVE-2007-2327](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2327) ### Description PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2635 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2328 (2007/CVE-2007-2328.md) ### [CVE-2007-2328](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2328) ### Description PHP remote file inclusion vulnerability in addvip.php in phpMYTGP 1.4b allows remote attackers to execute arbitrary PHP code via a URL in the msetstr[PROGSDIR] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2636 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2329 (2007/CVE-2007-2329.md) ### [CVE-2007-2329](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2329) ### Description PHP remote file inclusion vulnerability in searchbot.php in Searchactivity allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2637 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2330 (2007/CVE-2007-2330.md) ### [CVE-2007-2330](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2330) ### Description PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2638 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2331 (2007/CVE-2007-2331.md) ### [CVE-2007-2331](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2331) ### Description PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang_list parameter. ### POC #### Reference - http://securityreason.com/securityalert/2633 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2338 (2007/CVE-2007-2338.md) ### [CVE-2007-2338](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2338) ### Description Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter. ### POC #### Reference - http://securityreason.com/securityalert/2617 - http://www.waraxe.us/advisory-49.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2339 (2007/CVE-2007-2339.md) ### [CVE-2007-2339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2339) ### Description Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php. ### POC #### Reference - http://securityreason.com/securityalert/2617 - http://www.waraxe.us/advisory-49.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2340 (2007/CVE-2007-2340.md) ### [CVE-2007-2340](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2340) ### Description Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/3803 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2341 (2007/CVE-2007-2341.md) ### [CVE-2007-2341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2341) ### Description PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3802 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2342 (2007/CVE-2007-2342.md) ### [CVE-2007-2342](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2342) ### Description SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083. ### POC #### Reference - https://www.exploit-db.com/exploits/3767 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2345 (2007/CVE-2007-2345.md) ### [CVE-2007-2345](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2345) ### Description PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3668 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2346 (2007/CVE-2007-2346.md) ### [CVE-2007-2346](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2346) ### Description Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3669 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2347 (2007/CVE-2007-2347.md) ### [CVE-2007-2347](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2347) ### Description PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3667 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2350 (2007/CVE-2007-2350.md) ### [CVE-2007-2350](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2350) ### Description admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter. ### POC #### Reference - http://securityreason.com/securityalert/2652 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2352 (2007/CVE-2007-2352.md) ### [CVE-2007-2352](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2352) ### Description Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp. NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed. ### POC #### Reference - http://securityreason.com/securityalert/2657 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2353 (2007/CVE-2007-2353.md) ### [CVE-2007-2353](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2353) ### Description Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message. ### POC #### Reference No PoCs from references. #### Github - https://github.com/hinat0y/Dataset1 - https://github.com/hinat0y/Dataset10 - https://github.com/hinat0y/Dataset11 - https://github.com/hinat0y/Dataset12 - https://github.com/hinat0y/Dataset2 - https://github.com/hinat0y/Dataset3 - https://github.com/hinat0y/Dataset4 - https://github.com/hinat0y/Dataset5 - https://github.com/hinat0y/Dataset6 - https://github.com/hinat0y/Dataset7 - https://github.com/hinat0y/Dataset8 - https://github.com/hinat0y/Dataset9 --- ### 2007/CVE 2007 2356 (2007/CVE-2007-2356.md) ### [CVE-2007-2356](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2356) ### Description Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file. ### POC #### Reference - https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=238422 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2357 (2007/CVE-2007-2357.md) ### [CVE-2007-2357](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2357) ### Description Cross-site scripting (XSS) vulnerability in mods/Core/result.php in SineCms 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the stringa parameter. ### POC #### Reference - http://securityreason.com/securityalert/2649 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2358 (2007/CVE-2007-2358.md) ### [CVE-2007-2358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2358) ### Description Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php. NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001566.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2362 (2007/CVE-2007-2362.md) ### [CVE-2007-2362](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2362) ### Description Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c. ### POC #### Reference - http://securityreason.com/securityalert/2658 - http://www.digit-labs.org/files/exploits/mydns-rr-smash.c #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2363 (2007/CVE-2007-2363.md) ### [CVE-2007-2363](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2363) ### Description Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. ### POC #### Reference - https://www.exploit-db.com/exploits/3811 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2364 (2007/CVE-2007-2364.md) ### [CVE-2007-2364](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2364) ### Description Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/. ### POC #### Reference - https://www.exploit-db.com/exploits/3809 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2365 (2007/CVE-2007-2365.md) ### [CVE-2007-2365](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2365) ### Description Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. ### POC #### Reference - https://www.exploit-db.com/exploits/3812 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2366 (2007/CVE-2007-2366.md) ### [CVE-2007-2366](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2366) ### Description Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. ### POC #### Reference - https://www.exploit-db.com/exploits/3812 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2367 (2007/CVE-2007-2367.md) ### [CVE-2007-2367](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2367) ### Description Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI. ### POC #### Reference - http://securityreason.com/securityalert/2647 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2368 (2007/CVE-2007-2368.md) ### [CVE-2007-2368](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2368) ### Description picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3673 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2369 (2007/CVE-2007-2369.md) ### [CVE-2007-2369](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2369) ### Description Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3673 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2370 (2007/CVE-2007-2370.md) ### [CVE-2007-2370](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2370) ### Description SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings. ### POC #### Reference - https://www.exploit-db.com/exploits/3672 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2371 (2007/CVE-2007-2371.md) ### [CVE-2007-2371](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2371) ### Description admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action. ### POC #### Reference - https://www.exploit-db.com/exploits/3671 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2372 (2007/CVE-2007-2372.md) ### [CVE-2007-2372](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2372) ### Description admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/. ### POC #### Reference - https://www.exploit-db.com/exploits/3671 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2373 (2007/CVE-2007-2373.md) ### [CVE-2007-2373](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2373) ### Description SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - http://packetstormsecurity.org/0704-exploits/xoopswflinks-sql.txt - https://www.exploit-db.com/exploits/3670 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2383 (2007/CVE-2007-2383.md) ### [CVE-2007-2383](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2383) ### Description The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." ### POC #### Reference No PoCs from references. #### Github - https://github.com/sho-h/pkgvulscheck --- ### 2007/CVE 2007 2392 (2007/CVE-2007-2392.md) ### [CVE-2007-2392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2392) ### Description Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2393 (2007/CVE-2007-2393.md) ### [CVE-2007-2393](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2393) ### Description The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2394 (2007/CVE-2007-2394.md) ### [CVE-2007-2394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2394) ### Description Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2396 (2007/CVE-2007-2396.md) ### [CVE-2007-2396](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2396) ### Description The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2397 (2007/CVE-2007-2397.md) ### [CVE-2007-2397](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2397) ### Description QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2402 (2007/CVE-2007-2402.md) ### [CVE-2007-2402](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2402) ### Description QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2405 (2007/CVE-2007-2405.md) ### [CVE-2007-2405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2405) ### Description Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 2407 (2007/CVE-2007-2407.md) ### [CVE-2007-2407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2407) ### Description The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota. ### POC #### Reference No PoCs from references. #### Github - https://github.com/AhenKay/INPT_report - https://github.com/Farrhouq/Inpt-report --- ### 2007/CVE 2007 2408 (2007/CVE-2007-2408.md) ### [CVE-2007-2408](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2408) ### Description WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=3214 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2411 (2007/CVE-2007-2411.md) ### [CVE-2007-2411](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2411) ### Description PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. NOTE: a third party disputes this vulnerability, stating that "the application is not vulnerable to this issue. ### POC #### Reference - http://securityreason.com/securityalert/2648 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2412 (2007/CVE-2007-2412.md) ### [CVE-2007-2412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2412) ### Description Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter. NOTE: a third party has disputed this issue because the a array is populated by a database query before use ### POC #### Reference - http://securityreason.com/securityalert/2651 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2416 (2007/CVE-2007-2416.md) ### [CVE-2007-2416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2416) ### Description SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter. ### POC #### Reference - http://securityreason.com/securityalert/2650 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2422 (2007/CVE-2007-2422.md) ### [CVE-2007-2422](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2422) ### Description Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string ### POC #### Reference - http://securityreason.com/securityalert/2659 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2424 (2007/CVE-2007-2424.md) ### [CVE-2007-2424](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2424) ### Description PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3818 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2425 (2007/CVE-2007-2425.md) ### [CVE-2007-2425](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2425) ### Description Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3817 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2426 (2007/CVE-2007-2426.md) ### [CVE-2007-2426](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2426) ### Description PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3814 #### Github - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/awesome-cve-repo - https://github.com/goudunz1/CVE-2007-2426 - https://github.com/warriordog/little-log-scan --- ### 2007/CVE 2007 2427 (2007/CVE-2007-2427.md) ### [CVE-2007-2427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2427) ### Description SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3813 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2430 (2007/CVE-2007-2430.md) ### [CVE-2007-2430](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2430) ### Description shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3816 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2431 (2007/CVE-2007-2431.md) ### [CVE-2007-2431](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2431) ### Description Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3816 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2438 (2007/CVE-2007-2438.md) ### [CVE-2007-2438](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2438) ### Description The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9876 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/finagin/encyclopedia - https://github.com/luckyyyyy/editor-config - https://github.com/obiscr/vim - https://github.com/xiky/MyVimrc --- ### 2007/CVE 2007 2442 (2007/CVE-2007-2442.md) ### [CVE-2007-2442](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2442) ### Description The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup. ### POC #### Reference - http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2007-004.txt - http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt - http://www.kb.cert.org/vuls/id/356961 #### Github - https://github.com/Minakshi1030/Network-Penetration-Testing- --- ### 2007/CVE 2007 2443 (2007/CVE-2007-2443.md) ### [CVE-2007-2443](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2443) ### Description Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value. ### POC #### Reference - http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2007-004.txt - http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-004.txt - http://www.kb.cert.org/vuls/id/365313 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11277 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2444 (2007/CVE-2007-2444.md) ### [CVE-2007-2444](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444) ### Description Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user. ### POC #### Reference - http://securityreason.com/securityalert/2701 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-2007-2444 --- ### 2007/CVE 2007 2445 (2007/CVE-2007-2445.md) ### [CVE-2007-2445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2445) ### Description The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to cause a denial of service (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=508656&group_id=5624 - http://www.coresecurity.com/?action=item&id=2148 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2446 (2007/CVE-2007-2446.md) ### [CVE-2007-2446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446) ### Description Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names). ### POC #### Reference - http://securityreason.com/securityalert/2702 #### Github - https://github.com/DOCTOR-ANR/cybercaptor-server - https://github.com/Larryxi/My_tools - https://github.com/fiware-cybercaptor/cybercaptor-server - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 2447 (2007/CVE-2007-2447.md) ### [CVE-2007-2447](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447) ### Description The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management. ### POC #### Reference - http://securityreason.com/securityalert/2700 - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github - https://github.com/0xConstant/CVE-2007-2447 - https://github.com/0xConstant/ExploitDevJourney - https://github.com/0xKn/CVE-2007-2447 - https://github.com/0xTabun/CVE-2007-2447 - https://github.com/0xkasra/CVE-2007-2447 - https://github.com/0xkasra/ExploitDevJourney - https://github.com/0xwh1pl4sh/CVE-2007-2447 - https://github.com/3t4n/samba-3.0.24-CVE-2007-2447-vunerable- - https://github.com/3x1t1um/CVE-2007-2447 - https://github.com/4n0nym0u5dk/usermap_script_CVE-2007-2447 - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/Alien0ne/CVE-2007-2447 - https://github.com/Aman0003sarkar/Network-Penetration-Testing-with-Real-World-Exploits-and-Security-Remediation - https://github.com/Anekant-Singhai/Exploits - https://github.com/AveryVaughn/forCVE - https://github.com/Aviksaikat/CVE-2007-2447 - https://github.com/Avinash-05-web/CHE-project-4th-sem - https://github.com/BrunoCRovira/LameHTB - https://github.com/C4ort26/CyberSecurity-portfolio- - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/CYB3RLEO/Penenetration_Testing_Lab_Exploitation_Phase3-Metasploitable3-samba_user_map- - https://github.com/CYB3RLEO/Penetration_Test_Report_Metasploitable2 - https://github.com/CipherLucas/Metasploitable2-PenTest-Report - https://github.com/Desm0ndChan/OSCP-cheatsheet - https://github.com/DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2 - https://github.com/Divakar12p/divakar-manda - https://github.com/DmitriyPetrovskiy23/InfoSec-homework1 - https://github.com/Furious992/HW13-01 - https://github.com/G01d3nW01f/CVE-2007-2447 - https://github.com/GaloisInc/msf-haskell - https://github.com/H3xL00m/CVE-2007-2447 - https://github.com/HariprasadG92/Metasploitable2-Penetration-Test - https://github.com/HerculesRD/PyUsernameMapScriptRCE - https://github.com/IamLucif3r/CVE-2007-2447-Exploit - https://github.com/JoseBarrios/CVE-2007-2447 - https://github.com/Juantos/cve-2007-2447 - https://github.com/Ki11i0n4ir3/CVE-2007-2447 - https://github.com/Ki11i0n4ir3/Sambaster - https://github.com/Kr1tz3x3/HTB-Writeups - https://github.com/Lab2RKSB/PraktikHack - https://github.com/LyticOnaope/Penetration-Testing- - https://github.com/Madhan150320/metasploit-practice-lab - https://github.com/MalwareMusashi/flour-mill - https://github.com/MikeRega7/CVE-2007-2447-RCE - https://github.com/MohamedSayed47/DEPI_Final_project - https://github.com/MrRoma577/exploit_cve-2007-2447_again - https://github.com/N3rdyN3xus/CVE-2007-2447 - https://github.com/Neoju5t/expo-att - https://github.com/Nkemjika-123/Cybersecurity-Governance-Framework - https://github.com/Nosferatuvjr/Samba-Usermap-exploit - https://github.com/NyxByt3/CVE-2007-2447 - https://github.com/Patrick122333/4240project - https://github.com/Pritt014/metasploitable2-pentest - https://github.com/PuddinCat/GithubRepoSpider - https://github.com/Raja-jpeg/Ethical-Hacking-Lab - https://github.com/RedTeamShanks/Local-Network-Vulnerability-Assessment - https://github.com/Rohan1630/Internal_Pentest_Lab - https://github.com/SERMSN/vulnerabilities-attacks - https://github.com/SMSravya/LocalPortScanner - https://github.com/SamHackingArticles/CVE-2007-2447 - https://github.com/SanjuCyb3r/Metasploitable-2 - https://github.com/SeifEldienAhmad/Penetration-Testing-on-Metasploitable2 - https://github.com/ShivamDey/Samba-CVE-2007-2447-Exploit - https://github.com/Sp3c73rSh4d0w/CVE-2007-2447 - https://github.com/Takarigua/sys-pattern-homework13-01 - https://github.com/Tamie13/Penetration-Testing-Week-16 - https://github.com/TopekoX/belajar-ethical-hacking - https://github.com/Unix13/metasploitable2 - https://github.com/WildfootW/CVE-2007-2447_Samba_3.0.25rc3 - https://github.com/Y2FuZXBh/exploits - https://github.com/Ziemni/CVE-2007-2447-in-Python - https://github.com/aadithya-vimal/Metasploitable2-Pentest - https://github.com/aaroong/metasploitable2-writeup-aaroong - https://github.com/amriunix/CVE-2007-2447 - https://github.com/ankit-kumar-developer-122/Test - https://github.com/anneelv/htb-lame - https://github.com/aparnaa19/CVE-Exploits-on-Metasploitable2 - https://github.com/awakehns/defence-and-attack_13-01 - https://github.com/b1fair/smb_usermap - https://github.com/b33m0x00/CVE-2007-2447 - https://github.com/b3m0x00/CVE-2007-2447 - https://github.com/banomaly/CVE-2007-2447 - https://github.com/banomaly/ExploitDevJourney - https://github.com/basimnawaz6/Metasploitable2 - https://github.com/bdunlap9/CVE-2007-2447_python - https://github.com/beyioku/vulnerability-assessment-lab - https://github.com/boltunovag/sec-1 - https://github.com/bongguy09/Simulating-Real-World-Network-Exploitation-and-Defenses - https://github.com/bsbsmaster/OSCP-Cheat-Sheet - https://github.com/c0d3cr4f73r/CVE-2007-2447 - https://github.com/cherrera0001/CVE-2007-2447 - https://github.com/codeN0mad/Vulnerability-assessment-uneeq-internship- - https://github.com/crypticdante/CVE-2007-2447 - https://github.com/doval2222/doval2222 - https://github.com/doval2222/scripts-ciberseguridad - https://github.com/elphon/CVE-2007-2447-Exploit - https://github.com/foudadev/CVE-2007-2447 - https://github.com/gwyomarch/Lame-HTB-Writeup-FR - https://github.com/h3x0v3rl0rd/CVE-2007-2447 - https://github.com/h3xcr4ck3r/CVE-2007-2447 - https://github.com/hussien-almalki/Hack_lame - https://github.com/jaydenxjayden/HTB-writeup - https://github.com/jwardsmith/Penetration-Testing - https://github.com/k4u5h41/CVE-2007-2447 - https://github.com/macosta-42/Exploit-Development - https://github.com/manasmikku-ux/Vulnerability-Assessment-Project - https://github.com/marcocastro100/Intrusion_Detection_System-Python - https://github.com/mariannorasg/metasploitable2-pentesting-lab - https://github.com/mjay2992/Vulnerability-Exploitation-Project - https://github.com/mmezirard/cve-2007-2447 - https://github.com/mr-l0n3lly/CVE-2007-2447 - https://github.com/mylovemyon/memo - https://github.com/n0-traces/cve_monitor - https://github.com/n3masyst/n3masyst - https://github.com/n3ov4n1sh/CVE-2007-2447 - https://github.com/n3rdh4x0r/CVE-2007-2447 - https://github.com/nickvourd/smb-usermap-destroyer - https://github.com/nika0x38/CVE-2007-2447 - https://github.com/noahmtubbs/Cybersecurity-HomeLab - https://github.com/oscar-rk/CTF-Writeups - https://github.com/oscar-rk/exploits - https://github.com/ozuma/CVE-2007-2447 - https://github.com/pedr0alencar/vlab-metasploitable2 - https://github.com/pulkit-mital/samba-usermap-script - https://github.com/pwnd-root/exploits-and-stuff - https://github.com/raes3401/-HackTheBox-and-CTF-notes - https://github.com/rahulkore1/-basic-vulnerability-assessment - https://github.com/riveraJ45/netology - https://github.com/s4msec/CVE-2007-2447 - https://github.com/saralagrace/pentest - https://github.com/seerat-fatima21/Self-directed-Labs - https://github.com/seerat-fatima21/samba-exploitation - https://github.com/shadow-here/Ethical-Hacking-Project - https://github.com/skeeperloyaltie/network - https://github.com/tarikemal/exploit-ftp-samba - https://github.com/testaross4/CVE-2007-2447 - https://github.com/tourvan/penetration-testing-report - https://github.com/un4gi/CVE-2007-2447 - https://github.com/vasev85/exploit - https://github.com/vonoid/attacks-on-IS - https://github.com/voukatas/PenTest_Metasploitable2 - https://github.com/xbufu/CVE-2007-2447 - https://github.com/xlcc4096/exploit-CVE-2007-2447 - https://github.com/ygbull/Capstone - https://github.com/yukitsukai47/PenetrationTesting_cheatsheet - https://github.com/zhanpengliu-tencent/medium-cve --- ### 2007/CVE 2007 2448 (2007/CVE-2007-2448.md) ### [CVE-2007-2448](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2448) ### Description Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit. ### POC #### Reference - http://www.ubuntu.com/usn/USN-1053-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2449 (2007/CVE-2007-2449.md) ### [CVE-2007-2449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2449) ### Description Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates --- ### 2007/CVE 2007 2450 (2007/CVE-2007-2450.md) ### [CVE-2007-2450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2450) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx - http://securityreason.com/securityalert/2813 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2452 (2007/CVE-2007-2452.md) ### [CVE-2007-2452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2452) ### Description Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036. ### POC #### Reference - http://securityreason.com/securityalert/2760 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2453 (2007/CVE-2007-2453.md) ### [CVE-2007-2453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2453) ### Description The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9960 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2456 (2007/CVE-2007-2456.md) ### [CVE-2007-2456](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2456) ### Description Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/. ### POC #### Reference - https://www.exploit-db.com/exploits/3805 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2457 (2007/CVE-2007-2457.md) ### [CVE-2007-2457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2457) ### Description PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3733 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2458 (2007/CVE-2007-2458.md) ### [CVE-2007-2458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2458) ### Description Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457. ### POC #### Reference - https://www.exploit-db.com/exploits/3733 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2471 (2007/CVE-2007-2471.md) ### [CVE-2007-2471](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2471) ### Description Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3827 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2481 (2007/CVE-2007-2481.md) ### [CVE-2007-2481](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2481) ### Description PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. ### POC #### Reference - http://securityreason.com/securityalert/2660 - https://www.exploit-db.com/exploits/3825 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2482 (2007/CVE-2007-2482.md) ### [CVE-2007-2482](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2482) ### Description Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter. ### POC #### Reference - http://securityreason.com/securityalert/2660 - http://www.exploit-db.com/exploits/3825 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2483 (2007/CVE-2007-2483.md) ### [CVE-2007-2483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2483) ### Description Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3824 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2484 (2007/CVE-2007-2484.md) ### [CVE-2007-2484](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2484) ### Description PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3824 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2485 (2007/CVE-2007-2485.md) ### [CVE-2007-2485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2485) ### Description PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3828 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2486 (2007/CVE-2007-2486.md) ### [CVE-2007-2486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2486) ### Description Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3831 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2487 (2007/CVE-2007-2487.md) ### [CVE-2007-2487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2487) ### Description Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287. ### POC #### Reference - http://securityreason.com/securityalert/2675 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2492 (2007/CVE-2007-2492.md) ### [CVE-2007-2492](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2492) ### Description SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action. ### POC #### Reference - http://securityreason.com/securityalert/2674 - https://www.exploit-db.com/exploits/3835 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2493 (2007/CVE-2007-2493.md) ### [CVE-2007-2493](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2493) ### Description PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3833 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2494 (2007/CVE-2007-2494.md) ### [CVE-2007-2494](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2494) ### Description Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3826 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2495 (2007/CVE-2007-2495.md) ### [CVE-2007-2495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2495) ### Description Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3830 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2496 (2007/CVE-2007-2496.md) ### [CVE-2007-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2496) ### Description The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2497 (2007/CVE-2007-2497.md) ### [CVE-2007-2497](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2497) ### Description RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue was referred to as a "memory leak," but it is not clear if this is correct. ### POC #### Reference - https://www.exploit-db.com/exploits/3819 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2498 (2007/CVE-2007-2498.md) ### [CVE-2007-2498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2498) ### Description libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3823 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2503 (2007/CVE-2007-2503.md) ### [CVE-2007-2503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2503) ### Description Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion ### POC #### Reference - http://securityreason.com/securityalert/2673 - http://www.attrition.org/pipermail/vim/2007-April/001541.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2504 (2007/CVE-2007-2504.md) ### [CVE-2007-2504](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2504) ### Description PHP remote file inclusion vulnerability in user/turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion ### POC #### Reference - http://securityreason.com/securityalert/2673 - http://www.attrition.org/pipermail/vim/2007-April/001541.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2506 (2007/CVE-2007-2506.md) ### [CVE-2007-2506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2506) ### Description WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO. ### POC #### Reference - http://progress.atgnow.com/esprogress/resultDisplay.do?gotoLink=115&docType=1006&clusterName=CombinedCluster&contentId=12&groupId=3&answerGroup=1&score=1932&page=http%3A%2F%2Fprogress.atgnow.com%2Fesprogress%2Fdocs%2FSolutions%2FProgress%2FESERVER_P123694.xhtml&result=0&excerpt=P123694 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2507 (2007/CVE-2007-2507.md) ### [CVE-2007-2507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2507) ### Description Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3832 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2509 (2007/CVE-2007-2509.md) ### [CVE-2007-2509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2509) ### Description CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands. ### POC #### Reference - http://securityreason.com/securityalert/2672 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2514 (2007/CVE-2007-2514.md) ### [CVE-2007-2514](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2514) ### Description Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173. ### POC #### Reference - http://securityreason.com/securityalert/2785 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2519 (2007/CVE-2007-2519.md) ### [CVE-2007-2519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2519) ### Description Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions. ### POC #### Reference - http://pear.php.net/advisory-20070507.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2521 (2007/CVE-2007-2521.md) ### [CVE-2007-2521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2521) ### Description PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3846 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2524 (2007/CVE-2007-2524.md) ### [CVE-2007-2524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2524) ### Description Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841. ### POC #### Reference - http://securityreason.com/securityalert/2668 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2527 (2007/CVE-2007-2527.md) ### [CVE-2007-2527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2527) ### Description Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitrary PHP code via a URL in the HomeDir parameter to (1) dp_logs.php or (2) index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3868 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2530 (2007/CVE-2007-2530.md) ### [CVE-2007-2530](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2530) ### Description Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute arbitrary PHP code via a URL in the RESPATH parameter to (1) dosearch.php or (2) printfriendly.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3865 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2531 (2007/CVE-2007-2531.md) ### [CVE-2007-2531](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2531) ### Description PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execute arbitrary PHP code via a URL in the beryliumroot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3869 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2532 (2007/CVE-2007-2532.md) ### [CVE-2007-2532](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2532) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734. ### POC #### Reference - http://securityreason.com/securityalert/2666 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2534 (2007/CVE-2007-2534.md) ### [CVE-2007-2534](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2534) ### Description Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a login. NOTE: CVE disputes this vulnerability, since ADMIN_USER/ADMIN_PASS are initialized before use ### POC #### Reference - http://securityreason.com/securityalert/2669 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2535 (2007/CVE-2007-2535.md) ### [CVE-2007-2535](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2535) ### Description WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2536 (2007/CVE-2007-2536.md) ### [CVE-2007-2536](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2536) ### Description PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. ### POC #### Reference - http://securityreason.com/securityalert/2680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2537 (2007/CVE-2007-2537.md) ### [CVE-2007-2537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2537) ### Description Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the X-Forwarded-For (X_FORWARDED_FOR) HTTP header. ### POC #### Reference - http://securityreason.com/securityalert/2670 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2538 (2007/CVE-2007-2538.md) ### [CVE-2007-2538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2538) ### Description SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter. ### POC #### Reference - http://securityreason.com/securityalert/2671 - https://www.exploit-db.com/exploits/3850 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2539 (2007/CVE-2007-2539.md) ### [CVE-2007-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2539) ### Description The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2671 - https://www.exploit-db.com/exploits/3850 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2540 (2007/CVE-2007-2540.md) ### [CVE-2007-2540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2540) ### Description Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[pathMod] parameter to index.php in (1) mod/image/, (2) mod/liens/, (3) mod/liste/, (4) mod/special/, or (5) mod/texte/. ### POC #### Reference - https://www.exploit-db.com/exploits/3852 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2541 (2007/CVE-2007-2541.md) ### [CVE-2007-2541](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2541) ### Description PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to execute arbitrary PHP code via a URL in the urlModulo parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3847 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2542 (2007/CVE-2007-2542.md) ### [CVE-2007-2542](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2542) ### Description PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3848 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2543 (2007/CVE-2007-2543.md) ### [CVE-2007-2543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2543) ### Description SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3849 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2544 (2007/CVE-2007-2544.md) ### [CVE-2007-2544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2544) ### Description PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the right_file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3854 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2545 (2007/CVE-2007-2545.md) ### [CVE-2007-2545](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2545) ### Description Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the system[path] parameter to (1) blocks/headerfile.php, (2) files/blocks/latest_files.php, (3) filters/headerfile.php, (4) forums/blocks/latest_posts.php, (5) groups/headerfile.php, (6) links/blocks/links.php, (7) menu/headerfile.php, (8) news/blocks/latest_news.php, (9) settings/headerfile.php, or (10) users/headerfile.php, in modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/3853 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2546 (2007/CVE-2007-2546.md) ### [CVE-2007-2546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2546) ### Description Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. ### POC #### Reference - http://securityreason.com/securityalert/2676 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2547 (2007/CVE-2007-2547.md) ### [CVE-2007-2547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2547) ### Description Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. ### POC #### Reference - http://securityreason.com/securityalert/2677 - http://www.securityfocus.com/bid/23856 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2548 (2007/CVE-2007-2548.md) ### [CVE-2007-2548](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2548) ### Description Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation." ### POC #### Reference - http://securityreason.com/securityalert/2677 - http://www.securityfocus.com/bid/23856 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2549 (2007/CVE-2007-2549.md) ### [CVE-2007-2549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2549) ### Description SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. ### POC #### Reference - http://securityreason.com/securityalert/2677 - http://www.securityfocus.com/bid/23856 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2550 (2007/CVE-2007-2550.md) ### [CVE-2007-2550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2550) ### Description Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie name beginning with "ccSID" to (1) cart.php or (2) index.php. ### POC #### Reference - http://securityreason.com/securityalert/2678 - http://www.cubecart.com/site/forums/index.php?s=0cbaa8a2f26fc573d1fc888285f610b1&showtopic=27418 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2554 (2007/CVE-2007-2554.md) ### [CVE-2007-2554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2554) ### Description Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript. ### POC #### Reference - http://securityreason.com/securityalert/2679 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2555 (2007/CVE-2007-2555.md) ### [CVE-2007-2555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2555) ### Description Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly session fixation, via a META HTTP-EQUIV Set-cookie expression in the id parameter, related to "cookie manipulation." NOTE: this issue might be cross-site scripting (XSS). ### POC #### Reference - http://securityreason.com/securityalert/2664 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2556 (2007/CVE-2007-2556.md) ### [CVE-2007-2556](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2556) ### Description SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI. ### POC #### Reference - http://securityreason.com/securityalert/2665 - https://www.exploit-db.com/exploits/3858 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2558 (2007/CVE-2007-2558.md) ### [CVE-2007-2558](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2558) ### Description PHP remote file inclusion vulnerability in index.php in phpFullAnnu CMS (pfa CMS) 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the repinc parameter. NOTE: CVE disputes this issue since $repinc is set to a constant value before use ### POC #### Reference - http://securityreason.com/securityalert/2667 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2559 (2007/CVE-2007-2559.md) ### [CVE-2007-2559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2559) ### Description Multiple PHP remote file inclusion vulnerabilities in american cart 3.5 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php, (2) checkout.php, and (3) libsecure.php. ### POC #### Reference - http://securityreason.com/securityalert/2681 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2560 (2007/CVE-2007-2560.md) ### [CVE-2007-2560](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2560) ### Description Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rubrik parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3867 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2561 (2007/CVE-2007-2561.md) ### [CVE-2007-2561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2561) ### Description SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115. ### POC #### Reference - http://securityreason.com/securityalert/2688 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2562 (2007/CVE-2007-2562.md) ### [CVE-2007-2562](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2562) ### Description Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary web script or HTML via the _m parameter. ### POC #### Reference - http://securityreason.com/securityalert/2684 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2565 (2007/CVE-2007-2565.md) ### [CVE-2007-2565](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2565) ### Description Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file. ### POC #### Reference - http://securityreason.com/securityalert/2687 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2566 (2007/CVE-2007-2566.md) ### [CVE-2007-2566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2566) ### Description The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package. ### POC #### Reference - http://securityreason.com/securityalert/2683 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2567 (2007/CVE-2007-2567.md) ### [CVE-2007-2567](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2567) ### Description Buffer overflow in the SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2683 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2569 (2007/CVE-2007-2569.md) ### [CVE-2007-2569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2569) ### Description Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/. ### POC #### Reference - https://www.exploit-db.com/exploits/3864 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2570 (2007/CVE-2007-2570.md) ### [CVE-2007-2570](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2570) ### Description PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrary PHP code via a URL in the sous_rep parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3863 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2571 (2007/CVE-2007-2571.md) ### [CVE-2007-2571](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2571) ### Description SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action. ### POC #### Reference - https://www.exploit-db.com/exploits/3862 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2572 (2007/CVE-2007-2572.md) ### [CVE-2007-2572](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2572) ### Description PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3861 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2573 (2007/CVE-2007-2573.md) ### [CVE-2007-2573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2573) ### Description PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3860 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2574 (2007/CVE-2007-2574.md) ### [CVE-2007-2574](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2574) ### Description Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3859 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2575 (2007/CVE-2007-2575.md) ### [CVE-2007-2575](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2575) ### Description PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3857 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2576 (2007/CVE-2007-2576.md) ### [CVE-2007-2576](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2576) ### Description Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a long OpenDVD property value. NOTE: this issue might be related to CVE-2007-0976. ### POC #### Reference - http://moaxb.blogspot.com/2007/05/moaxb-05-east-wind-software.html - https://www.exploit-db.com/exploits/3856 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2577 (2007/CVE-2007-2577.md) ### [CVE-2007-2577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2577) ### Description Multiple SQL injection vulnerabilities in ACP3 4.0 beta 3 allow remote attackers to execute arbitrary SQL commands via (1) the mode parameter to feeds.php, the (2) form[cat] parameter to (a) news/list/index.php or (b) certain news/details/id_*/action_create/index.php files, or (3) the form[mods][] parameter to search/list/action_search/index.php. ### POC #### Reference - http://securityreason.com/securityalert/2686 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2578 (2007/CVE-2007-2578.md) ### [CVE-2007-2578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2578) ### Description Unspecified vulnerability in search/list/action_search/index.php in ACP3 4.0 beta 3 allows remote attackers to have unknown impact, relating to "Cookie Manipulation", via the form[search_term] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2686 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2579 (2007/CVE-2007-2579.md) ### [CVE-2007-2579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2579) ### Description Multiple cross-site scripting (XSS) vulnerabilities in ACP3 4.0 beta 3 allow remote attackers to inject arbitrary web script or HTML via (1) the form[mail] parameter to contact/contact/index.php; the (2) form[mods][] or (3) form[search_term] parameter to search/list/action_search/index.php; (4) the id parameter to modules/dl/download.php; (5) the form[cat] parameter to news/list/index.php; the (6) form[cat], (7) form[name], or (8) form[message] parameter to certain news/details/id_*/action_create/index.php files; or (9) the form[mail] parameter to newsletter/create/index.php. ### POC #### Reference - http://securityreason.com/securityalert/2686 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2580 (2007/CVE-2007-2580.md) ### [CVE-2007-2580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2580) ### Description Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script. ### POC #### Reference - http://securityreason.com/securityalert/2685 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2581 (2007/CVE-2007-2581.md) ### [CVE-2007-2581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2581) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. ### POC #### Reference - http://securityreason.com/securityalert/2682 - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-059 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2582 (2007/CVE-2007-2582.md) ### [CVE-2007-2582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2582) ### Description Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2583 (2007/CVE-2007-2583.md) ### [CVE-2007-2583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2583) ### Description The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference. ### POC #### Reference - http://packetstormsecurity.com/files/124295/MySQL-5.0.x-Denial-Of-Service.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9930 #### Github - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 2586 (2007/CVE-2007-2586.md) ### [CVE-2007-2586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2586) ### Description The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259. ### POC #### Reference No PoCs from references. #### Github - https://github.com/alt3kx/alt3kx.github.io --- ### 2007/CVE 2007 2590 (2007/CVE-2007-2590.md) ### [CVE-2007-2590](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2590) ### Description Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp. ### POC #### Reference - http://securityreason.com/securityalert/2689 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2591 (2007/CVE-2007-2591.md) ### [CVE-2007-2591](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2591) ### Description usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action. ### POC #### Reference - http://securityreason.com/securityalert/2689 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2592 (2007/CVE-2007-2592.md) ### [CVE-2007-2592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2592) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files. ### POC #### Reference - http://securityreason.com/securityalert/2689 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2593 (2007/CVE-2007-2593.md) ### [CVE-2007-2593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2593) ### Description The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2007/CVE 2007 2594 (2007/CVE-2007-2594.md) ### [CVE-2007-2594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2594) ### Description PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[CHEMINMODULES] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3879 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2596 (2007/CVE-2007-2596.md) ### [CVE-2007-2596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2596) ### Description PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3884 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2597 (2007/CVE-2007-2597.md) ### [CVE-2007-2597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2597) ### Description Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) ordnertiefe parameter to site_conf.php; or the (2) tt_docroot parameter to (a) class.csv.php, (b) produkte_nach_serie.php, or (c) ref_kd_rubrik.php in functionen/; (d) hg_referenz_jobgalerie.php, (e) surfer_anmeldung_NWL.php, (f) produkte_nach_serie_alle.php, (g) surfer_aendern.php, (h) ref_kd_rubrik.php, or (i) referenz.php in module/; or (j) 1/lay.php or (k) 3/lay.php in standard/. ### POC #### Reference - https://www.exploit-db.com/exploits/3885 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2598 (2007/CVE-2007-2598.md) ### [CVE-2007-2598](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2598) ### Description SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3886 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2599 (2007/CVE-2007-2599.md) ### [CVE-2007-2599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2599) ### Description Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or (3) the search parameter to search.php. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1742 - https://www.exploit-db.com/exploits/3887 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2600 (2007/CVE-2007-2600.md) ### [CVE-2007-2600](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2600) ### Description Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1742 - https://www.exploit-db.com/exploits/3887 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2601 (2007/CVE-2007-2601.md) ### [CVE-2007-2601](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2601) ### Description Buffer overflow in a certain ActiveX control in the GDivX Zenith Player AviFixer class in fix.dll 1.0.0.1 allows remote attackers to execute arbitrary code via a long SetInputFile property value. ### POC #### Reference - https://www.exploit-db.com/exploits/3889 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2602 (2007/CVE-2007-2602.md) ### [CVE-2007-2602](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2602) ### Description Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common scenario under which MIBEXTRA.EXE is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE. ### POC #### Reference - http://securityreason.com/securityalert/2708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2603 (2007/CVE-2007-2603.md) ### [CVE-2007-2603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2603) ### Description Unspecified vulnerability in the Init function in the Audio CD Ripper OCX (AudioCDRipperOCX.ocx) 1.0 ActiveX control allows remote attackers to cause a denial of service (NULL dereference and Internet Explorer crash) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2604 (2007/CVE-2007-2604.md) ### [CVE-2007-2604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2604) ### Description Unspecified vulnerability in the FlexLabel ActiveX control allows remote attackers to cause a denial of service (unstable behavior) via an improper initialization, as demonstrated by a certain value of the Caption property. ### POC #### Reference - http://securityreason.com/securityalert/2708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2605 (2007/CVE-2007-2605.md) ### [CVE-2007-2605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2605) ### Description Unspecified vulnerability in the GetPropertyById function in ISoftomateObj in SoftomateLib in BRUJULA4.NET.DLL in the Brujula Toolbar (Brujula.net toolbar) allows attackers to cause a denial of service (NULL dereference and browser crash) via certain arguments. ### POC #### Reference - http://securityreason.com/securityalert/2708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2606 (2007/CVE-2007-2606.md) ### [CVE-2007-2606](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2606) ### Description Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\ConfigFile.cpp or (2) msgs\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE. ### POC #### Reference - http://securityreason.com/securityalert/2708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2607 (2007/CVE-2007-2607.md) ### [CVE-2007-2607](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2607) ### Description PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3870 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2608 (2007/CVE-2007-2608.md) ### [CVE-2007-2608](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2608) ### Description PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via a URL in the system[smarty][dir] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3878 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2609 (2007/CVE-2007-2609.md) ### [CVE-2007-2609](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2609) ### Description Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR parameter to (1) libs/lom.php; (2) lom_update.php, (3) check-lom.php, and (4) weigh_keywords.php in scripts/; the (b) LIBSDIR parameter to (5) logout.php, (6) help.php, (7) index.php, (8) login.php; and the ETCDIR parameter to (9) web/lom.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3876 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2611 (2007/CVE-2007-2611.md) ### [CVE-2007-2611](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2611) ### Description Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX parameter to (1) mtdialogo.php, (2) ltdialogo.php, (3) login.php, and (4) logingecon.php in inc/; and multiple unspecified files in frm/, sql/, and cns/. ### POC #### Reference - https://www.exploit-db.com/exploits/3874 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2614 (2007/CVE-2007-2614.md) ### [CVE-2007-2614](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2614) ### Description PHP remote file inclusion vulnerability in examples/widget8.php in phpHtmlLib 2.4.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. ### POC #### Reference - http://securityreason.com/securityalert/2690 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2615 (2007/CVE-2007-2615.md) ### [CVE-2007-2615](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2615) ### Description Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_local parameter to (1) ftp.php, (2) libs/db.php, and (3) libs/ftp.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3875 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2618 (2007/CVE-2007-2618.md) ### [CVE-2007-2618](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2618) ### Description CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS." ### POC #### Reference - http://securityreason.com/securityalert/2691 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2620 (2007/CVE-2007-2620.md) ### [CVE-2007-2620](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2620) ### Description PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the x[1] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3894 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2621 (2007/CVE-2007-2621.md) ### [CVE-2007-2621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2621) ### Description SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3895 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2622 (2007/CVE-2007-2622.md) ### [CVE-2007-2622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2622) ### Description Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login.php or (2) the taskid parameter to notes.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3896 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2623 (2007/CVE-2007-2623.md) ### [CVE-2007-2623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2623) ### Description Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via (1) a long first argument to the connect function or (2) a long InternalServer property value, possibly involving ntdll.dll. ### POC #### Reference - https://www.exploit-db.com/exploits/3891 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2626 (2007/CVE-2007-2626.md) ### [CVE-2007-2626](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2626) ### Description SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because 'username' does not exist, and the password is not used in any queries ### POC #### Reference - http://securityreason.com/securityalert/2695 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2627 (2007/CVE-2007-2627.md) ### [CVE-2007-2627](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2627) ### Description Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622. ### POC #### Reference - http://securityreason.com/securityalert/2694 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2628 (2007/CVE-2007-2628.md) ### [CVE-2007-2628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2628) ### Description PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityAdmin, PSA) 4.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the PSA_PATH parameter. ### POC #### Reference - http://securityreason.com/securityalert/2693 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2629 (2007/CVE-2007-2629.md) ### [CVE-2007-2629](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2629) ### Description Bradford CampusManager Network Control Application Server 3.1(6) allows remote attackers to obtain sensitive information (backup, log, and configuration files) via direct request for certain files in (1) /runTime/ or (2) /remediationReports/. ### POC #### Reference - http://securityreason.com/securityalert/2698 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2632 (2007/CVE-2007-2632.md) ### [CVE-2007-2632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2632) ### Description Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[]. ### POC #### Reference - http://marc.info/?l=bugtraq&m=117883301207293&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2638 (2007/CVE-2007-2638.md) ### [CVE-2007-2638](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2638) ### Description eFileCabinet 3.3 allows remote attackers to bypass authentication and access restricted portions of the interface via an invalid filecabinetnumber, which can be leveraged to obtain sensitive information or create new data structures. ### POC #### Reference - http://securityreason.com/securityalert/2696 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2639 (2007/CVE-2007-2639.md) ### [CVE-2007-2639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2639) ### Description Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2699 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2641 (2007/CVE-2007-2641.md) ### [CVE-2007-2641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2641) ### Description SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter, a different vector than CVE-2007-0920. ### POC #### Reference - http://securityreason.com/securityalert/2692 - https://www.exploit-db.com/exploits/3905 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2642 (2007/CVE-2007-2642.md) ### [CVE-2007-2642](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2642) ### Description Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3902 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2643 (2007/CVE-2007-2643.md) ### [CVE-2007-2643](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2643) ### Description Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3901 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2644 (2007/CVE-2007-2644.md) ### [CVE-2007-2644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2644) ### Description A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename. ### POC #### Reference - https://www.exploit-db.com/exploits/3899 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2645 (2007/CVE-2007-2645.md) ### [CVE-2007-2645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2645) ### Description Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2646 (2007/CVE-2007-2646.md) ### [CVE-2007-2646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2646) ### Description Heap-based buffer overflow in yEnc32 1.0.7.207 allows user-assisted remote attackers to execute arbitrary code via a long filename in an NTX file. ### POC #### Reference - http://securityreason.com/securityalert/2706 - http://vuln.sg/yenc32-107-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2647 (2007/CVE-2007-2647.md) ### [CVE-2007-2647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2647) ### Description Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users to inject arbitrary PHP code into the conf/config.inc.php file via the (1) gadm_pass, (2) gadm_user, (3) gcfgHote, (4) gcfgPass, (5) gcfgUser, (6) gclassement_rep, (7) gcontour, (8) gfond, (9) ggd_version, (10) ghome, (11) ghor, (12) gimg_copyright, (13) glangage, (14) gmenu_visible, (15) gmini_hasard, (16) gordre_rep, (17) gpage, (18) gracine, (19) grech_inactive, (20) grep_mini, (21) grepertoire, (22) gsite, (23) gslide, (24) gtitre, (25) guse_copyright, (26) gversion, (27) gvert, or (28) gcfgBase parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3903 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2649 (2007/CVE-2007-2649.md) ### [CVE-2007-2649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2649) ### Description Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script. ### POC #### Reference - http://securityreason.com/securityalert/2705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2654 (2007/CVE-2007-2654.md) ### [CVE-2007-2654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2654) ### Description xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. ### POC #### Reference - http://www.ubuntu.com/usn/usn-516-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2656 (2007/CVE-2007-2656.md) ### [CVE-2007-2656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2656) ### Description Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile method. ### POC #### Reference - https://www.exploit-db.com/exploits/3898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2657 (2007/CVE-2007-2657.md) ### [CVE-2007-2657](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2657) ### Description Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote attackers to cause a denial of service via a long argument to the SaveBarCode method. ### POC #### Reference - https://www.exploit-db.com/exploits/3910 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2658 (2007/CVE-2007-2658.md) ### [CVE-2007-2658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2658) ### Description Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows remote attackers to cause a denial of service via a long argument to the SaveEnhWMF method. ### POC #### Reference - https://www.exploit-db.com/exploits/3917 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2659 (2007/CVE-2007-2659.md) ### [CVE-2007-2659](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2659) ### Description Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter in a downloadfile action. ### POC #### Reference - https://www.exploit-db.com/exploits/3918 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2660 (2007/CVE-2007-2660.md) ### [CVE-2007-2660](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2660) ### Description PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this issue since there is no include statement in pcltrace.lib.php. NOTE: the pcltar.lib.php vector is already covered by CVE-2007-2199 ### POC #### Reference - https://www.exploit-db.com/exploits/3915 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2661 (2007/CVE-2007-2661.md) ### [CVE-2007-2661](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2661) ### Description SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via the var parameter, a different vector than CVE-2006-5976. ### POC #### Reference - https://www.exploit-db.com/exploits/3914 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2662 (2007/CVE-2007-2662.md) ### [CVE-2007-2662](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2662) ### Description SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI. ### POC #### Reference - https://www.exploit-db.com/exploits/3911 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2663 (2007/CVE-2007-2663.md) ### [CVE-2007-2663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2663) ### Description PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3909 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2664 (2007/CVE-2007-2664.md) ### [CVE-2007-2664](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2664) ### Description PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, possibly related to the __autoload function. ### POC #### Reference - https://www.exploit-db.com/exploits/3908 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2665 (2007/CVE-2007-2665.md) ### [CVE-2007-2665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2665) ### Description PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3906 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2666 (2007/CVE-2007-2666.md) ### [CVE-2007-2666](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2666) ### Description Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++. ### POC #### Reference - https://www.exploit-db.com/exploits/3912 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2667 (2007/CVE-2007-2667.md) ### [CVE-2007-2667](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2667) ### Description Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3916 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2668 (2007/CVE-2007-2668.md) ### [CVE-2007-2668](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2668) ### Description Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c. ### POC #### Reference - https://www.exploit-db.com/exploits/3913 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2671 (2007/CVE-2007-2671.md) ### [CVE-2007-2671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2671) ### Description Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access. ### POC #### Reference - http://securityreason.com/securityalert/2704 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2672 (2007/CVE-2007-2672.md) ### [CVE-2007-2672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2672) ### Description SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL commands via the bus parameter in a viewbus page. ### POC #### Reference - https://www.exploit-db.com/exploits/3839 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2673 (2007/CVE-2007-2673.md) ### [CVE-2007-2673](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2673) ### Description SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3843 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2674 (2007/CVE-2007-2674.md) ### [CVE-2007-2674](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2674) ### Description SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3842 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2675 (2007/CVE-2007-2675.md) ### [CVE-2007-2675](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2675) ### Description SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3840 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2676 (2007/CVE-2007-2676.md) ### [CVE-2007-2676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2676) ### Description PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attackers to execute arbitrary PHP code via a URL in the ote_home parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3838 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2677 (2007/CVE-2007-2677.md) ### [CVE-2007-2677](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2677) ### Description Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2) layout_admin_cfg.php, (3) layout_cfg.php, or (4) layout_t_top.php in skins/phpchess/. NOTE: vector 1 has been disputed by CVE, since the code is defined within a function that is not called from within includes/language.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3837 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2681 (2007/CVE-2007-2681.md) ### [CVE-2007-2681](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2681) ### Description Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter. ### POC #### Reference - http://securityreason.com/securityalert/2697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2683 (2007/CVE-2007-2683.md) ### [CVE-2007-2683](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2683) ### Description Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 2691 (2007/CVE-2007-2691.md) ### [CVE-2007-2691](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2691) ### Description MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559 #### Github - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 2692 (2007/CVE-2007-2692.md) ### [CVE-2007-2692](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2692) ### Description The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9166 #### Github - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 2695 (2007/CVE-2007-2695.md) ### [CVE-2007-2695](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2695) ### Description The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," which allows remote attackers to access administrative data or functionality. ### POC #### Reference - http://dev2dev.bea.com/pub/advisory/227 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2696 (2007/CVE-2007-2696.md) ### [CVE-2007-2696](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2696) ### Description The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queues via direct requests to the JMS back-end server. ### POC #### Reference - http://dev2dev.bea.com/pub/advisory/228 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2697 (2007/CVE-2007-2697.md) ### [CVE-2007-2697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2697) ### Description The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service. ### POC #### Reference - http://dev2dev.bea.com/pub/advisory/229 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2699 (2007/CVE-2007-2699.md) ### [CVE-2007-2699](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2699) ### Description The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files. ### POC #### Reference - http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2706 (2007/CVE-2007-2706.md) ### [CVE-2007-2706](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2706) ### Description PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3924 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2707 (2007/CVE-2007-2707.md) ### [CVE-2007-2707](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2707) ### Description PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3923 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2708 (2007/CVE-2007-2708.md) ### [CVE-2007-2708](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2708) ### Description PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3920 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2709 (2007/CVE-2007-2709.md) ### [CVE-2007-2709](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2709) ### Description PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3919 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2711 (2007/CVE-2007-2711.md) ### [CVE-2007-2711](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2711) ### Description Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113. ### POC #### Reference - https://www.exploit-db.com/exploits/3925 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2713 (2007/CVE-2007-2713.md) ### [CVE-2007-2713](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2713) ### Description ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI. ### POC #### Reference - http://securityreason.com/securityalert/2707 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2714 (2007/CVE-2007-2714.md) ### [CVE-2007-2714](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2714) ### Description Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2715 (2007/CVE-2007-2715.md) ### [CVE-2007-2715](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2715) ### Description Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action. ### POC #### Reference - https://www.exploit-db.com/exploits/3900 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2717 (2007/CVE-2007-2717.md) ### [CVE-2007-2717](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2717) ### Description SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537. ### POC #### Reference - https://www.exploit-db.com/exploits/3907 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2721 (2007/CVE-2007-2721.md) ### [CVE-2007-2721](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721) ### Description The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9397 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2722 (2007/CVE-2007-2722.md) ### [CVE-2007-2722](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2722) ### Description Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence. ### POC #### Reference - https://www.exploit-db.com/exploits/3930 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2723 (2007/CVE-2007-2723.md) ### [CVE-2007-2723](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2723) ### Description Media Player Classic 6.4.9.0 allows user-assisted remote attackers to cause a denial of service (web browser crash) via an "empty" .MPA file, which triggers a divide-by-zero error. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Nmerryman/cve_rev --- ### 2007/CVE 2007 2724 (2007/CVE-2007-2724.md) ### [CVE-2007-2724](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2724) ### Description Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter. ### POC #### Reference - http://securityreason.com/securityalert/2713 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2726 (2007/CVE-2007-2726.md) ### [CVE-2007-2726](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2726) ### Description BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns. ### POC #### Reference - https://www.exploit-db.com/exploits/3929 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2727 (2007/CVE-2007-2727.md) ### [CVE-2007-2727](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2727) ### Description The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2007-2727 --- ### 2007/CVE 2007 2728 (2007/CVE-2007-2728.md) ### [CVE-2007-2728](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2728) ### Description The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2729 (2007/CVE-2007-2729.md) ### [CVE-2007-2729](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2729) ### Description Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier. ### POC #### Reference - http://securityreason.com/securityalert/2714 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2730 (2007/CVE-2007-2730.md) ### [CVE-2007-2730](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2730) ### Description Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier. ### POC #### Reference - http://securityreason.com/securityalert/2714 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2731 (2007/CVE-2007-2731.md) ### [CVE-2007-2731](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2731) ### Description CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A) sequences in the subject parameter, a related issue to CVE-2007-1898. ### POC #### Reference - http://securityreason.com/securityalert/2710 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2732 (2007/CVE-2007-2732.md) ### [CVE-2007-2732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2732) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/. ### POC #### Reference - http://securityreason.com/securityalert/2711 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2733 (2007/CVE-2007-2733.md) ### [CVE-2007-2733](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2733) ### Description Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448. ### POC #### Reference - http://securityreason.com/securityalert/2711 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2734 (2007/CVE-2007-2734.md) ### [CVE-2007-2734](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2734) ### Description The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic. ### POC #### Reference - http://securityreason.com/securityalert/2712 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2735 (2007/CVE-2007-2735.md) ### [CVE-2007-2735](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2735) ### Description SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id_reserv parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3931 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2736 (2007/CVE-2007-2736.md) ### [CVE-2007-2736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2736) ### Description PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3928 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2738 (2007/CVE-2007-2738.md) ### [CVE-2007-2738](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2738) ### Description SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action. ### POC #### Reference - https://www.exploit-db.com/exploits/3932 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2743 (2007/CVE-2007-2743.md) ### [CVE-2007-2743](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2743) ### Description PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3935 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2748 (2007/CVE-2007-2748.md) ### [CVE-2007-2748](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2748) ### Description The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2749 (2007/CVE-2007-2749.md) ### [CVE-2007-2749](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2749) ### Description SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action. ### POC #### Reference - https://www.exploit-db.com/exploits/3943 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2750 (2007/CVE-2007-2750.md) ### [CVE-2007-2750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2750) ### Description SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQL commands via the newsnr parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3942 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2751 (2007/CVE-2007-2751.md) ### [CVE-2007-2751](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2751) ### Description Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3941 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2752 (2007/CVE-2007-2752.md) ### [CVE-2007-2752](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2752) ### Description SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3936 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2753 (2007/CVE-2007-2753.md) ### [CVE-2007-2753](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2753) ### Description RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb. ### POC #### Reference - https://www.exploit-db.com/exploits/3936 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2754 (2007/CVE-2007-2754.md) ### [CVE-2007-2754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754) ### Description Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2755 (2007/CVE-2007-2755.md) ### [CVE-2007-2755](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2755) ### Description The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744. ### POC #### Reference - https://www.exploit-db.com/exploits/3938 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2756 (2007/CVE-2007-2756.md) ### [CVE-2007-2756](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2756) ### Description The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0146.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2757 (2007/CVE-2007-2757.md) ### [CVE-2007-2757](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2757) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) wp-content/themes/redoable/searchloop.php or (2) wp-content/themes/redoable/header.php. ### POC #### Reference - http://securityreason.com/securityalert/2721 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2758 (2007/CVE-2007-2758.md) ### [CVE-2007-2758](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2758) ### Description Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow during extraction, or (2) a heap-based buffer overflow during traversal. ### POC #### Reference - http://vuln.sg/winimage808000-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2761 (2007/CVE-2007-2761.md) ### [CVE-2007-2761](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2761) ### Description Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file. ### POC #### Reference - https://www.exploit-db.com/exploits/3945 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2762 (2007/CVE-2007-2762.md) ### [CVE-2007-2762](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2762) ### Description Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/. ### POC #### Reference - https://www.exploit-db.com/exploits/3947 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2764 (2007/CVE-2007-2764.md) ### [CVE-2007-2764](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2764) ### Description The embedded Linux kernel in certain Sun-Brocade SilkWorm switches before 20070516 does not properly handle a situation in which a non-root user creates a kernel process, which allows attackers to cause a denial of service (oops and device reboot) via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/BobyMCbobs/talos-linux-cve-research - https://github.com/BobyMCbobs/talos-linux-cve-research.old --- ### 2007/CVE 2007 2768 (2007/CVE-2007-2768.md) ### [CVE-2007-2768](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2768) ### Description OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan - https://github.com/siddicky/git-and-crumpets - https://github.com/vshaliii/DC-4-Vulnhub-Walkthrough --- ### 2007/CVE 2007 2770 (2007/CVE-2007-2770.md) ### [CVE-2007-2770](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2770) ### Description Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue. ### POC #### Reference - https://www.exploit-db.com/exploits/3934 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2771 (2007/CVE-2007-2771.md) ### [CVE-2007-2771](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2771) ### Description Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2772 (2007/CVE-2007-2772.md) ### [CVE-2007-2772](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2772) ### Description (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet. ### POC #### Reference - http://securityreason.com/securityalert/2727 - https://www.exploit-db.com/exploits/3939 - https://www.exploit-db.com/exploits/3940 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/shirkdog/exploits --- ### 2007/CVE 2007 2773 (2007/CVE-2007-2773.md) ### [CVE-2007-2773](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2773) ### Description SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3955 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2774 (2007/CVE-2007-2774.md) ### [CVE-2007-2774](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2774) ### Description Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3953 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2775 (2007/CVE-2007-2775.md) ### [CVE-2007-2775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2775) ### Description AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3957 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2776 (2007/CVE-2007-2776.md) ### [CVE-2007-2776](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2776) ### Description AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2777 (2007/CVE-2007-2777.md) ### [CVE-2007-2777](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2777) ### Description Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/. ### POC #### Reference - https://www.exploit-db.com/exploits/3959 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2778 (2007/CVE-2007-2778.md) ### [CVE-2007-2778](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2778) ### Description Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts. ### POC #### Reference - https://www.exploit-db.com/exploits/3949 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2779 (2007/CVE-2007-2779.md) ### [CVE-2007-2779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2779) ### Description PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3948 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2780 (2007/CVE-2007-2780.md) ### [CVE-2007-2780](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2780) ### Description PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=117948032428148&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2781 (2007/CVE-2007-2781.md) ### [CVE-2007-2781](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2781) ### Description Cross-site scripting (XSS) vulnerability in include/sessionRegister.php in WikyBlog before 1.4.13 allows remote attackers to inject arbitrary web script or HTML, probably via vectors related to a certain data2 array element. ### POC #### Reference - http://wikyblog.svn.sourceforge.net/viewvc/wikyblog/trunk/include/sessionRegister.php?view=log #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2782 (2007/CVE-2007-2782.md) ### [CVE-2007-2782](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2782) ### Description Packeteer PacketShaper uses fixed increments in TCP initial sequence number (ISN) values, which allows remote attackers to predict the ISN value, and perform session hijacking or disruption. ### POC #### Reference - http://securityreason.com/securityalert/2726 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2783 (2007/CVE-2007-2783.md) ### [CVE-2007-2783](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2783) ### Description Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. NOTE: this issue has no actionable information, and perhaps should not be included in CVE. ### POC #### Reference - http://securityreason.com/securityalert/2723 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2785 (2007/CVE-2007-2785.md) ### [CVE-2007-2785](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2785) ### Description manage-admins.php in eSyndiCat Pro 1.x allows remote attackers to create additional administrative accounts, and have other unspecified impact, via modified username, new_pass, new_pass2, status, super, and certain other parameters in an add action. ### POC #### Reference - http://securityreason.com/securityalert/2729 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2787 (2007/CVE-2007-2787.md) ### [CVE-2007-2787](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2787) ### Description Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument. ### POC #### Reference - https://www.exploit-db.com/exploits/3951 - https://www.exploit-db.com/exploits/3952 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2788 (2007/CVE-2007-2788.md) ### [CVE-2007-2788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2788) ### Description Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0100.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2789 (2007/CVE-2007-2789.md) ### [CVE-2007-2789](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2789) ### Description The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0100.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2790 (2007/CVE-2007-2790.md) ### [CVE-2007-2790](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2790) ### Description Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter. ### POC #### Reference - http://securityreason.com/securityalert/2728 - http://www.vpasp.com/helpnotes/fixes.asp?version=v650 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2792 (2007/CVE-2007-2792.md) ### [CVE-2007-2792](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2792) ### Description SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://packetstormsecurity.org/0806-exploits/joomlayanc-sql.txt - https://www.exploit-db.com/exploits/3944 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2793 (2007/CVE-2007-2793.md) ### [CVE-2007-2793](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2793) ### Description PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3946 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2797 (2007/CVE-2007-2797.md) ### [CVE-2007-2797](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2797) ### Description xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals. ### POC #### Reference - http://securityreason.com/securityalert/3066 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2798 (2007/CVE-2007-2798.md) ### [CVE-2007-2798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798) ### Description Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal. ### POC #### Reference - http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2007-005.txt - http://www.kb.cert.org/vuls/id/554257 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9996 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2801 (2007/CVE-2007-2801.md) ### [CVE-2007-2801](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2801) ### Description Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On." ### POC #### Reference - http://www.securityfocus.com/archive/1/472434/100/0/threaded #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2803 (2007/CVE-2007-2803.md) ### [CVE-2007-2803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2803) ### Description SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a haberdetay action. ### POC #### Reference - https://www.exploit-db.com/exploits/4007 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2809 (2007/CVE-2007-2809.md) ### [CVE-2007-2809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2809) ### Description Buffer overflow in the transfer manager in Opera before 9.21 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted torrent file. NOTE: due to the lack of details, it is not clear if this is the same issue as CVE-2007-2274. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=2823 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2810 (2007/CVE-2007-2810.md) ### [CVE-2007-2810](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2810) ### Description SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2715 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2812 (2007/CVE-2007-2812.md) ### [CVE-2007-2812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2812) ### Description Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.35, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the action parameter. ### POC #### Reference - http://securityreason.com/securityalert/2724 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2815 (2007/CVE-2007-2815.md) ### [CVE-2007-2815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2815) ### Description The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw. ### POC #### Reference - http://securityreason.com/securityalert/2725 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2816 (2007/CVE-2007-2816.md) ### [CVE-2007-2816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2816) ### Description Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11) test6.php, (12) frames1_left.php, and (13) frames1_center.php in themes/. ### POC #### Reference - https://www.exploit-db.com/exploits/3962 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2817 (2007/CVE-2007-2817.md) ### [CVE-2007-2817](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2817) ### Description SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3964 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2820 (2007/CVE-2007-2820.md) ### [CVE-2007-2820](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2820) ### Description Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote attackers to execute arbitrary code via long arguments to the (1) SWAT_Init, (2) SWAT_InitEx, (3) SWAT_InitEx2, (4) SWAT_InitEx3, and (5) SWAT_Login functions. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=117981953312669&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2821 (2007/CVE-2007-2821.md) ### [CVE-2007-2821](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2821) ### Description SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter. ### POC #### Reference - http://www.waraxe.us/advisory-50.html #### Github - https://github.com/llouks/cst312 --- ### 2007/CVE 2007 2822 (2007/CVE-2007-2822.md) ### [CVE-2007-2822](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2822) ### Description TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3963 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2824 (2007/CVE-2007-2824.md) ### [CVE-2007-2824](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2824) ### Description SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3956 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2826 (2007/CVE-2007-2826.md) ### [CVE-2007-2826](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2826) ### Description PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2718 - https://www.exploit-db.com/exploits/4031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2827 (2007/CVE-2007-2827.md) ### [CVE-2007-2827](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2827) ### Description Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2828 (2007/CVE-2007-2828.md) ### [CVE-2007-2828](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2828) ### Description Cross-site request forgery (CSRF) vulnerability in adsense-deluxe.php in the AdSense-Deluxe 0.x plugin for WordPress allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 2829 (2007/CVE-2007-2829.md) ### [CVE-2007-2829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2829) ### Description The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system hang) via a crafted length field in nested 802.3 Ethernet frames in Fast Frame packets, which results in a NULL pointer dereference. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2830 (2007/CVE-2007-2830.md) ### [CVE-2007-2830](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2830) ### Description The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system crash) via crafted beacon interval information when scanning for access points, which triggers a divide-by-zero error. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2831 (2007/CVE-2007-2831.md) ### [CVE-2007-2831](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2831) ### Description Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel memory contents, and possibly execute arbitrary code via a large negative array index value. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2833 (2007/CVE-2007-2833.md) ### [CVE-2007-2833](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2833) ### Description Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation. ### POC #### Reference - http://www.ubuntu.com/usn/usn-504-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2834 (2007/CVE-2007-2834.md) ### [CVE-2007-2834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2834) ### Description Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9967 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2843 (2007/CVE-2007-2843.md) ### [CVE-2007-2843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2843) ### Description Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events. ### POC #### Reference - http://www.thespanner.co.uk/2007/05/18/safari-needs-fixing/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2845 (2007/CVE-2007-2845.md) ### [CVE-2007-2845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2845) ### Description Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB archive, resulting from an "integer cast around". ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118000321419384&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2846 (2007/CVE-2007-2846.md) ### [CVE-2007-2846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2846) ### Description Heap-based buffer overflow in the SIS unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted SIS archive, resulting from an "integer cast around." ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118007660813710&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2851 (2007/CVE-2007-2851.md) ### [CVE-2007-2851](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2851) ### Description A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via the WriteDataToFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/3961 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2852 (2007/CVE-2007-2852.md) ### [CVE-2007-2852](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2852) ### Description Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name. ### POC #### Reference - http://securityreason.com/securityalert/2733 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2853 (2007/CVE-2007-2853.md) ### [CVE-2007-2853](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2853) ### Description The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function. ### POC #### Reference - https://www.exploit-db.com/exploits/3967 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2854 (2007/CVE-2007-2854.md) ### [CVE-2007-2854](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2854) ### Description Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3970 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2857 (2007/CVE-2007-2857.md) ### [CVE-2007-2857](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2857) ### Description PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2732 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2858 (2007/CVE-2007-2858.md) ### [CVE-2007-2858](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2858) ### Description SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field. ### POC #### Reference - http://securityreason.com/securityalert/2731 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2859 (2007/CVE-2007-2859.md) ### [CVE-2007-2859](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2859) ### Description Multiple PHP remote file inclusion vulnerabilities in SimpGB 1.46.0 allow remote attackers to execute arbitrary PHP code via a URL in the path_simpgb parameter to (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php, and possibly other PHP scripts. ### POC #### Reference - http://securityreason.com/securityalert/2735 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2860 (2007/CVE-2007-2860.md) ### [CVE-2007-2860](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2860) ### Description user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action. ### POC #### Reference - http://securityreason.com/securityalert/2736 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2861 (2007/CVE-2007-2861.md) ### [CVE-2007-2861](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2861) ### Description Multiple PHP remote file inclusion vulnerabilities in Simple Accessible XHTML Online News (SAXON) 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) news.php, (2) preview.php, or (3) archive-display.php. ### POC #### Reference - http://securityreason.com/securityalert/2734 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2862 (2007/CVE-2007-2862.md) ### [CVE-2007-2862](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2862) ### Description Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification. ### POC #### Reference - http://securityreason.com/securityalert/2730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2863 (2007/CVE-2007-2863.md) ### [CVE-2007-2863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2863) ### Description Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file. ### POC #### Reference - http://securityreason.com/securityalert/2790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2865 (2007/CVE-2007-2865.md) ### [CVE-2007-2865](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2865) ### Description Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=117987658110713&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2867 (2007/CVE-2007-2867.md) ### [CVE-2007-2867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2867) ### Description Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2868 (2007/CVE-2007-2868.md) ### [CVE-2007-2868](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2868) ### Description Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger memory corruption. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2870 (2007/CVE-2007-2870.md) ### [CVE-2007-2870](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870) ### Description Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9547 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2872 (2007/CVE-2007-2872.md) ### [CVE-2007-2872](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2872) ### Description Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9424 #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 2875 (2007/CVE-2007-2875.md) ### [CVE-2007-2875](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2875) ### Description Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9251 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2877 (2007/CVE-2007-2877.md) ### [CVE-2007-2877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2877) ### Description Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=10894&release_id=503937 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2879 (2007/CVE-2007-2879.md) ### [CVE-2007-2879](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2879) ### Description Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter. ### POC #### Reference - http://securityreason.com/securityalert/2737 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2880 (2007/CVE-2007-2880.md) ### [CVE-2007-2880](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2880) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp. ### POC #### Reference - http://securityreason.com/securityalert/2738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2883 (2007/CVE-2007-2883.md) ### [CVE-2007-2883](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2883) ### Description Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the product is intended to protect the data on a stolen computer. ### POC #### Reference - http://securityreason.com/securityalert/2753 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2884 (2007/CVE-2007-2884.md) ### [CVE-2007-2884](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2884) ### Description Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field. ### POC #### Reference - https://www.exploit-db.com/exploits/3976 - https://www.exploit-db.com/exploits/3977 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2887 (2007/CVE-2007-2887.md) ### [CVE-2007-2887](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2887) ### Description Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page. ### POC #### Reference - http://securityreason.com/securityalert/2742 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2888 (2007/CVE-2007-2888.md) ### [CVE-2007-2888](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2888) ### Description Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/3978 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2889 (2007/CVE-2007-2889.md) ### [CVE-2007-2889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2889) ### Description SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3980 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2890 (2007/CVE-2007-2890.md) ### [CVE-2007-2890](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2890) ### Description SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3981 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2891 (2007/CVE-2007-2891.md) ### [CVE-2007-2891](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2891) ### Description Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3983 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2896 (2007/CVE-2007-2896.md) ### [CVE-2007-2896](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2896) ### Description Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports. ### POC #### Reference - http://securityresponse.symantec.com/avcenter/security/Content/2007.05.24b.html - http://www.vupen.com/english/advisories/2007/1940 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2898 (2007/CVE-2007-2898.md) ### [CVE-2007-2898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2898) ### Description SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php. ### POC #### Reference - http://securityreason.com/securityalert/2752 - http://www.waraxe.us/advisory-51.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2899 (2007/CVE-2007-2899.md) ### [CVE-2007-2899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2899) ### Description Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action. ### POC #### Reference - https://www.exploit-db.com/exploits/3971 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2900 (2007/CVE-2007-2900.md) ### [CVE-2007-2900](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2900) ### Description Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/. ### POC #### Reference - https://www.exploit-db.com/exploits/3972 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2901 (2007/CVE-2007-2901.md) ### [CVE-2007-2901](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2901) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/3974 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2902 (2007/CVE-2007-2902.md) ### [CVE-2007-2902](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2902) ### Description SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3974 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2903 (2007/CVE-2007-2903.md) ### [CVE-2007-2903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2903) ### Description Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2905 (2007/CVE-2007-2905.md) ### [CVE-2007-2905](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2905) ### Description SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the post_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2752 - http://www.waraxe.us/advisory-51.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2908 (2007/CVE-2007-2908.md) ### [CVE-2007-2908](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2908) ### Description Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action. ### POC #### Reference - http://securityreason.com/securityalert/2751 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2913 (2007/CVE-2007-2913.md) ### [CVE-2007-2913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2913) ### Description Cross-site scripting (XSS) vulnerability in index.php in ClonusWiki .5 allows remote attackers to inject arbitrary web script or HTML via the query parameter. ### POC #### Reference - http://securityreason.com/securityalert/2749 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2914 (2007/CVE-2007-2914.md) ### [CVE-2007-2914](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2914) ### Description Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php, (4) weapons.php, and possibly other unspecified files. ### POC #### Reference - http://securityreason.com/securityalert/2750 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2915 (2007/CVE-2007-2915.md) ### [CVE-2007-2915](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2915) ### Description Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email. ### POC #### Reference - http://securityreason.com/securityalert/2746 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2916 (2007/CVE-2007-2916.md) ### [CVE-2007-2916](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2916) ### Description Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote attackers to inject arbitrary web script or HTML via the st parameter. ### POC #### Reference - http://securityreason.com/securityalert/2745 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2919 (2007/CVE-2007-2919.md) ### [CVE-2007-2919](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2919) ### Description Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8) SubURL, and (9) LoadOpf properties. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2926 (2007/CVE-2007-2926.md) ### [CVE-2007-2926](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926) ### Description ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning. ### POC #### Reference - http://www.kb.cert.org/vuls/id/252735 - http://www.trusteer.com/docs/bind9dns.html - http://www.trusteer.com/docs/bind9dns_s.html - http://www.ubuntu.com/usn/usn-491-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2928 (2007/CVE-2007-2928.md) ### [CVE-2007-2928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2928) ### Description Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2929 (2007/CVE-2007-2929.md) ### [CVE-2007-2929](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2929) ### Description The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2930 (2007/CVE-2007-2930.md) ### [CVE-2007-2930](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2930) ### Description The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926. ### POC #### Reference - http://www.trusteer.com/docs/bind8dns.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2931 (2007/CVE-2007-2931.md) ### [CVE-2007-2931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2931) ### Description Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-054 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2932 (2007/CVE-2007-2932.md) ### [CVE-2007-2932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2932) ### Description Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action. ### POC #### Reference - http://securityreason.com/securityalert/2743 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2933 (2007/CVE-2007-2933.md) ### [CVE-2007-2933](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2933) ### Description SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4003 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2934 (2007/CVE-2007-2934.md) ### [CVE-2007-2934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2934) ### Description Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3999 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2935 (2007/CVE-2007-2935.md) ### [CVE-2007-2935](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2935) ### Description core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3998 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2936 (2007/CVE-2007-2936.md) ### [CVE-2007-2936](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2936) ### Description Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3997 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2937 (2007/CVE-2007-2937.md) ### [CVE-2007-2937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2937) ### Description PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3995 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2938 (2007/CVE-2007-2938.md) ### [CVE-2007-2938](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2938) ### Description Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods. ### POC #### Reference - https://www.exploit-db.com/exploits/3993 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2939 (2007/CVE-2007-2939.md) ### [CVE-2007-2939](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2939) ### Description Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/. ### POC #### Reference - https://www.exploit-db.com/exploits/3994 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2940 (2007/CVE-2007-2940.md) ### [CVE-2007-2940](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2940) ### Description Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3992 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2941 (2007/CVE-2007-2941.md) ### [CVE-2007-2941](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2941) ### Description Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3990 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2942 (2007/CVE-2007-2942.md) ### [CVE-2007-2942](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2942) ### Description SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3989 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2943 (2007/CVE-2007-2943.md) ### [CVE-2007-2943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2943) ### Description PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3987 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2945 (2007/CVE-2007-2945.md) ### [CVE-2007-2945](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2945) ### Description RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2754 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2946 (2007/CVE-2007-2946.md) ### [CVE-2007-2946](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2946) ### Description Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath property value. ### POC #### Reference - https://www.exploit-db.com/exploits/3986 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2947 (2007/CVE-2007-2947.md) ### [CVE-2007-2947](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2947) ### Description Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php. ### POC #### Reference - https://www.exploit-db.com/exploits/3991 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2948 (2007/CVE-2007-2948.md) ### [CVE-2007-2948](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2948) ### Description Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2954 (2007/CVE-2007-2954.md) ### [CVE-2007-2954](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2954) ### Description Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2957 (2007/CVE-2007-2957.md) ### [CVE-2007-2957](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2957) ### Description Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow. ### POC #### Reference - https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614035&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=614035 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2958 (2007/CVE-2007-2958.md) ### [CVE-2007-2958](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2958) ### Description Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=190104 - http://www.novell.com/linux/security/advisories/2007_20_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2959 (2007/CVE-2007-2959.md) ### [CVE-2007-2959](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2959) ### Description SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter. ### POC #### Reference - http://securityreason.com/securityalert/2747 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2961 (2007/CVE-2007-2961.md) ### [CVE-2007-2961](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2961) ### Description Unrestricted file upload vulnerability in FileCloset before 1.1.5 allows remote attackers to upload arbitrary PHP files via unspecified vectors. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=185741&release_id=512101 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2962 (2007/CVE-2007-2962.md) ### [CVE-2007-2962](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2962) ### Description Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter. ### POC #### Reference - http://securityreason.com/securityalert/2748 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2968 (2007/CVE-2007-2968.md) ### [CVE-2007-2968](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2968) ### Description Cross-site scripting (XSS) vulnerability in register.php in cpCommerce 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter (Full Name field). ### POC #### Reference - http://securityreason.com/securityalert/2761 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2969 (2007/CVE-2007-2969.md) ### [CVE-2007-2969](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2969) ### Description PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4000 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2971 (2007/CVE-2007-2971.md) ### [CVE-2007-2971](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2971) ### Description SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/3988 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2972 (2007/CVE-2007-2972.md) ### [CVE-2007-2972](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2972) ### Description The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118040810718045&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2974 (2007/CVE-2007-2974.md) ### [CVE-2007-2974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2974) ### Description Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around." ### POC #### Reference - http://securityreason.com/securityalert/2764 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2975 (2007/CVE-2007-2975.md) ### [CVE-2007-2975](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2975) ### Description The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader. ### POC #### Reference - http://www.igniterealtime.org/issues/browse/JM-1049 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2977 (2007/CVE-2007-2977.md) ### [CVE-2007-2977](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2977) ### Description Buffer overflow in the receive function in submit/submitcommon.c in the submit daemon in DOMjudge before 2.0.0RC1 allows remote attackers to cause a denial of service or have other unspecified impact. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=511778 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2978 (2007/CVE-2007-2978.md) ### [CVE-2007-2978](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2978) ### Description Session fixation vulnerability in eggblog 3.1.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. ### POC #### Reference - http://securityreason.com/securityalert/2756 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2979 (2007/CVE-2007-2979.md) ### [CVE-2007-2979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2979) ### Description Techno Dreams Web Directory / Search Engine 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2755 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2980 (2007/CVE-2007-2980.md) ### [CVE-2007-2980](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2980) ### Description Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2985 (2007/CVE-2007-2985.md) ### [CVE-2007-2985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2985) ### Description Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4006 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2986 (2007/CVE-2007-2986.md) ### [CVE-2007-2986](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2986) ### Description PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4005 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 2988 (2007/CVE-2007-2988.md) ### [CVE-2007-2988](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2988) ### Description A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php. ### POC #### Reference - http://securityreason.com/securityalert/2763 - https://www.exploit-db.com/exploits/4004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2991 (2007/CVE-2007-2991.md) ### [CVE-2007-2991](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2991) ### Description Cross-site scripting (XSS) vulnerability in includes/send.inc.php in Evenzia CMS allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. ### POC #### Reference - http://securityreason.com/securityalert/2757 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2992 (2007/CVE-2007-2992.md) ### [CVE-2007-2992](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2992) ### Description Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. ### POC #### Reference - http://securityreason.com/securityalert/2759 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2993 (2007/CVE-2007-2993.md) ### [CVE-2007-2993](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2993) ### Description Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. ### POC #### Reference - http://securityreason.com/securityalert/2759 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2994 (2007/CVE-2007-2994.md) ### [CVE-2007-2994](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2994) ### Description SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector than CVE-2007-0693. ### POC #### Reference - http://securityreason.com/securityalert/2762 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 2997 (2007/CVE-2007-2997.md) ### [CVE-2007-2997](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2997) ### Description Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product. ### POC #### Reference - http://securityreason.com/securityalert/2758 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3000 (2007/CVE-2007-3000.md) ### [CVE-2007-3000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3000) ### Description Multiple SQL injection vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to execute arbitrary SQL commands via (1) the iCategoryUnq parameter to G_Display.php or (2) the iSearchID parameter to Search/DisplayResults.php. ### POC #### Reference - http://securityreason.com/securityalert/2768 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3001 (2007/CVE-2007-3001.md) ### [CVE-2007-3001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3001) ### Description Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the sUName parameter to UserArea/Authenticate.php, (2) the sAccountUnq parameter to UserArea/NewAccounts/index.php, or the (3) iCategoryUnq, (4) iDBLoc, (5) iTtlNumItems, (6) iNumPerPage, or (7) sSort parameter to G_Display.php, different vectors than CVE-2005-4239. ### POC #### Reference - http://securityreason.com/securityalert/2768 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3002 (2007/CVE-2007-3002.md) ### [CVE-2007-3002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3002) ### Description PHP JackKnife (PHPJK) allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid value of the iParentUnq[] parameter, or a request to G_Display.php with an invalid (2) iCategoryUnq[] or (3) sSort[] array parameter, which reveals the path in various error messages. ### POC #### Reference - http://securityreason.com/securityalert/2768 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3003 (2007/CVE-2007-3003.md) ### [CVE-2007-3003](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3003) ### Description Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225. ### POC #### Reference - http://securityreason.com/securityalert/2769 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3006 (2007/CVE-2007-3006.md) ### [CVE-2007-3006](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3006) ### Description Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. NOTE: it was later claimed that 4.51 Build 147 is also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4017 - https://www.exploit-db.com/exploits/6329 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3007 (2007/CVE-2007-3007.md) ### [CVE-2007-3007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3007) ### Description PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. NOTE: this issue might also involve the realpath function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2007-3007 --- ### 2007/CVE 2007 3008 (2007/CVE-2007-3008.md) ### [CVE-2007-3008](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3008) ### Description Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398. ### POC #### Reference No PoCs from references. #### Github - https://github.com/CamillaMagistrello/gmpScan --- ### 2007/CVE 2007 3010 (2007/CVE-2007-3010.md) ### [CVE-2007-3010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3010) ### Description masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119002152126755&w=2 - http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors --- ### 2007/CVE 2007 3011 (2007/CVE-2007-3011.md) ### [CVE-2007-3011](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3011) ### Description The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter. ### POC #### Reference - http://securityreason.com/securityalert/2858 - http://www.redteam-pentesting.de/advisories/rt-sa-2007-002.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3012 (2007/CVE-2007-3012.md) ### [CVE-2007-3012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3012) ### Description The web interface in Fujitsu-Siemens Computers PRIMERGY BX300 Switch Blade allows remote attackers to obtain sensitive information by canceling the authentication dialog when accessing a sub-page, which still displays the form field contents of the sub-page, as demonstrated using (1) config/ip_management.htm and (2) config/snmp_config.htm. ### POC #### Reference - http://www.redteam-pentesting.de/advisories/rt-sa-2007-003.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3013 (2007/CVE-2007-3013.md) ### [CVE-2007-3013](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3013) ### Description SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors. ### POC #### Reference - http://www.redteam-pentesting.de/advisories/rt-sa-2007-004.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3014 (2007/CVE-2007-3014.md) ### [CVE-2007-3014](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3014) ### Description Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype). ### POC #### Reference - http://www.redteam-pentesting.de/advisories/rt-sa-2007-005.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3017 (2007/CVE-2007-3017.md) ### [CVE-2007-3017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3017) ### Description The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp. ### POC #### Reference - http://www.redteam-pentesting.de/advisories/rt-sa-2007-006.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3018 (2007/CVE-2007-3018.md) ### [CVE-2007-3018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3018) ### Description activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories. ### POC #### Reference - http://www.redteam-pentesting.de/advisories/rt-sa-2007-007.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3027 (2007/CVE-2007-3027.md) ### [CVE-2007-3027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3027) ### Description Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka "Language Pack Installation Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3028 (2007/CVE-2007-3028.md) ### [CVE-2007-3028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3028) ### Description The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-039 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3029 (2007/CVE-2007-3029.md) ### [CVE-2007-3029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3029) ### Description Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3030 (2007/CVE-2007-3030.md) ### [CVE-2007-3030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3030) ### Description Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability". ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3032 (2007/CVE-2007-3032.md) ### [CVE-2007-3032](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3032) ### Description Unspecified vulnerability in Windows Vista Contacts Gadget in Windows Vista allows user-assisted remote attackers to execute arbitrary code via crafted contact information that is not properly handled when it is imported. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-048 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3033 (2007/CVE-2007-3033.md) ### [CVE-2007-3033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3033) ### Description Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-048 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3034 (2007/CVE-2007-3034.md) ### [CVE-2007-3034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3034) ### Description Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-046 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3038 (2007/CVE-2007-3038.md) ### [CVE-2007-3038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3038) ### Description The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka "Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3039 (2007/CVE-2007-3039.md) ### [CVE-2007-3039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3039) ### Description Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065 - https://www.exploit-db.com/exploits/4745 - https://www.exploit-db.com/exploits/4760 - https://www.exploit-db.com/exploits/4934 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3040 (2007/CVE-2007-3040.md) ### [CVE-2007-3040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3040) ### Description Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205. ### POC #### Reference - http://securityreason.com/securityalert/3124 - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-051 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3041 (2007/CVE-2007-3041.md) ### [CVE-2007-3041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3041) ### Description Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "ActiveX Object Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3047 (2007/CVE-2007-3047.md) ### [CVE-2007-3047](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3047) ### Description The Vonage VoIP Telephone Adapter has a default administrator username "user" and password "user," which allows remote attackers to obtain administrative access. ### POC #### Reference - http://securityreason.com/securityalert/2771 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3051 (2007/CVE-2007-3051.md) ### [CVE-2007-3051](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3051) ### Description SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/4020 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3052 (2007/CVE-2007-3052.md) ### [CVE-2007-3052](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3052) ### Description SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4026 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3057 (2007/CVE-2007-3057.md) ### [CVE-2007-3057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3057) ### Description PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. ### POC #### Reference - https://www.exploit-db.com/exploits/4022 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3059 (2007/CVE-2007-3059.md) ### [CVE-2007-3059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3059) ### Description SendCard 3.3.0 allows remote attackers to obtain sensitive information via an invalid sc_language parameter to sendcard.php, which reveals the path in an error message. ### POC #### Reference - http://securityreason.com/securityalert/2770 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3061 (2007/CVE-2007-3061.md) ### [CVE-2007-3061](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3061) ### Description Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2780 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3065 (2007/CVE-2007-3065.md) ### [CVE-2007-3065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3065) ### Description SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862. ### POC #### Reference - https://www.exploit-db.com/exploits/4019 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3066 (2007/CVE-2007-3066.md) ### [CVE-2007-3066](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3066) ### Description Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) view.inc.php, (2) users.inc.php, (3) updatecms.inc.php, and (4) polls.inc.php in inc/; and other unspecified files, different vectors than CVE-2006-3983. ### POC #### Reference - http://securityreason.com/securityalert/2773 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3068 (2007/CVE-2007-3068.md) ### [CVE-2007-3068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3068) ### Description Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename. ### POC #### Reference - https://www.exploit-db.com/exploits/4024 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3070 (2007/CVE-2007-3070.md) ### [CVE-2007-3070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3070) ### Description Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter. ### POC #### Reference - http://securityreason.com/securityalert/2772 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3072 (2007/CVE-2007-3072.md) ### [CVE-2007-3072](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3072) ### Description Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI. ### POC #### Reference - https://bugzilla.mozilla.org/show_bug.cgi?id=367428 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3073 (2007/CVE-2007-3073.md) ### [CVE-2007-3073](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3073) ### Description Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI. ### POC #### Reference - https://bugzilla.mozilla.org/show_bug.cgi?id=367428 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3074 (2007/CVE-2007-3074.md) ### [CVE-2007-3074](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3074) ### Description Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI. ### POC #### Reference - https://bugzilla.mozilla.org/show_bug.cgi?id=367428 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3077 (2007/CVE-2007-3077.md) ### [CVE-2007-3077](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3077) ### Description SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4030 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3080 (2007/CVE-2007-3080.md) ### [CVE-2007-3080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3080) ### Description SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2766 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3081 (2007/CVE-2007-3081.md) ### [CVE-2007-3081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3081) ### Description PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2779 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3082 (2007/CVE-2007-3082.md) ### [CVE-2007-3082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3082) ### Description Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4029 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3083 (2007/CVE-2007-3083.md) ### [CVE-2007-3083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3083) ### Description Z-Blog 1.7 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for zblog.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2776 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3085 (2007/CVE-2007-3085.md) ### [CVE-2007-3085](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3085) ### Description Multiple PHP remote file inclusion vulnerabilities in PBSite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dbpath parameter to (a) useronline.php, (b) ucp.php, (c) setcookie.php, (d) sendpm.php, (e) search.php, (f) register.php, (g) profile.php, (h) post.php, (i) pmpshow.php, (j) pm.php, (k) ntopic.php, (l) nreply.php, (m) news.php, (n) memberslist.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (u) editpost.php, (v) delpost.php, (w) delpm.php, (x) confirm.php, (y) board.php, (z) admin2.php, (aa) admin.php, or (bb) templates/pb/css/formstyles.php; or the (2) temppath parameter to (a) useronline.php, (c) setcookie.php, (e) search.php, (f) register.php, (h) post.php, (l) nreply.php, (m) news.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (w) delpm.php, (x) confirm.php, or (y) board.php. ### POC #### Reference - http://securityreason.com/securityalert/2777 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3086 (2007/CVE-2007-3086.md) ### [CVE-2007-3086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3086) ### Description Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex. ### POC #### Reference - http://securityreason.com/securityalert/2775 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3087 (2007/CVE-2007-3087.md) ### [CVE-2007-3087](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3087) ### Description Peercast places a cleartext password in a query string, which might allow attackers to obtain sensitive information by sniffing the network, or obtaining Referer or browser history information. ### POC #### Reference - http://securityreason.com/securityalert/2774 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3088 (2007/CVE-2007-3088.md) ### [CVE-2007-3088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3088) ### Description SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter. ### POC #### Reference - http://securityreason.com/securityalert/2778 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3089 (2007/CVE-2007-3089.md) ### [CVE-2007-3089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089) ### Description Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568. ### POC #### Reference - http://securityreason.com/securityalert/2781 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3091 (2007/CVE-2007-3091.md) ### [CVE-2007-3091](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3091) ### Description Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonstrated by setInterval functions that set location.href within a try/catch expression, aka the "bait & switch vulnerability" or "Race Condition Cross-Domain Information Disclosure Vulnerability." ### POC #### Reference - http://lcamtuf.coredump.cx/ierace/ - http://securityreason.com/securityalert/2781 - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-019 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3092 (2007/CVE-2007-3092.md) ### [CVE-2007-3092](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3092) ### Description Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls. NOTE: this issue can be leveraged for phishing and other attacks. ### POC #### Reference - http://securityreason.com/securityalert/2781 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3096 (2007/CVE-2007-3096.md) ### [CVE-2007-3096](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3096) ### Description Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3098 (2007/CVE-2007-3098.md) ### [CVE-2007-3098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3098) ### Description The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP. ### POC #### Reference - https://www.exploit-db.com/exploits/4033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3102 (2007/CVE-2007-3102.md) ### [CVE-2007-3102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3102) ### Description Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0703.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3103 (2007/CVE-2007-3103.md) ### [CVE-2007-3103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3103) ### Description The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file. ### POC #### Reference - https://www.exploit-db.com/exploits/5167 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3107 (2007/CVE-2007-3107.md) ### [CVE-2007-3107](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3107) ### Description The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9936 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3108 (2007/CVE-2007-3108.md) ### [CVE-2007-3108](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3108) ### Description The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0964.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9984 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 3109 (2007/CVE-2007-3109.md) ### [CVE-2007-3109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3109) ### Description The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO. ### POC #### Reference - http://securityreason.com/securityalert/2784 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3111 (2007/CVE-2007-3111.md) ### [CVE-2007-3111](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3111) ### Description Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value. ### POC #### Reference - https://www.exploit-db.com/exploits/4023 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3114 (2007/CVE-2007-3114.md) ### [CVE-2007-3114](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3114) ### Description Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3115 and CVE-2007-3116. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3115 (2007/CVE-2007-3115.md) ### [CVE-2007-3115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3115) ### Description Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (memory consumption) via (1) reverse lookups or (2) requests for records in a class other than Internet (IN), a different set of affected versions than CVE-2007-3114 and CVE-2007-3116. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3116 (2007/CVE-2007-3116.md) ### [CVE-2007-3116](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3116) ### Description Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3118 (2007/CVE-2007-3118.md) ### [CVE-2007-3118](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3118) ### Description Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4034 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3119 (2007/CVE-2007-3119.md) ### [CVE-2007-3119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3119) ### Description SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4040 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3120 (2007/CVE-2007-3120.md) ### [CVE-2007-3120](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3120) ### Description Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocp_dp parameter. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=514035 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3131 (2007/CVE-2007-3131.md) ### [CVE-2007-3131](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3131) ### Description Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2783 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3132 (2007/CVE-2007-3132.md) ### [CVE-2007-3132](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3132) ### Description Multiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers to cause a denial of service (client or server crash) via malformed requests to the daemon port, 1346/udp or 1347/udp. ### POC #### Reference - http://www.symantec.com/avcenter/security/Content/2007.06.05b.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3133 (2007/CVE-2007-3133.md) ### [CVE-2007-3133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3133) ### Description SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2782 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3135 (2007/CVE-2007-3135.md) ### [CVE-2007-3135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3135) ### Description Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter. ### POC #### Reference - http://securityreason.com/securityalert/2787 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3136 (2007/CVE-2007-3136.md) ### [CVE-2007-3136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3136) ### Description PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4041 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3137 (2007/CVE-2007-3137.md) ### [CVE-2007-3137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3137) ### Description Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect. ### POC #### Reference - http://securityreason.com/securityalert/2789 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3138 (2007/CVE-2007-3138.md) ### [CVE-2007-3138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3138) ### Description Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an sLanguage cookie, which is used to define a value in config/general.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4025 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3139 (2007/CVE-2007-3139.md) ### [CVE-2007-3139](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3139) ### Description config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOTE: this can be leveraged to upload and execute arbitrary code. ### POC #### Reference - https://www.exploit-db.com/exploits/4025 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3140 (2007/CVE-2007-3140.md) ### [CVE-2007-3140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3140) ### Description SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897. ### POC #### Reference - https://www.exploit-db.com/exploits/4039 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3141 (2007/CVE-2007-3141.md) ### [CVE-2007-3141](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3141) ### Description PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. NOTE: the editor_insert_bottom vector is already covered by CVE-2006-6042. ### POC #### Reference - http://securityreason.com/securityalert/2786 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3142 (2007/CVE-2007-3142.md) ### [CVE-2007-3142](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3142) ### Description Visual truncation vulnerability in Opera 9.21 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after 34 characters, as demonstrated by a phishing attack using HTTP Basic Authentication. ### POC #### Reference - http://www.0x000000.com/?i=334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3143 (2007/CVE-2007-3143.md) ### [CVE-2007-3143](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3143) ### Description Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication. ### POC #### Reference - http://www.0x000000.com/?i=334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3144 (2007/CVE-2007-3144.md) ### [CVE-2007-3144](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3144) ### Description Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication. ### POC #### Reference - http://www.0x000000.com/?i=334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3145 (2007/CVE-2007-3145.md) ### [CVE-2007-3145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3145) ### Description Visual truncation vulnerability in Galeon 2.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication. ### POC #### Reference - http://www.0x000000.com/?i=334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3146 (2007/CVE-2007-3146.md) ### [CVE-2007-3146](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3146) ### Description Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2788 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3147 (2007/CVE-2007-3147.md) ### [CVE-2007-3147](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3147) ### Description Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4042 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3148 (2007/CVE-2007-3148.md) ### [CVE-2007-3148](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3148) ### Description Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method. ### POC #### Reference - https://www.exploit-db.com/exploits/4043 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3154 (2007/CVE-2007-3154.md) ### [CVE-2007-3154](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3154) ### Description Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3155 (2007/CVE-2007-3155.md) ### [CVE-2007-3155](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3155) ### Description Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3157 (2007/CVE-2007-3157.md) ### [CVE-2007-3157](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3157) ### Description IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related to the IPv6 support for IPSec. ### POC #### Reference - http://securityreason.com/securityalert/2803 - http://www.digit-labs.org/files/exploits/safenet-dos.c #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3158 (2007/CVE-2007-3158.md) ### [CVE-2007-3158](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3158) ### Description download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter. ### POC #### Reference - http://securityreason.com/securityalert/2793 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3159 (2007/CVE-2007-3159.md) ### [CVE-2007-3159](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3159) ### Description http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/4046 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3160 (2007/CVE-2007-3160.md) ### [CVE-2007-3160](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3160) ### Description PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4055 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3161 (2007/CVE-2007-3161.md) ### [CVE-2007-3161](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3161) ### Description Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response. ### POC #### Reference - https://www.exploit-db.com/exploits/4058 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3162 (2007/CVE-2007-3162.md) ### [CVE-2007-3162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3162) ### Description Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument. ### POC #### Reference - http://www.exploit-db.com/exploits/14938 - https://www.exploit-db.com/exploits/4056 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3166 (2007/CVE-2007-3166.md) ### [CVE-2007-3166](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3166) ### Description Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command. ### POC #### Reference - https://www.exploit-db.com/exploits/4014 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3167 (2007/CVE-2007-3167.md) ### [CVE-2007-3167](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3167) ### Description Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value. ### POC #### Reference - https://www.exploit-db.com/exploits/4015 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3168 (2007/CVE-2007-3168.md) ### [CVE-2007-3168](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3168) ### Description A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4010 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3169 (2007/CVE-2007-3169.md) ### [CVE-2007-3169](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3169) ### Description Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4009 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3176 (2007/CVE-2007-3176.md) ### [CVE-2007-3176](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3176) ### Description Unspecified vulnerability in Ingate Firewall and SIParator before 4.5.2 allows remote authenticated users without full privileges to download a Support Report. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1973 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3177 (2007/CVE-2007-3177.md) ### [CVE-2007-3177](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3177) ### Description Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/1973 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3178 (2007/CVE-2007-3178.md) ### [CVE-2007-3178](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3178) ### Description Multiple SQL injection vulnerabilities in Zindizayn Okul Web Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) pass parameter to (a) mezungiris.asp or (b) ogretmenkontrol.asp. ### POC #### Reference - http://securityreason.com/securityalert/2798 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3179 (2007/CVE-2007-3179.md) ### [CVE-2007-3179](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3179) ### Description Multiple SQL injection vulnerabilities in archives.php in Particle Blogger 1.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the month parameter and other unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2799 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3184 (2007/CVE-2007-3184.md) ### [CVE-2007-3184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3184) ### Description Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation. ### POC #### Reference - http://securityreason.com/securityalert/2796 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3188 (2007/CVE-2007-3188.md) ### [CVE-2007-3188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3188) ### Description SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3193 (2007/CVE-2007-3193.md) ### [CVE-2007-3193](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3193) ### Description lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations. ### POC #### Reference - http://sourceforge.net/tracker/index.php?func=detail&aid=1732882&group_id=6121&atid=106121 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3194 (2007/CVE-2007-3194.md) ### [CVE-2007-3194](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3194) ### Description Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE: another researcher disputes the vulnerability because the files are protected against direct requests, contain no relevant include statements, or do not exist ### POC #### Reference - http://securityreason.com/securityalert/2794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3196 (2007/CVE-2007-3196.md) ### [CVE-2007-3196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3196) ### Description SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action. ### POC #### Reference - http://securityreason.com/securityalert/2795 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3198 (2007/CVE-2007-3198.md) ### [CVE-2007-3198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3198) ### Description Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2797 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3199 (2007/CVE-2007-3199.md) ### [CVE-2007-3199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3199) ### Description Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg. ### POC #### Reference - https://www.exploit-db.com/exploits/4059 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3201 (2007/CVE-2007-3201.md) ### [CVE-2007-3201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3201) ### Description Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID. ### POC #### Reference - http://securityreason.com/securityalert/2791 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3202 (2007/CVE-2007-3202.md) ### [CVE-2007-3202](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3202) ### Description Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document. ### POC #### Reference - http://securityreason.com/securityalert/2792 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3205 (2007/CVE-2007-3205.md) ### [CVE-2007-3205](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3205) ### Description The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. ### POC #### Reference - http://securityreason.com/securityalert/2800 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3208 (2007/CVE-2007-3208.md) ### [CVE-2007-3208](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3208) ### Description CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3214 (2007/CVE-2007-3214.md) ### [CVE-2007-3214](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3214) ### Description SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the template parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4054 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3215 (2007/CVE-2007-3215.md) ### [CVE-2007-3215](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215) ### Description PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. ### POC #### Reference - http://seclists.org/fulldisclosure/2011/Oct/223 - http://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_rce #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3217 (2007/CVE-2007-3217.md) ### [CVE-2007-3217](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3217) ### Description Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the path_inc parameter to (1) index.php in gestion/; (2) identification.php, (3) disconnect.php, (4) loginliste.php, (5) loginmodif.php, (6) index.php, and (7) ident.inc.php in ident/; (8) menuadministration.php and (9) menuprincipal.php in menu/; (10) param.inc.php in param/; (11) index.php in plugins/phpgacl/; and (12) index.php and (13) common.inc.php. ### POC #### Reference - http://securityreason.com/securityalert/2812 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3220 (2007/CVE-2007-3220.md) ### [CVE-2007-3220](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3220) ### Description PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656. ### POC #### Reference - https://www.exploit-db.com/exploits/4070 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3221 (2007/CVE-2007-3221.md) ### [CVE-2007-3221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3221) ### Description PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. ### POC #### Reference - https://www.exploit-db.com/exploits/4069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3222 (2007/CVE-2007-3222.md) ### [CVE-2007-3222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3222) ### Description PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4068 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3228 (2007/CVE-2007-3228.md) ### [CVE-2007-3228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3228) ### Description PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess. ### POC #### Reference - https://www.exploit-db.com/exploits/4071 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3230 (2007/CVE-2007-3230.md) ### [CVE-2007-3230](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3230) ### Description PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4072 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3233 (2007/CVE-2007-3233.md) ### [CVE-2007-3233](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3233) ### Description The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method. ### POC #### Reference - https://www.exploit-db.com/exploits/4060 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3234 (2007/CVE-2007-3234.md) ### [CVE-2007-3234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3234) ### Description SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4062 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3235 (2007/CVE-2007-3235.md) ### [CVE-2007-3235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3235) ### Description Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection. ### POC #### Reference - https://www.exploit-db.com/exploits/4062 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3236 (2007/CVE-2007-3236.md) ### [CVE-2007-3236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3236) ### Description PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4064 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3237 (2007/CVE-2007-3237.md) ### [CVE-2007-3237](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3237) ### Description PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. ### POC #### Reference - https://www.exploit-db.com/exploits/4063 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3239 (2007/CVE-2007-3239.md) ### [CVE-2007-3239](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3239) ### Description Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3240 (2007/CVE-2007-3240.md) ### [CVE-2007-3240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3240) ### Description Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3241 (2007/CVE-2007-3241.md) ### [CVE-2007-3241](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3241) ### Description Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3248 (2007/CVE-2007-3248.md) ### [CVE-2007-3248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3248) ### Description Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic. ### POC #### Reference - http://www.securityfocus.com/bid/24473 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3249 (2007/CVE-2007-3249.md) ### [CVE-2007-3249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3249) ### Description Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118184411720509&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3251 (2007/CVE-2007-3251.md) ### [CVE-2007-3251](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3251) ### Description Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the adminlang cookie to admin/functions.php or (2) read arbitrary local files via the img parameter to admin/show_img.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4054 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3254 (2007/CVE-2007-3254.md) ### [CVE-2007-3254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3254) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server. ### POC #### Reference - http://securityreason.com/securityalert/2845 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3255 (2007/CVE-2007-3255.md) ### [CVE-2007-3255](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3255) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server. ### POC #### Reference - http://securityreason.com/securityalert/2845 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3256 (2007/CVE-2007-3256.md) ### [CVE-2007-3256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3256) ### Description Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution. ### POC #### Reference - http://securityreason.com/securityalert/2845 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3257 (2007/CVE-2007-3257.md) ### [CVE-2007-3257](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3257) ### Description Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3259 (2007/CVE-2007-3259.md) ### [CVE-2007-3259](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3259) ### Description Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages. ### POC #### Reference - http://securityreason.com/securityalert/2841 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3261 (2007/CVE-2007-3261.md) ### [CVE-2007-3261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3261) ### Description Cross-site scripting (XSS) vulnerability in widgets/widget_search.php in dKret before 2.6 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=516770&group_id=185847 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3266 (2007/CVE-2007-3266.md) ### [CVE-2007-3266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3266) ### Description Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter. ### POC #### Reference - http://securityreason.com/securityalert/2816 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3267 (2007/CVE-2007-3267.md) ### [CVE-2007-3267](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3267) ### Description Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235. ### POC #### Reference - http://securityreason.com/securityalert/2815 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3269 (2007/CVE-2007-3269.md) ### [CVE-2007-3269](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3269) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in a GET request or (2) the Title field of a visitor comment, and (3) allow remote authenticated users to inject arbitrary web script or HTML via a message to another user. NOTE: vector (2) might overlap CVE-2006-3571.1. ### POC #### Reference - http://securityreason.com/securityalert/2825 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3270 (2007/CVE-2007-3270.md) ### [CVE-2007-3270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3270) ### Description PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4074 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3271 (2007/CVE-2007-3271.md) ### [CVE-2007-3271](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3271) ### Description PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4075 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3272 (2007/CVE-2007-3272.md) ### [CVE-2007-3272](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3272) ### Description Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action. ### POC #### Reference - https://www.exploit-db.com/exploits/4076 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3274 (2007/CVE-2007-3274.md) ### [CVE-2007-3274](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3274) ### Description Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location. ### POC #### Reference - http://securityreason.com/securityalert/2810 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3278 (2007/CVE-2007-3278.md) ### [CVE-2007-3278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3278) ### Description PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2007-6601 --- ### 2007/CVE 2007 3280 (2007/CVE-2007-3280.md) ### [CVE-2007-3280](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3280) ### Description The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/CVEDB/awesome-cve-repo - https://github.com/DenuwanJayasekara/CVE-Exploitation-Reports - https://github.com/baoloc10/SoftwareSec-Metasploitable2 - https://github.com/darkushhhh/Penetration-Testing-Report --- ### 2007/CVE 2007 3281 (2007/CVE-2007-3281.md) ### [CVE-2007-3281](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3281) ### Description Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. ### POC #### Reference - http://securityreason.com/securityalert/2811 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3282 (2007/CVE-2007-3282.md) ### [CVE-2007-3282](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3282) ### Description Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method. ### POC #### Reference - https://www.exploit-db.com/exploits/4067 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3284 (2007/CVE-2007-3284.md) ### [CVE-2007-3284](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3284) ### Description corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name. ### POC #### Reference - http://lostmon.blogspot.com/2007/06/safari-301-552122-for-windows.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3288 (2007/CVE-2007-3288.md) ### [CVE-2007-3288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3288) ### Description Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field. ### POC #### Reference - http://securityreason.com/securityalert/2826 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3289 (2007/CVE-2007-3289.md) ### [CVE-2007-3289](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3289) ### Description PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. ### POC #### Reference - https://www.exploit-db.com/exploits/4084 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3290 (2007/CVE-2007-3290.md) ### [CVE-2007-3290](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3290) ### Description categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message. ### POC #### Reference - https://www.exploit-db.com/exploits/4082 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3291 (2007/CVE-2007-3291.md) ### [CVE-2007-3291](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3291) ### Description Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4082 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3292 (2007/CVE-2007-3292.md) ### [CVE-2007-3292](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3292) ### Description Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article. ### POC #### Reference - https://www.exploit-db.com/exploits/4082 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3293 (2007/CVE-2007-3293.md) ### [CVE-2007-3293](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3293) ### Description SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4082 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3294 (2007/CVE-2007-3294.md) ### [CVE-2007-3294](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3294) ### Description Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the tidy_repair_string function. NOTE: this might only be an issue in environments where vsnprintf is implemented as a wrapper for vsprintf. ### POC #### Reference - https://www.exploit-db.com/exploits/4080 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3295 (2007/CVE-2007-3295.md) ### [CVE-2007-3295](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3295) ### Description Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the member hash, and is propagated to the language variable in (1) HelpCentre.pl and (2) ICQPager.pl, (3) the use_lang variable in Subs.pl, and the actlang variable in (4) Post.pl and (5) InstantMessage.pl; as demonstrated by pointing userlanguage to the English folder, modifying English/HelpCentre.lng file to contain Perl statements, and then invoking the help action in YaBB.pl. ### POC #### Reference - http://securityreason.com/securityalert/2818 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3297 (2007/CVE-2007-3297.md) ### [CVE-2007-3297](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3297) ### Description Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3) modules/SoundImporter.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4085 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3303 (2007/CVE-2007-3303.md) ### [CVE-2007-3303](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3303) ### Description Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments. ### POC #### Reference - http://securityreason.com/securityalert/2814 #### Github - https://github.com/kasem545/vulnsearch --- ### 2007/CVE 2007 3304 (2007/CVE-2007-3304.md) ### [CVE-2007-3304](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304) ### Description Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer." ### POC #### Reference - http://marc.info/?l=apache-httpd-dev&m=118252946632447&w=2 - http://securityreason.com/securityalert/2814 #### Github - https://github.com/Live-Hack-CVE/CVE-2007-3304 - https://github.com/kasem545/vulnsearch --- ### 2007/CVE 2007 3306 (2007/CVE-2007-3306.md) ### [CVE-2007-3306](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3306) ### Description PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489. ### POC #### Reference - https://www.exploit-db.com/exploits/4079 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3307 (2007/CVE-2007-3307.md) ### [CVE-2007-3307](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3307) ### Description SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/4078 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3311 (2007/CVE-2007-3311.md) ### [CVE-2007-3311](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3311) ### Description SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2817 - https://www.exploit-db.com/exploits/3588 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3312 (2007/CVE-2007-3312.md) ### [CVE-2007-3312](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3312) ### Description Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arbitrary local files a .. (dot dot) in the u parameter. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers. ### POC #### Reference - https://www.exploit-db.com/exploits/4081 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3313 (2007/CVE-2007-3313.md) ### [CVE-2007-3313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3313) ### Description Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4081 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3314 (2007/CVE-2007-3314.md) ### [CVE-2007-3314](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3314) ### Description Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file. ### POC #### Reference - http://vuln.sg/salamander25-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3316 (2007/CVE-2007-3316.md) ### [CVE-2007-3316](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3316) ### Description Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3323 (2007/CVE-2007-3323.md) ### [CVE-2007-3323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3323) ### Description SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2. ### POC #### Reference - http://securityreason.com/securityalert/2819 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3324 (2007/CVE-2007-3324.md) ### [CVE-2007-3324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3324) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681. ### POC #### Reference - http://securityreason.com/securityalert/2819 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3325 (2007/CVE-2007-3325.md) ### [CVE-2007-3325](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3325) ### Description PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205. ### POC #### Reference - https://www.exploit-db.com/exploits/4086 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3326 (2007/CVE-2007-3326.md) ### [CVE-2007-3326](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3326) ### Description Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and other attacks, a different vulnerability than CVE-2005-3025.2. ### POC #### Reference - http://securityreason.com/securityalert/2820 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3327 (2007/CVE-2007-3327.md) ### [CVE-2007-3327](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3327) ### Description httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space). ### POC #### Reference - http://securityreason.com/securityalert/2828 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3330 (2007/CVE-2007-3330.md) ### [CVE-2007-3330](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3330) ### Description Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is stored in news/ without sanitization. ### POC #### Reference - http://securityreason.com/securityalert/2829 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3331 (2007/CVE-2007-3331.md) ### [CVE-2007-3331](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3331) ### Description Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post. ### POC #### Reference - http://securityreason.com/securityalert/2829 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3332 (2007/CVE-2007-3332.md) ### [CVE-2007-3332](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3332) ### Description Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the name parameter in a modload action. ### POC #### Reference - http://securityreason.com/securityalert/2830 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3339 (2007/CVE-2007-3339.md) ### [CVE-2007-3339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3339) ### Description Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm. ### POC #### Reference - http://securityreason.com/securityalert/2842 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3340 (2007/CVE-2007-3340.md) ### [CVE-2007-3340](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3340) ### Description BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages. ### POC #### Reference - http://securityreason.com/securityalert/2822 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3342 (2007/CVE-2007-3342.md) ### [CVE-2007-3342](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3342) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Movable Type (MT) before 3.34 allow remote attackers to inject arbitrary web script or HTML via comments that have (1) a malformed SGML numeric character reference with a '\0' (0x00) character in a javascript: URI or (2) an attribute in an element that lacks the '>' character at the end of the start tag, a different vulnerability than CVE-2007-0231. ### POC #### Reference - http://securityreason.com/securityalert/2821 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3354 (2007/CVE-2007-3354.md) ### [CVE-2007-3354](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3354) ### Description Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978. ### POC #### Reference - http://securityreason.com/securityalert/2824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3355 (2007/CVE-2007-3355.md) ### [CVE-2007-3355](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3355) ### Description Multiple cross-site scripting (XSS) vulnerabilities in NetClassifieds Premium Edition allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3356 (2007/CVE-2007-3356.md) ### [CVE-2007-3356](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3356) ### Description NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of __FILE__ in error reporting by imageresizer.php; and (4) via certain requests that reveal the table name and complete query, related to the Halt_On_Error setting in Mysql_db.php. ### POC #### Reference - http://securityreason.com/securityalert/2824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3357 (2007/CVE-2007-3357.md) ### [CVE-2007-3357](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3357) ### Description NetClassifieds Premium Edition does not use encryption for (1) stored passwords or (2) sensitive data, which might allow attackers to obtain information via certain vectors. ### POC #### Reference - http://securityreason.com/securityalert/2824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3358 (2007/CVE-2007-3358.md) ### [CVE-2007-3358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3358) ### Description PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4089 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3360 (2007/CVE-2007-3360.md) ### [CVE-2007-3360](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3360) ### Description hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands. ### POC #### Reference - https://www.exploit-db.com/exploits/4087 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3364 (2007/CVE-2007-3364.md) ### [CVE-2007-3364](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3364) ### Description Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content. ### POC #### Reference - http://securityreason.com/securityalert/2823 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3365 (2007/CVE-2007-3365.md) ### [CVE-2007-3365](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3365) ### Description MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI. ### POC #### Reference - http://securityreason.com/securityalert/2827 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3370 (2007/CVE-2007-3370.md) ### [CVE-2007-3370](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3370) ### Description Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4091 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3371 (2007/CVE-2007-3371.md) ### [CVE-2007-3371](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3371) ### Description PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4090 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3372 (2007/CVE-2007-3372.md) ### [CVE-2007-3372](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3372) ### Description The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3374 (2007/CVE-2007-3374.md) ### [CVE-2007-3374](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3374) ### Description Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3375 (2007/CVE-2007-3375.md) ### [CVE-2007-3375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3375) ### Description Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper. ### POC #### Reference - http://vuln.sg/lhaca121-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3377 (2007/CVE-2007-3377.md) ### [CVE-2007-3377](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377) ### Description Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9904 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3378 (2007/CVE-2007-3378.md) ### [CVE-2007-3378](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3378) ### Description The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess. ### POC #### Reference - http://seclists.org/fulldisclosure/2020/Sep/34 - http://securityreason.com/achievement_exploitalert/9 - http://www.openwall.com/lists/oss-security/2020/09/17/3 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3380 (2007/CVE-2007-3380.md) ### [CVE-2007-3380](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3380) ### Description The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9337 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3382 (2007/CVE-2007-3382.md) ### [CVE-2007-3382](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382) ### Description Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3384 (2007/CVE-2007-3384.md) ### [CVE-2007-3384](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3384) ### Description Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages. ### POC #### Reference - http://securityreason.com/securityalert/2971 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3385 (2007/CVE-2007-3385.md) ### [CVE-2007-3385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385) ### Description Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9549 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3386 (2007/CVE-2007-3386.md) ### [CVE-2007-3386](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3386) ### Description Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3387 (2007/CVE-2007-3387.md) ### [CVE-2007-3387](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387) ### Description Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function. ### POC #### Reference - http://www.ubuntu.com/usn/usn-496-2 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 3388 (2007/CVE-2007-3388.md) ### [CVE-2007-3388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3388) ### Description Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9690 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3389 (2007/CVE-2007-3389.md) ### [CVE-2007-3389](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3389) ### Description Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9964 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3390 (2007/CVE-2007-3390.md) ### [CVE-2007-3390](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3390) ### Description Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10865 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3394 (2007/CVE-2007-3394.md) ### [CVE-2007-3394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3394) ### Description Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873. ### POC #### Reference - http://securityreason.com/securityalert/2839 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3396 (2007/CVE-2007-3396.md) ### [CVE-2007-3396](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3396) ### Description Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter. ### POC #### Reference - http://securityreason.com/securityalert/2840 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3398 (2007/CVE-2007-3398.md) ### [CVE-2007-3398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3398) ### Description LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages. ### POC #### Reference - http://securityreason.com/securityalert/2835 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3400 (2007/CVE-2007-3400.md) ### [CVE-2007-3400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3400) ### Description The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4101 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3401 (2007/CVE-2007-3401.md) ### [CVE-2007-3401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3401) ### Description PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4102 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3402 (2007/CVE-2007-3402.md) ### [CVE-2007-3402](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3402) ### Description SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action. ### POC #### Reference - https://www.exploit-db.com/exploits/4107 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3403 (2007/CVE-2007-3403.md) ### [CVE-2007-3403](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3403) ### Description Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4106 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3404 (2007/CVE-2007-3404.md) ### [CVE-2007-3404](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3404) ### Description Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4105 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3407 (2007/CVE-2007-3407.md) ### [CVE-2007-3407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3407) ### Description Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20). ### POC #### Reference - http://securityreason.com/securityalert/2832 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3410 (2007/CVE-2007-3410.md) ### [CVE-2007-3410](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3410) ### Description Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3425 (2007/CVE-2007-3425.md) ### [CVE-2007-3425](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3425) ### Description Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2. ### POC #### Reference - https://www.exploit-db.com/exploits/4100 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3426 (2007/CVE-2007-3426.md) ### [CVE-2007-3426](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3426) ### Description Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4100 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3427 (2007/CVE-2007-3427.md) ### [CVE-2007-3427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3427) ### Description SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action. ### POC #### Reference - https://www.exploit-db.com/exploits/4100 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3429 (2007/CVE-2007-3429.md) ### [CVE-2007-3429](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3429) ### Description Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg. ### POC #### Reference - https://www.exploit-db.com/exploits/4099 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3430 (2007/CVE-2007-3430.md) ### [CVE-2007-3430](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3430) ### Description SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action. ### POC #### Reference - https://www.exploit-db.com/exploits/4098 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3431 (2007/CVE-2007-3431.md) ### [CVE-2007-3431](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3431) ### Description PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4097 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3432 (2007/CVE-2007-3432.md) ### [CVE-2007-3432](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3432) ### Description Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename. ### POC #### Reference - https://www.exploit-db.com/exploits/4096 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3433 (2007/CVE-2007-3433.md) ### [CVE-2007-3433](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3433) ### Description SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action. ### POC #### Reference - https://www.exploit-db.com/exploits/4095 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3434 (2007/CVE-2007-3434.md) ### [CVE-2007-3434](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3434) ### Description index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message. ### POC #### Reference - https://www.exploit-db.com/exploits/4095 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3435 (2007/CVE-2007-3435.md) ### [CVE-2007-3435](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3435) ### Description Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument. ### POC #### Reference - https://www.exploit-db.com/exploits/4094 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3440 (2007/CVE-2007-3440.md) ### [CVE-2007-3440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3440) ### Description The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to place calls to arbitrary phone numbers via certain requests to the web server on port 1800. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3446 (2007/CVE-2007-3446.md) ### [CVE-2007-3446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3446) ### Description BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. ### POC #### Reference - https://www.exploit-db.com/exploits/4103 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3447 (2007/CVE-2007-3447.md) ### [CVE-2007-3447](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3447) ### Description SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4103 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3448 (2007/CVE-2007-3448.md) ### [CVE-2007-3448](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3448) ### Description Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4103 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3449 (2007/CVE-2007-3449.md) ### [CVE-2007-3449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3449) ### Description SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4104 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3451 (2007/CVE-2007-3451.md) ### [CVE-2007-3451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3451) ### Description PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4104 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3452 (2007/CVE-2007-3452.md) ### [CVE-2007-3452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3452) ### Description SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action. ### POC #### Reference - https://www.exploit-db.com/exploits/4108 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3453 (2007/CVE-2007-3453.md) ### [CVE-2007-3453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3453) ### Description SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid parameter to certain components. ### POC #### Reference - http://securityreason.com/securityalert/2843 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3456 (2007/CVE-2007-3456.md) ### [CVE-2007-3456](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3456) ### Description Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative. ### POC #### Reference - http://www.mindedsecurity.com/labs/advisories/MSA01110707 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3459 (2007/CVE-2007-3459.md) ### [CVE-2007-3459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3459) ### Description A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method. ### POC #### Reference - http://securityreason.com/securityalert/2844 - https://www.exploit-db.com/exploits/4110 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3460 (2007/CVE-2007-3460.md) ### [CVE-2007-3460](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3460) ### Description Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4112 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3461 (2007/CVE-2007-3461.md) ### [CVE-2007-3461](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3461) ### Description SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4114 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3462 (2007/CVE-2007-3462.md) ### [CVE-2007-3462](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3462) ### Description Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network. ### POC #### Reference - http://labs.calyptix.com/CX-2007-04.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3464 (2007/CVE-2007-3464.md) ### [CVE-2007-3464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3464) ### Description Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow attackers to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors. ### POC #### Reference - http://labs.calyptix.com/CX-2007-04.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3465 (2007/CVE-2007-3465.md) ### [CVE-2007-3465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3465) ### Description Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, has a certain default password. ### POC #### Reference - http://labs.calyptix.com/CX-2007-04.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3470 (2007/CVE-2007-3470.md) ### [CVE-2007-3470](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3470) ### Description Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9165 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3472 (2007/CVE-2007-3472.md) ### [CVE-2007-3472](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3472) ### Description Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0146.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3473 (2007/CVE-2007-3473.md) ### [CVE-2007-3473](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3473) ### Description The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0146.html #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 3475 (2007/CVE-2007-3475.md) ### [CVE-2007-3475](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3475) ### Description The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0146.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9728 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3476 (2007/CVE-2007-3476.md) ### [CVE-2007-3476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3476) ### Description Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0146.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3487 (2007/CVE-2007-3487.md) ### [CVE-2007-3487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3487) ### Description Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method. ### POC #### Reference - http://securityreason.com/securityalert/2846 - https://www.exploit-db.com/exploits/4119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3488 (2007/CVE-2007-3488.md) ### [CVE-2007-3488](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3488) ### Description Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method. ### POC #### Reference - https://www.exploit-db.com/exploits/4120 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3489 (2007/CVE-2007-3489.md) ### [CVE-2007-3489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3489) ### Description Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface. ### POC #### Reference - http://securityreason.com/securityalert/2848 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3490 (2007/CVE-2007-3490.md) ### [CVE-2007-3490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3490) ### Description Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls. ### POC #### Reference - http://pstgroup.blogspot.com/2007/06/exploitmicrosoft-excel-20002003-sheet.html - https://www.exploit-db.com/exploits/4121 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3491 (2007/CVE-2007-3491.md) ### [CVE-2007-3491](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3491) ### Description Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message. ### POC #### Reference - http://securityreason.com/securityalert/2851 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3492 (2007/CVE-2007-3492.md) ### [CVE-2007-3492](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3492) ### Description Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string containing "//A:" in the argument to the LIST command. ### POC #### Reference - http://securityreason.com/securityalert/2847 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3493 (2007/CVE-2007-3493.md) ### [CVE-2007-3493](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3493) ### Description A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400. ### POC #### Reference - https://www.exploit-db.com/exploits/4109 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3494 (2007/CVE-2007-3494.md) ### [CVE-2007-3494](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3494) ### Description Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users to (1) read the entire database by accessing the database backup plugin via a devtools/templates/newdump_backend.html argument in the template parameter to interna/plugin.php, (2) create plugins, (3) remove plugins, (4) enable debug mode, and have other unspecified impact. ### POC #### Reference - http://securityreason.com/securityalert/2853 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3495 (2007/CVE-2007-3495.md) ### [CVE-2007-3495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3495) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP Basis component 700 before SP12, and 640 before SP20, allow remote attackers to inject arbitrary web script or HTML via certain parameters associated with the default login error page. ### POC #### Reference - http://securityreason.com/securityalert/2849 - http://www.csnc.ch/advisory/sap02.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3496 (2007/CVE-2007-3496.md) ### [CVE-2007-3496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3496) ### Description Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. ### POC #### Reference - http://securityreason.com/securityalert/2850 - http://www.csnc.ch/advisory/sap01.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3500 (2007/CVE-2007-3500.md) ### [CVE-2007-3500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3500) ### Description Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie. ### POC #### Reference - http://securityreason.com/securityalert/2852 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3505 (2007/CVE-2007-3505.md) ### [CVE-2007-3505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3505) ### Description Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4115 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3507 (2007/CVE-2007-3507.md) ### [CVE-2007-3507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3507) ### Description Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length. ### POC #### Reference - http://securityreason.com/securityalert/2854 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3511 (2007/CVE-2007-3511.md) ### [CVE-2007-3511](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3511) ### Description The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9763 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3512 (2007/CVE-2007-3512.md) ### [CVE-2007-3512](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3512) ### Description Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375. ### POC #### Reference - http://vuln.sg/lhaca121-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3513 (2007/CVE-2007-3513.md) ### [CVE-2007-3513](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3513) ### Description The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption). ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9883 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3515 (2007/CVE-2007-3515.md) ### [CVE-2007-3515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3515) ### Description SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4130 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3518 (2007/CVE-2007-3518.md) ### [CVE-2007-3518](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3518) ### Description SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4136 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3519 (2007/CVE-2007-3519.md) ### [CVE-2007-3519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3519) ### Description SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4135 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3520 (2007/CVE-2007-3520.md) ### [CVE-2007-3520](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3520) ### Description SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4134 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3521 (2007/CVE-2007-3521.md) ### [CVE-2007-3521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3521) ### Description SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/4133 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3522 (2007/CVE-2007-3522.md) ### [CVE-2007-3522](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3522) ### Description Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4132 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3523 (2007/CVE-2007-3523.md) ### [CVE-2007-3523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3523) ### Description Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4131 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3524 (2007/CVE-2007-3524.md) ### [CVE-2007-3524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3524) ### Description Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4129 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3526 (2007/CVE-2007-3526.md) ### [CVE-2007-3526](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3526) ### Description Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4128 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3534 (2007/CVE-2007-3534.md) ### [CVE-2007-3534](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3534) ### Description SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4125 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3535 (2007/CVE-2007-3535.md) ### [CVE-2007-3535](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3535) ### Description Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4124 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3536 (2007/CVE-2007-3536.md) ### [CVE-2007-3536](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3536) ### Description Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values. ### POC #### Reference - https://www.exploit-db.com/exploits/4123 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3539 (2007/CVE-2007-3539.md) ### [CVE-2007-3539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3539) ### Description Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3. ### POC #### Reference - https://www.exploit-db.com/exploits/5222 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3542 (2007/CVE-2007-3542.md) ### [CVE-2007-3542](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3542) ### Description Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4096 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3543 (2007/CVE-2007-3543.md) ### [CVE-2007-3543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3543) ### Description Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php. ### POC #### Reference - http://www.buayacorp.com/files/wordpress/wordpress-advisory.html #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3544 (2007/CVE-2007-3544.md) ### [CVE-2007-3544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3544) ### Description Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543. ### POC #### Reference - http://www.buayacorp.com/files/wordpress/wordpress-advisory.html #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3547 (2007/CVE-2007-3547.md) ### [CVE-2007-3547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3547) ### Description Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4116 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3548 (2007/CVE-2007-3548.md) ### [CVE-2007-3548](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3548) ### Description Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file. ### POC #### Reference - https://www.exploit-db.com/exploits/4126 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3549 (2007/CVE-2007-3549.md) ### [CVE-2007-3549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3549) ### Description SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4127 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3550 (2007/CVE-2007-3550.md) ### [CVE-2007-3550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3550) ### Description Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated ### POC #### Reference - http://securityreason.com/securityalert/2855 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3555 (2007/CVE-2007-3555.md) ### [CVE-2007-3555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3555) ### Description Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424. ### POC #### Reference - http://securityreason.com/securityalert/2857 - http://securityvulns.ru/Rdocument391.html - http://tracker.moodle.org/browse/MDL-10341 - http://tracker.moodle.org/secure/IssueNavigator.jspa?mode=hide&requestId=10252 - http://websecurity.com.ua/1045/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3556 (2007/CVE-2007-3556.md) ### [CVE-2007-3556](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3556) ### Description Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc. ### POC #### Reference - http://securityreason.com/securityalert/2857 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3557 (2007/CVE-2007-3557.md) ### [CVE-2007-3557](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3557) ### Description SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter. ### POC #### Reference - http://securityreason.com/securityalert/2856 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3559 (2007/CVE-2007-3559.md) ### [CVE-2007-3559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3559) ### Description Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant. ### POC #### Reference - http://www.xssed.com/advisory/60/PHP-FUSION_FUSION_QUERY_Cross-Site_Scripting_Vulnerability/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3562 (2007/CVE-2007-3562.md) ### [CVE-2007-3562](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3562) ### Description SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4139 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3563 (2007/CVE-2007-3563.md) ### [CVE-2007-3563](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3563) ### Description SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4138 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3567 (2007/CVE-2007-3567.md) ### [CVE-2007-3567](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3567) ### Description MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests. ### POC #### Reference - http://securityreason.com/securityalert/2859 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3569 (2007/CVE-2007-3569.md) ### [CVE-2007-3569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3569) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform parameters to the (b) "Basic Search page"; and (8) username parameter when (c) logging on. ### POC #### Reference - http://securityreason.com/securityalert/2868 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3573 (2007/CVE-2007-3573.md) ### [CVE-2007-3573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3573) ### Description Multiple SQL injection vulnerabilities in akocomment allow remote attackers to execute arbitrary SQL commands via the (1) acparentid or (2) acitemid parameter to an unspecified component, different vectors than CVE-2006-1421. ### POC #### Reference - http://securityreason.com/securityalert/2860 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3574 (2007/CVE-2007-3574.md) ### [CVE-2007-3574](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3574) ### Description Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter. ### POC #### Reference - http://www.gnucitizen.org/blog/persistent-xss-and-csrf-on-wireless-g-adsl-gateway-with-speedbooster-wag54gs/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3575 (2007/CVE-2007-3575.md) ### [CVE-2007-3575](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3575) ### Description SQL injection vulnerability in includes/functions in FreeDomain.co.nr Clone allows remote attackers to execute arbitrary SQL commands via the logindomain parameter to members.php. ### POC #### Reference - http://securityreason.com/securityalert/2862 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3582 (2007/CVE-2007-3582.md) ### [CVE-2007-3582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3582) ### Description SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitrary SQL commands via the o parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4141 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3583 (2007/CVE-2007-3583.md) ### [CVE-2007-3583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3583) ### Description SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the idnew parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4142 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3584 (2007/CVE-2007-3584.md) ### [CVE-2007-3584](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3584) ### Description SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4147 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3585 (2007/CVE-2007-3585.md) ### [CVE-2007-3585](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3585) ### Description PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3586 (2007/CVE-2007-3586.md) ### [CVE-2007-3586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3586) ### Description Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files. ### POC #### Reference - https://www.exploit-db.com/exploits/4144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3587 (2007/CVE-2007-3587.md) ### [CVE-2007-3587](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3587) ### Description MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3588 (2007/CVE-2007-3588.md) ### [CVE-2007-3588](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3588) ### Description SQL injection vulnerability in reply.php in VBZooM 1.12 allows remote attackers to execute arbitrary SQL commands via the UserID parameter to sub-join.php. NOTE: this may be the same as CVE-2006-3691.4. ### POC #### Reference - http://securityreason.com/securityalert/2861 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3589 (2007/CVE-2007-3589.md) ### [CVE-2007-3589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3589) ### Description Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4122 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3590 (2007/CVE-2007-3590.md) ### [CVE-2007-3590](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3590) ### Description Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4122 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3597 (2007/CVE-2007-3597.md) ### [CVE-2007-3597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3597) ### Description Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter. ### POC #### Reference - http://securityreason.com/securityalert/2866 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3605 (2007/CVE-2007-3605.md) ### [CVE-2007-3605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3605) ### Description Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function. ### POC #### Reference - http://securityreason.com/securityalert/2873 - https://www.exploit-db.com/exploits/4148 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3606 (2007/CVE-2007-3606.md) ### [CVE-2007-3606](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3606) ### Description Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function. ### POC #### Reference - https://www.exploit-db.com/exploits/4149 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3607 (2007/CVE-2007-3607.md) ### [CVE-2007-3607](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3607) ### Description Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2873 - https://www.exploit-db.com/exploits/4148 - https://www.exploit-db.com/exploits/4149 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3608 (2007/CVE-2007-3608.md) ### [CVE-2007-3608](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3608) ### Description Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2873 - https://www.exploit-db.com/exploits/4148 - https://www.exploit-db.com/exploits/4149 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3609 (2007/CVE-2007-3609.md) ### [CVE-2007-3609](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3609) ### Description Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4154 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3610 (2007/CVE-2007-3610.md) ### [CVE-2007-3610](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3610) ### Description SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4153 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3611 (2007/CVE-2007-3611.md) ### [CVE-2007-3611](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3611) ### Description admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4150 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3612 (2007/CVE-2007-3612.md) ### [CVE-2007-3612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3612) ### Description Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command. ### POC #### Reference - https://www.exploit-db.com/exploits/4152 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3613 (2007/CVE-2007-3613.md) ### [CVE-2007-3613](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3613) ### Description Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. ### POC #### Reference - http://securityreason.com/securityalert/2865 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3614 (2007/CVE-2007-3614.md) ### [CVE-2007-3614](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3614) ### Description Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields." ### POC #### Reference - http://securityreason.com/securityalert/2867 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3619 (2007/CVE-2007-3619.md) ### [CVE-2007-3619](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3619) ### Description Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. ### POC #### Reference - http://securityreason.com/securityalert/2864 - http://www.netragard.com/pdfs/research/NETRAGARD-20070628-MAILGUARD.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3621 (2007/CVE-2007-3621.md) ### [CVE-2007-3621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3621) ### Description Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters. ### POC #### Reference - http://securityreason.com/securityalert/2863 - https://www.exploit-db.com/exploits/4151 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3630 (2007/CVE-2007-3630.md) ### [CVE-2007-3630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3630) ### Description changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4163 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3631 (2007/CVE-2007-3631.md) ### [CVE-2007-3631](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3631) ### Description SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field. ### POC #### Reference - https://www.exploit-db.com/exploits/4159 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3632 (2007/CVE-2007-3632.md) ### [CVE-2007-3632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3632) ### Description Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/. ### POC #### Reference - https://www.exploit-db.com/exploits/4156 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3633 (2007/CVE-2007-3633.md) ### [CVE-2007-3633](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3633) ### Description Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method. ### POC #### Reference - https://www.exploit-db.com/exploits/4160 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3639 (2007/CVE-2007-3639.md) ### [CVE-2007-3639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3639) ### Description WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php. ### POC #### Reference - http://securityreason.com/securityalert/2869 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 3640 (2007/CVE-2007-3640.md) ### [CVE-2007-3640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3640) ### Description Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent attackers to modify arbitrary files within an executing .air file (compiled AIR application) and perform cross-site scripting (XSS) attacks, as demonstrated by an application that modifies an HTML file inside itself via JavaScript that uses an APPEND open operation and the writeUTFBytes function. NOTE: this may be an intended consequence of the AIR permission model; if so, then perhaps this issue should not be included in CVE. ### POC #### Reference - http://securityreason.com/securityalert/2882 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3641 (2007/CVE-2007-3641.md) ### [CVE-2007-3641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3641) ### Description archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Hwangtaewon/radamsa - https://github.com/JulianDavis/radamsa - https://github.com/StephenHaruna/RADAMSA - https://github.com/marcostolosa/radamsa - https://github.com/nqwang/radamsa - https://github.com/sambacha/mirror-radamsa - https://github.com/sunzu94/radamsa-Fuzzer - https://github.com/vnc0/radamsa-ios --- ### 2007/CVE 2007 3644 (2007/CVE-2007-3644.md) ### [CVE-2007-3644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3644) ### Description archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Hwangtaewon/radamsa - https://github.com/JulianDavis/radamsa - https://github.com/StephenHaruna/RADAMSA - https://github.com/marcostolosa/radamsa - https://github.com/nqwang/radamsa - https://github.com/sambacha/mirror-radamsa - https://github.com/sunzu94/radamsa-Fuzzer - https://github.com/vnc0/radamsa-ios --- ### 2007/CVE 2007 3645 (2007/CVE-2007-3645.md) ### [CVE-2007-3645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3645) ### Description archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Hwangtaewon/radamsa - https://github.com/JulianDavis/radamsa - https://github.com/StephenHaruna/RADAMSA - https://github.com/marcostolosa/radamsa - https://github.com/nqwang/radamsa - https://github.com/sambacha/mirror-radamsa - https://github.com/sunzu94/radamsa-Fuzzer - https://github.com/vnc0/radamsa-ios --- ### 2007/CVE 2007 3646 (2007/CVE-2007-3646.md) ### [CVE-2007-3646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3646) ### Description SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action. ### POC #### Reference - https://www.exploit-db.com/exploits/4161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3647 (2007/CVE-2007-3647.md) ### [CVE-2007-3647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3647) ### Description The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the username cookie to "traffic." NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2870 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3648 (2007/CVE-2007-3648.md) ### [CVE-2007-3648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3648) ### Description SQL injection vulnerability in Webmatic before 2.6.2, and possibly other versions before 2.7, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly related to admin/admin_album.php and admin/admin_downloads.php. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2465 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3649 (2007/CVE-2007-3649.md) ### [CVE-2007-3649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3649) ### Description Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4155 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3655 (2007/CVE-2007-3655.md) ### [CVE-2007-3655](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3655) ### Description Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file. ### POC #### Reference - http://www.exploit-db.com/exploits/30284 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3656 (2007/CVE-2007-3656.md) ### [CVE-2007-3656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656) ### Description Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9105 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3657 (2007/CVE-2007-3657.md) ### [CVE-2007-3657](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3657) ### Description Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3658 (2007/CVE-2007-3658.md) ### [CVE-2007-3658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3658) ### Description Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3662 (2007/CVE-2007-3662.md) ### [CVE-2007-3662](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3662) ### Description Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FLV file. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3663 (2007/CVE-2007-3663.md) ### [CVE-2007-3663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3663) ### Description Divide-by-zero error in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted MPA file. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3665 (2007/CVE-2007-3665.md) ### [CVE-2007-3665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3665) ### Description Multiple unspecified vulnerabilities in FileBackup.DLL in Symantec Norton Ghost 12.0 allow remote attackers to cause a denial of service via unspecified vectors involving the UpdateCatalog and other functions. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3666 (2007/CVE-2007-3666.md) ### [CVE-2007-3666](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3666) ### Description Buffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function. ### POC #### Reference - http://www.securityfocus.com/archive/1/473212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3670 (2007/CVE-2007-3670.md) ### [CVE-2007-3670](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3670) ### Description Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data." ### POC #### Reference - http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/ - http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/ #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/b9q/EAOrigin_remote_code --- ### 2007/CVE 2007 3671 (2007/CVE-2007-3671.md) ### [CVE-2007-3671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3671) ### Description Unspecified vulnerability in the kernel in Microsoft Windows Vista has unspecified remote attack vectors and impact, as shown in the "0day IPO" presentation at SyScan'07. ### POC #### Reference - http://www.immunityinc.com/downloads/0day_IPO.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3675 (2007/CVE-2007-3675.md) ### [CVE-2007-3675](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3675) ### Description Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows. ### POC #### Reference - http://www.kaspersky.com/news?id=207575572 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3676 (2007/CVE-2007-3676.md) ### [CVE-2007-3676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3676) ### Description IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3678 (2007/CVE-2007-3678.md) ### [CVE-2007-3678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3678) ### Description Stack-based buffer overflow in the MSWord text-import extension (Word 6-2000 Filter.xnt) in QuarkXPress 7.2 for Windows, when using the Rectangle Text Box tool for importing text, allows user-assisted remote attackers to execute arbitrary code via a long font name. ### POC #### Reference - http://vuln.sg/quarkxpress72-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3681 (2007/CVE-2007-3681.md) ### [CVE-2007-3681](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3681) ### Description The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4165 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3682 (2007/CVE-2007-3682.md) ### [CVE-2007-3682](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3682) ### Description SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4167 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3683 (2007/CVE-2007-3683.md) ### [CVE-2007-3683](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3683) ### Description SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary SQL commands via the topic_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4164 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3687 (2007/CVE-2007-3687.md) ### [CVE-2007-3687](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3687) ### Description SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module, allows remote authenticated attackers to execute arbitrary SQL commands via the id parameter in a ScanMember do action. ### POC #### Reference - https://www.exploit-db.com/exploits/4166 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3697 (2007/CVE-2007-3697.md) ### [CVE-2007-3697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3697) ### Description PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2881 - https://www.exploit-db.com/exploits/4169 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3698 (2007/CVE-2007-3698.md) ### [CVE-2007-3698](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3698) ### Description The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sr-20070725-jsse.shtml - http://www.redhat.com/support/errata/RHSA-2008-0100.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3702 (2007/CVE-2007-3702.md) ### [CVE-2007-3702](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3702) ### Description Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action. ### POC #### Reference - https://www.exploit-db.com/exploits/4171 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3703 (2007/CVE-2007-3703.md) ### [CVE-2007-3703](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3703) ### Description Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. NOTE: this is probably a different issue than CVE-2007-2987. ### POC #### Reference - http://www.exploit-db.com/exploits/4170 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3718 (2007/CVE-2007-3718.md) ### [CVE-2007-3718](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3718) ### Description Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher. ### POC #### Reference - http://security-protocols.com/2007/06/12/safari-3-beta-released-on-windows/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3726 (2007/CVE-2007-3726.md) ### [CVE-2007-3726](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3726) ### Description Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number. ### POC #### Reference - http://securityreason.com/securityalert/2880 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3727 (2007/CVE-2007-3727.md) ### [CVE-2007-3727](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3727) ### Description Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the "administration area." ### POC #### Reference - http://www.vupen.com/english/advisories/2007/2465 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3738 (2007/CVE-2007-3738.md) ### [CVE-2007-3738](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738) ### Description Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9875 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3740 (2007/CVE-2007-3740.md) ### [CVE-2007-3740](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3740) ### Description The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9953 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3742 (2007/CVE-2007-3742.md) ### [CVE-2007-3742](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3742) ### Description WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike characters" (homographs) and possibly perform phishing attacks. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=3214 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3743 (2007/CVE-2007-3743.md) ### [CVE-2007-3743](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3743) ### Description Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=3214 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3768 (2007/CVE-2007-3768.md) ### [CVE-2007-3768](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3768) ### Description The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118409539009277&w=2 - http://securityreason.com/securityalert/2883 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3769 (2007/CVE-2007-3769.md) ### [CVE-2007-3769](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3769) ### Description Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=118409539009277&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3772 (2007/CVE-2007-3772.md) ### [CVE-2007-3772](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3772) ### Description Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4174 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3773 (2007/CVE-2007-3773.md) ### [CVE-2007-3773](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3773) ### Description Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators. ### POC #### Reference - http://chxsecurity.org/advisories/adv-2-mid.txt - http://securityreason.com/securityalert/2896 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3774 (2007/CVE-2007-3774.md) ### [CVE-2007-3774](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3774) ### Description Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb. ### POC #### Reference - http://securityreason.com/securityalert/2886 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3775 (2007/CVE-2007-3775.md) ### [CVE-2007-3775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3775) ### Description Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2) CSCsj19985. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070711-voip.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3776 (2007/CVE-2007-3776.md) ### [CVE-2007-3776](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3776) ### Description Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070711-voip.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3777 (2007/CVE-2007-3777.md) ### [CVE-2007-3777](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3777) ### Description avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges via arbitrary address arguments to a function provided by the 0x5348E004 IOCTL for the generic DeviceIoControl handler. ### POC #### Reference - http://securityreason.com/securityalert/2887 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3778 (2007/CVE-2007-3778.md) ### [CVE-2007-3778](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3778) ### Description The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the messageSignedText parameter to the gpg_check_sign_pgp_mime function in gpg_hook_functions.php. NOTE: a parameter value can be set in the contents of an e-mail message. ### POC #### Reference - http://www.attrition.org/pipermail/vim/2007-July/001704.html - http://www.attrition.org/pipermail/vim/2007-July/001710.html - https://exchange.xforce.ibmcloud.com/vulnerabilities/35363 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3781 (2007/CVE-2007-3781.md) ### [CVE-2007-3781](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3781) ### Description MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9195 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3786 (2007/CVE-2007-3786.md) ### [CVE-2007-3786](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3786) ### Description Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer ### POC #### Reference - http://labs.calyptix.com/CX-2007-05.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3787 (2007/CVE-2007-3787.md) ### [CVE-2007-3787](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3787) ### Description The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks. ### POC #### Reference - http://labs.calyptix.com/CX-2007-05.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3788 (2007/CVE-2007-3788.md) ### [CVE-2007-3788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3788) ### Description The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document. ### POC #### Reference - http://labs.calyptix.com/CX-2007-05.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3790 (2007/CVE-2007-3790.md) ### [CVE-2007-3790](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3790) ### Description The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument. ### POC #### Reference - https://www.exploit-db.com/exploits/4175 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3792 (2007/CVE-2007-3792.md) ### [CVE-2007-3792](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3792) ### Description Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/. ### POC #### Reference - http://securityreason.com/securityalert/2888 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3798 (2007/CVE-2007-3798.md) ### [CVE-2007-3798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798) ### Description Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=184815 - http://www.digit-labs.org/files/exploits/private/tcpdump-bgp.c - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9771 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3799 (2007/CVE-2007-3799.md) ### [CVE-2007-3799](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3799) ### Description The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9792 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3803 (2007/CVE-2007-3803.md) ### [CVE-2007-3803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3803) ### Description The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists. ### POC #### Reference - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_80_04.pdf - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_81_01.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3804 (2007/CVE-2007-3804.md) ### [CVE-2007-3804](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3804) ### Description The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files. ### POC #### Reference - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_80_04.pdf - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_81_01.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3805 (2007/CVE-2007-3805.md) ### [CVE-2007-3805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3805) ### Description The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates. ### POC #### Reference - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_80_04.pdf - http://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_81_01.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3806 (2007/CVE-2007-3806.md) ### [CVE-2007-3806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3806) ### Description The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure. ### POC #### Reference No PoCs from references. #### Github - https://github.com/LimeCola228/Nitro-Giveaway-Game-PHP - https://github.com/X1pe0/Nitro-Giveaway-Game-PHP --- ### 2007/CVE 2007 3807 (2007/CVE-2007-3807.md) ### [CVE-2007-3807](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3807) ### Description Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2893 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3808 (2007/CVE-2007-3808.md) ### [CVE-2007-3808](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3808) ### Description SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000. ### POC #### Reference - http://www.exploit-db.com/exploits/4186 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3809 (2007/CVE-2007-3809.md) ### [CVE-2007-3809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3809) ### Description Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4185 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3810 (2007/CVE-2007-3810.md) ### [CVE-2007-3810](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3810) ### Description SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4184 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3811 (2007/CVE-2007-3811.md) ### [CVE-2007-3811](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3811) ### Description Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4183 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3812 (2007/CVE-2007-3812.md) ### [CVE-2007-3812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3812) ### Description SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0707-exploits/cmscout.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3813 (2007/CVE-2007-3813.md) ### [CVE-2007-3813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3813) ### Description PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4180 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3814 (2007/CVE-2007-3814.md) ### [CVE-2007-3814](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3814) ### Description Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4179 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3815 (2007/CVE-2007-3815.md) ### [CVE-2007-3815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3815) ### Description Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment. ### POC #### Reference - http://securityreason.com/securityalert/2898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3821 (2007/CVE-2007-3821.md) ### [CVE-2007-3821](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3821) ### Description Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/2890 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3822 (2007/CVE-2007-3822.md) ### [CVE-2007-3822](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3822) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names. ### POC #### Reference - http://securityreason.com/securityalert/2890 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3823 (2007/CVE-2007-3823.md) ### [CVE-2007-3823](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3823) ### Description The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string to port 5151/udp. ### POC #### Reference - http://packetstormsecurity.org/0707-advisories/wsftp75290-dos.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3824 (2007/CVE-2007-3824.md) ### [CVE-2007-3824](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3824) ### Description SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter. ### POC #### Reference - http://www.packetstormsecurity.org/0707-exploits/mzkblog-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3826 (2007/CVE-2007-3826.md) ### [CVE-2007-3826](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3826) ### Description Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before the onBeforeUnload function is called. ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3829 (2007/CVE-2007-3829.md) ### [CVE-2007-3829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3829) ### Description Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL attribute in the IAMCE ActiveX Control (IAMCE.dll) or a (2) long URLCode attribute in the IAKey ActiveX Control (IAKey.dll). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3830 (2007/CVE-2007-3830.md) ### [CVE-2007-3830](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3830) ### Description Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2007/CVE 2007 3831 (2007/CVE-2007-3831.md) ### [CVE-2007-3831](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3831) ### Description PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2007/CVE 2007 3834 (2007/CVE-2007-3834.md) ### [CVE-2007-3834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3834) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a URL that can be discovered through a keyword search. NOTE: this may be related to the MetaLib XSS issue, CVE-2007-3835. ### POC #### Reference - http://securityreason.com/securityalert/2889 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3835 (2007/CVE-2007-3835.md) ### [CVE-2007-3835](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3835) ### Description Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search. ### POC #### Reference - http://securityreason.com/securityalert/2889 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3840 (2007/CVE-2007-3840.md) ### [CVE-2007-3840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3840) ### Description SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL commands via the offset parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4187 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3843 (2007/CVE-2007-3843.md) ### [CVE-2007-3843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3843) ### Description The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9670 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3844 (2007/CVE-2007-3844.md) ### [CVE-2007-3844](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844) ### Description Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9493 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3846 (2007/CVE-2007-3846.md) ### [CVE-2007-3846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3846) ### Description Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository. ### POC #### Reference - http://crisp.cs.du.edu/?q=node/36 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3847 (2007/CVE-2007-3847.md) ### [CVE-2007-3847](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3847) ### Description The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read. ### POC #### Reference - http://www-1.ibm.com/support/docview.wss?uid=swg1PK50469 - http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html - http://www.vupen.com/english/advisories/2008/1697 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/Live-Hack-CVE/CVE-2007-3847 - https://github.com/kasem545/vulnsearch --- ### 2007/CVE 2007 3852 (2007/CVE-2007-3852.md) ### [CVE-2007-3852](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3852) ### Description The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code. ### POC #### Reference - https://bugs.gentoo.org/show_bug.cgi?id=188808 #### Github - https://github.com/lucassbeiler/linux_hardening_arsenal --- ### 2007/CVE 2007 3871 (2007/CVE-2007-3871.md) ### [CVE-2007-3871](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3871) ### Description Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of service (stamp invalidation) via a SOAP request with an id value for a stamp that has not yet been printed. ### POC #### Reference - http://securityreason.com/securityalert/3129 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3876 (2007/CVE-2007-3876.md) ### [CVE-2007-3876](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3876) ### Description Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long workgroup (-W) option to mount_smbfs or (2) an unspecified manipulation of the command line to smbutil. ### POC #### Reference - https://www.exploit-db.com/exploits/4759 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3881 (2007/CVE-2007-3881.md) ### [CVE-2007-3881](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3881) ### Description SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrary SQL commands via the msgid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4191 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3882 (2007/CVE-2007-3882.md) ### [CVE-2007-3882](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3882) ### Description SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4189 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3883 (2007/CVE-2007-3883.md) ### [CVE-2007-3883](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3883) ### Description The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method. ### POC #### Reference - https://www.exploit-db.com/exploits/4190 - https://www.exploit-db.com/exploits/5395 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3887 (2007/CVE-2007-3887.md) ### [CVE-2007-3887](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3887) ### Description Multiple cross-site scripting (XSS) vulnerabilities in mesaj_formu.asp in ASP Ziyaretci Defteri 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Isim, (2) Mesajiniz, and (3) E-posta fields. NOTE: these probably correspond to the isim, mesaj, and posta parameters to save.php. ### POC #### Reference - http://www.packetstormsecurity.org/0707-exploits/aspziy-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3889 (2007/CVE-2007-3889.md) ### [CVE-2007-3889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3889) ### Description Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/5774 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3890 (2007/CVE-2007-3890.md) ### [CVE-2007-3890](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3890) ### Description Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-044 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3891 (2007/CVE-2007-3891.md) ### [CVE-2007-3891](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3891) ### Description Unspecified vulnerability in Windows Vista Weather Gadgets in Windows Vista allows remote attackers to execute arbitrary code via crafted HTML attributes. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-048 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3892 (2007/CVE-2007-3892.md) ### [CVE-2007-3892](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3892) ### Description Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826. ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3893 (2007/CVE-2007-3893.md) ### [CVE-2007-3893](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3893) ### Description Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error. ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3895 (2007/CVE-2007-3895.md) ### [CVE-2007-3895](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3895) ### Description Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-064 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3896 (2007/CVE-2007-3896.md) ### [CVE-2007-3896](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3896) ### Description The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers. ### POC #### Reference - http://www.heise-security.co.uk/news/96982 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3897 (2007/CVE-2007-3897.md) ### [CVE-2007-3897](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3897) ### Description Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption. ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-056 #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2007/CVE 2007 3898 (2007/CVE-2007-3898.md) ### [CVE-2007-3898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3898) ### Description The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors. ### POC #### Reference - http://securityreason.com/securityalert/3373 - http://www.trusteer.com/docs/windowsdns.html - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3899 (2007/CVE-2007-3899.md) ### [CVE-2007-3899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3899) ### Description Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability." ### POC #### Reference - http://www.securityfocus.com/archive/1/482366/100/0/threaded #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3901 (2007/CVE-2007-3901.md) ### [CVE-2007-3901](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3901) ### Description Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-064 - https://www.exploit-db.com/exploits/4866 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3902 (2007/CVE-2007-3902.md) ### [CVE-2007-3902](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3902) ### Description Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3903 (2007/CVE-2007-3903.md) ### [CVE-2007-3903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3903) ### Description Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344, a variant of "Uninitialized Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3907 (2007/CVE-2007-3907.md) ### [CVE-2007-3907](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3907) ### Description Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=523576&group_id=175965 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3912 (2007/CVE-2007-3912.md) ### [CVE-2007-3912](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3912) ### Description checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process. ### POC #### Reference - http://www.ubuntu.com/usn/usn-526-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3919 (2007/CVE-2007-3919.md) ### [CVE-2007-3919](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3919) ### Description (1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9913 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3923 (2007/CVE-2007-3923.md) ### [CVE-2007-3923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3923) ### Description The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070718-waas.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3927 (2007/CVE-2007-3927.md) ### [CVE-2007-3927](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3927) ### Description Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3928 (2007/CVE-2007-3928.md) ### [CVE-2007-3928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3928) ### Description Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638. ### POC #### Reference - http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064669.html - http://securityreason.com/securityalert/2906 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3931 (2007/CVE-2007-3931.md) ### [CVE-2007-3931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3931) ### Description The wrap_setuid_third_party_application function in the installation script for the Samsung SCX-4200 Driver 2.00.95 adds setuid permissions to third party applications such as xsane and xscanimage, which allows local users to gain privileges. ### POC #### Reference - http://linuxfr.org/forums/15/22562.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3932 (2007/CVE-2007-3932.md) ### [CVE-2007-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3932) ### Description uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder. ### POC #### Reference - https://www.exploit-db.com/exploits/4194 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3933 (2007/CVE-2007-3933.md) ### [CVE-2007-3933](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3933) ### Description SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053. ### POC #### Reference - https://www.exploit-db.com/exploits/4193 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3934 (2007/CVE-2007-3934.md) ### [CVE-2007-3934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3934) ### Description PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL in the p_mode parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4195 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3935 (2007/CVE-2007-3935.md) ### [CVE-2007-3935](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3935) ### Description PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4197 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3936 (2007/CVE-2007-3936.md) ### [CVE-2007-3936](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3936) ### Description Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filename references in the delfiles parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4198 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3937 (2007/CVE-2007-3937.md) ### [CVE-2007-3937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3937) ### Description Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4198 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3938 (2007/CVE-2007-3938.md) ### [CVE-2007-3938](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3938) ### Description SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676. ### POC #### Reference - https://www.exploit-db.com/exploits/4199 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3939 (2007/CVE-2007-3939.md) ### [CVE-2007-3939](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3939) ### Description SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4192 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3940 (2007/CVE-2007-3940.md) ### [CVE-2007-3940](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3940) ### Description Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search action. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://packetstormsecurity.org/0707-advisories/quickersite-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3944 (2007/CVE-2007-3944.md) ### [CVE-2007-3944](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3944) ### Description Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone. NOTE: it is not clear whether this stems from an issue in the original distribution of PCRE, which might already have a separate CVE identifier. ### POC #### Reference - http://www.nytimes.com/2007/07/23/technology/23iphone.html?_r=1&adxnnl=1&adxnnlx=1185163364-1OTsRJvbylLamj17FY2wnw&oref=slogin #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3947 (2007/CVE-2007-3947.md) ### [CVE-2007-3947](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3947) ### Description request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 3951 (2007/CVE-2007-3951.md) ### [CVE-2007-3951](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3951) ### Description Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around." ### POC #### Reference - http://securityreason.com/securityalert/2912 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3952 (2007/CVE-2007-3952.md) ### [CVE-2007-3952](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3952) ### Description The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an "integer cast around". ### POC #### Reference - http://securityreason.com/securityalert/2913 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3953 (2007/CVE-2007-3953.md) ### [CVE-2007-3953](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3953) ### Description The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to cause a denial of service via a crafted DOC file that triggers a divide-by-zero error. ### POC #### Reference - http://securityreason.com/securityalert/2914 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3955 (2007/CVE-2007-3955.md) ### [CVE-2007-3955](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3955) ### Description Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3956 (2007/CVE-2007-3956.md) ### [CVE-2007-3956](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3956) ### Description TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534. ### POC #### Reference - https://www.exploit-db.com/exploits/4205 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3957 (2007/CVE-2007-3957.md) ### [CVE-2007-3957](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3957) ### Description Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. ### POC #### Reference - https://www.exploit-db.com/exploits/4216 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3958 (2007/CVE-2007-3958.md) ### [CVE-2007-3958](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3958) ### Description Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif. ### POC #### Reference - http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html - https://www.exploit-db.com/exploits/4215 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3963 (2007/CVE-2007-3963.md) ### [CVE-2007-3963](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3963) ### Description Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193. ### POC #### Reference - http://securityreason.com/securityalert/2915 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3969 (2007/CVE-2007-3969.md) ### [CVE-2007-3969](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3969) ### Description Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from an "Integer Cast Around." ### POC #### Reference - http://securityreason.com/securityalert/2920 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3970 (2007/CVE-2007-3970.md) ### [CVE-2007-3970](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3970) ### Description Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption. ### POC #### Reference - http://securityreason.com/securityalert/2922 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3971 (2007/CVE-2007-3971.md) ### [CVE-2007-3971](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3971) ### Description Integer overflow in ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted ASPACK packed file, which triggers an infinite loop. ### POC #### Reference - http://securityreason.com/securityalert/2923 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3972 (2007/CVE-2007-3972.md) ### [CVE-2007-3972](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3972) ### Description ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error. ### POC #### Reference - http://securityreason.com/securityalert/2924 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3973 (2007/CVE-2007-3973.md) ### [CVE-2007-3973](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3973) ### Description Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4211 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3974 (2007/CVE-2007-3974.md) ### [CVE-2007-3974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3974) ### Description admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4211 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3975 (2007/CVE-2007-3975.md) ### [CVE-2007-3975](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3975) ### Description Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vulnerability than CVE-2005-3412. ### POC #### Reference - http://securityreason.com/securityalert/2933 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3976 (2007/CVE-2007-3976.md) ### [CVE-2007-3976](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3976) ### Description SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the newsID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4213 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3977 (2007/CVE-2007-3977.md) ### [CVE-2007-3977](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3977) ### Description Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4213 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3978 (2007/CVE-2007-3978.md) ### [CVE-2007-3978](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3978) ### Description Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4213 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3979 (2007/CVE-2007-3979.md) ### [CVE-2007-3979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3979) ### Description SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4206 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3980 (2007/CVE-2007-3980.md) ### [CVE-2007-3980](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3980) ### Description PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4210 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3981 (2007/CVE-2007-3981.md) ### [CVE-2007-3981](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3981) ### Description SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL commands via the catid parameter in a displaycat action. ### POC #### Reference - https://www.exploit-db.com/exploits/4209 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3982 (2007/CVE-2007-3982.md) ### [CVE-2007-3982](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3982) ### Description Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method. ### POC #### Reference - https://www.exploit-db.com/exploits/4208 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3984 (2007/CVE-2007-3984.md) ### [CVE-2007-3984](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3984) ### Description Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to execute arbitrary code via a long argument to the Scan method. NOTE: this is probably a different issue than CVE-2007-2987. ### POC #### Reference - https://www.exploit-db.com/exploits/4214 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3988 (2007/CVE-2007-3988.md) ### [CVE-2007-3988](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3988) ### Description Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. ### POC #### Reference - http://securityreason.com/securityalert/2926 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3996 (2007/CVE-2007-3996.md) ### [CVE-2007-3996](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3996) ### Description Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function. ### POC #### Reference - http://securityreason.com/securityalert/3103 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 3997 (2007/CVE-2007-3997.md) ### [CVE-2007-3997](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3997) ### Description The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE. ### POC #### Reference - http://securityreason.com/securityalert/3102 - https://www.exploit-db.com/exploits/4392 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 3999 (2007/CVE-2007-3999.md) ### [CVE-2007-3999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999) ### Description Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message. ### POC #### Reference - http://securityreason.com/securityalert/3092 - http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9379 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4000 (2007/CVE-2007-4000.md) ### [CVE-2007-4000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4000) ### Description The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer. ### POC #### Reference - http://securityreason.com/securityalert/3092 - http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-006.txt - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9278 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4005 (2007/CVE-2007-4005.md) ### [CVE-2007-4005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4005) ### Description Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the shell port (514/tcp). NOTE: this might overlap CVE-2007-4006. ### POC #### Reference - https://www.exploit-db.com/exploits/4222 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4007 (2007/CVE-2007-4007.md) ### [CVE-2007-4007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4007) ### Description PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4221 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4008 (2007/CVE-2007-4008.md) ### [CVE-2007-4008](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4008) ### Description Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4220 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4009 (2007/CVE-2007-4009.md) ### [CVE-2007-4009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4009) ### Description PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4219 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4010 (2007/CVE-2007-4010.md) ### [CVE-2007-4010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4010) ### Description The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function. ### POC #### Reference - https://www.exploit-db.com/exploits/4218 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4014 (2007/CVE-2007-4014.md) ### [CVE-2007-4014](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4014) ### Description Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4022 (2007/CVE-2007-4022.md) ### [CVE-2007-4022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4022) ### Description Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter. ### POC #### Reference - http://securityreason.com/securityalert/2930 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4029 (2007/CVE-2007-4029.md) ### [CVE-2007-4029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4029) ### Description libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4031 (2007/CVE-2007-4031.md) ### [CVE-2007-4031](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4031) ### Description Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. ### POC #### Reference - https://www.exploit-db.com/exploits/4230 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4032 (2007/CVE-2007-4032.md) ### [CVE-2007-4032](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4032) ### Description Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file. ### POC #### Reference - https://www.exploit-db.com/exploits/4229 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4033 (2007/CVE-2007-4033.md) ### [CVE-2007-4033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4033) ### Description Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3. ### POC #### Reference - https://www.exploit-db.com/exploits/4227 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4038 (2007/CVE-2007-4038.md) ### [CVE-2007-4038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4038) ### Description Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking Thunderbird.exe, a similar issue to CVE-2007-3670. ### POC #### Reference - http://seclists.org/fulldisclosure/2007/Jul/0557.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4039 (2007/CVE-2007-4039.md) ### [CVE-2007-4039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4039) ### Description Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670. ### POC #### Reference - http://seclists.org/fulldisclosure/2007/Jul/0557.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4040 (2007/CVE-2007-4040.md) ### [CVE-2007-4040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4040) ### Description Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670. ### POC #### Reference - http://seclists.org/fulldisclosure/2007/Jul/0557.html #### Github - https://github.com/GuiMatosInfra/explorer2sectool - https://github.com/xaitax/SploitScan --- ### 2007/CVE 2007 4045 (2007/CVE-2007-4045.md) ### [CVE-2007-4045](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4045) ### Description The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_14_sr.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9303 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4046 (2007/CVE-2007-4046.md) ### [CVE-2007-4046](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4046) ### Description SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4201 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4047 (2007/CVE-2007-4047.md) ### [CVE-2007-4047](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4047) ### Description geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified impact via a request with a valid id parameter. ### POC #### Reference - http://securityreason.com/securityalert/2934 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4050 (2007/CVE-2007-4050.md) ### [CVE-2007-4050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4050) ### Description Unspecified vulnerability in WebUI in ADempiere Bazaar before 3.3 beta Victoria edition allows remote attackers to access system-level windows via unspecified vectors. ### POC #### Reference - http://sourceforge.net/tracker/index.php?func=detail&aid=1745707&group_id=176962&atid=879334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4053 (2007/CVE-2007-4053.md) ### [CVE-2007-4053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4053) ### Description SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the order parameter to new_images.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4242 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4054 (2007/CVE-2007-4054.md) ### [CVE-2007-4054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4054) ### Description SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4241 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4055 (2007/CVE-2007-4055.md) ### [CVE-2007-4055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4055) ### Description SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this may be related to CVE-2006-4300. ### POC #### Reference - https://www.exploit-db.com/exploits/4239 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4056 (2007/CVE-2007-4056.md) ### [CVE-2007-4056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4056) ### Description SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect. ### POC #### Reference - https://www.exploit-db.com/exploits/4238 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4057 (2007/CVE-2007-4057.md) ### [CVE-2007-4057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4057) ### Description Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png. ### POC #### Reference - https://www.exploit-db.com/exploits/4235 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4058 (2007/CVE-2007-4058.md) ### [CVE-2007-4058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4058) ### Description Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method. ### POC #### Reference - https://www.exploit-db.com/exploits/4244 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4059 (2007/CVE-2007-4059.md) ### [CVE-2007-4059](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4059) ### Description Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SetLogFileName method. ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html - https://www.exploit-db.com/exploits/4240 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4060 (2007/CVE-2007-4060.md) ### [CVE-2007-4060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4060) ### Description Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code via a long string in the (1) method name or (2) URI in an HTTP request. ### POC #### Reference - https://www.exploit-db.com/exploits/4243 #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 4061 (2007/CVE-2007-4061.md) ### [CVE-2007-4061](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4061) ### Description Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. NOTE: this can be leveraged for code execution by writing to a Startup folder. ### POC #### Reference - https://www.exploit-db.com/exploits/4237 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4065 (2007/CVE-2007-4065.md) ### [CVE-2007-4065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4065) ### Description lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9173 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4067 (2007/CVE-2007-4067.md) ### [CVE-2007-4067](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4067) ### Description Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4226 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4068 (2007/CVE-2007-4068.md) ### [CVE-2007-4068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4068) ### Description Multiple SQL injection vulnerabilities in Webyapar 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the kat_id parameter to the default URI in a download action or (2) the id parameter to the default URI in a duyurular_detay action. ### POC #### Reference - https://www.exploit-db.com/exploits/4224 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4069 (2007/CVE-2007-4069.md) ### [CVE-2007-4069](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4069) ### Description SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4225 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4070 (2007/CVE-2007-4070.md) ### [CVE-2007-4070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4070) ### Description Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8334 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4071 (2007/CVE-2007-4071.md) ### [CVE-2007-4071](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4071) ### Description Multiple cross-site scripting (XSS) vulnerabilities in uploader/index.php in Webbler CMS before 3.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) login parameter. ### POC #### Reference - http://securityreason.com/securityalert/2946 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4093 (2007/CVE-2007-4093.md) ### [CVE-2007-4093](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4093) ### Description Minb Is Not a Blog (minb) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing usernames and encrypted passwords via a direct request for db/users.db. ### POC #### Reference - http://securityreason.com/securityalert/2931 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4094 (2007/CVE-2007-4094.md) ### [CVE-2007-4094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4094) ### Description PHP remote file inclusion vulnerability in library/authorize.php in IDevSpot PhpHostBot allows remote attackers to execute arbitrary PHP code via a URL in the login_form parameter, a different vector than CVE-2006-3776. ### POC #### Reference - http://securityreason.com/securityalert/2932 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4095 (2007/CVE-2007-4095.md) ### [CVE-2007-4095](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4095) ### Description SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp. ### POC #### Reference - http://securityreason.com/securityalert/2935 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4101 (2007/CVE-2007-4101.md) ### [CVE-2007-4101](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4101) ### Description Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php. ### POC #### Reference - http://securityreason.com/securityalert/2937 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4102 (2007/CVE-2007-4102.md) ### [CVE-2007-4102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4102) ### Description Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/> sequence in the search string. ### POC #### Reference - http://securityreason.com/securityalert/2942 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4104 (2007/CVE-2007-4104.md) ### [CVE-2007-4104](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4104) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4105 (2007/CVE-2007-4105.md) ### [CVE-2007-4105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4105) ### Description A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4108 (2007/CVE-2007-4108.md) ### [CVE-2007-4108](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4108) ### Description SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. ### POC #### Reference - http://securityreason.com/securityalert/2948 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4109 (2007/CVE-2007-4109.md) ### [CVE-2007-4109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4109) ### Description SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. ### POC #### Reference - http://securityreason.com/securityalert/2947 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4110 (2007/CVE-2007-4110.md) ### [CVE-2007-4110](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4110) ### Description SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter. ### POC #### Reference - http://securityreason.com/securityalert/2936 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4111 (2007/CVE-2007-4111.md) ### [CVE-2007-4111](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4111) ### Description SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. ### POC #### Reference - http://securityreason.com/securityalert/2949 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4114 (2007/CVE-2007-4114.md) ### [CVE-2007-4114](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4114) ### Description Multiple SQL injection vulnerabilities in unuttum.asp in SuskunDuygular Uyelik Sistemi 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) kadi or (2) email parameter. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2945 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4115 (2007/CVE-2007-4115.md) ### [CVE-2007-4115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4115) ### Description Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php. ### POC #### Reference - http://securityreason.com/securityalert/2953 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4117 (2007/CVE-2007-4117.md) ### [CVE-2007-4117](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4117) ### Description PHP remote file inclusion vulnerability in index.php in phpWebFileManager 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the PN_PathPrefix parameter. NOTE: this issue is disputed by a reliable third party, who demonstrates that PN_PathPrefix is defined before use ### POC #### Reference - http://securityreason.com/securityalert/2940 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4118 (2007/CVE-2007-4118.md) ### [CVE-2007-4118](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4118) ### Description PHP remote file inclusion vulnerability in includes/functions.inc.php in phpVoter 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. ### POC #### Reference - http://securityreason.com/securityalert/2939 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4119 (2007/CVE-2007-4119.md) ### [CVE-2007-4119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4119) ### Description Multiple SQL injection vulnerabilities in yonetici.asp in Berthanas Ziyaretci Defteri 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) Pass fields. ### POC #### Reference - http://securityreason.com/securityalert/2943 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4120 (2007/CVE-2007-4120.md) ### [CVE-2007-4120](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4120) ### Description Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) specialtemplates parameter to includes/functions_forumdisplay.php. NOTE: this issue is disputed by a reliable third party who states "further investigation has revealed that the application is not vulnerable to this issue." The original researcher also has a history of erroneous claims ### POC #### Reference - http://securityreason.com/securityalert/2941 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4121 (2007/CVE-2007-4121.md) ### [CVE-2007-4121](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4121) ### Description Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/2944 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4126 (2007/CVE-2007-4126.md) ### [CVE-2007-4126](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4126) ### Description Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9039 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4127 (2007/CVE-2007-4127.md) ### [CVE-2007-4127](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4127) ### Description PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0 ### POC #### Reference - http://securityreason.com/securityalert/2938 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4128 (2007/CVE-2007-4128.md) ### [CVE-2007-4128](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4128) ### Description SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action. ### POC #### Reference - https://www.exploit-db.com/exploits/4248 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4135 (2007/CVE-2007-4135.md) ### [CVE-2007-4135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4135) ### Description The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9864 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4136 (2007/CVE-2007-4136.md) ### [CVE-2007-4136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4136) ### Description The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9871 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4138 (2007/CVE-2007-4138.md) ### [CVE-2007-4138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138) ### Description The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined. ### POC #### Reference - http://securityreason.com/securityalert/3135 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4139 (2007/CVE-2007-4139.md) ### [CVE-2007-4139](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4139) ### Description Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4140 (2007/CVE-2007-4140.md) ### [CVE-2007-4140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4140) ### Description Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary code via a .mpr file (replay file) that contains a long car name. ### POC #### Reference - https://www.exploit-db.com/exploits/4252 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4145 (2007/CVE-2007-4145.md) ### [CVE-2007-4145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4145) ### Description Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method. ### POC #### Reference - http://securityreason.com/securityalert/2959 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4153 (2007/CVE-2007-4153.md) ### [CVE-2007-4153](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4153) ### Description Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4154 (2007/CVE-2007-4154.md) ### [CVE-2007-4154](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4154) ### Description SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4155 (2007/CVE-2007-4155.md) ### [CVE-2007-4155](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4155) ### Description Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method. ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html - https://www.exploit-db.com/exploits/4245 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4156 (2007/CVE-2007-4156.md) ### [CVE-2007-4156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4156) ### Description Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid variable), and possibly the (3) pwd parameter, to admin/index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4246 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4165 (2007/CVE-2007-4165.md) ### [CVE-2007-4165](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4165) ### Description Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757 and CVE-2007-4014. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4166 (2007/CVE-2007-4166.md) ### [CVE-2007-4166](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4166) ### Description Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757, CVE-2007-4014, and CVE-2007-4165. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4171 (2007/CVE-2007-4171.md) ### [CVE-2007-4171](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4171) ### Description SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4254 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4180 (2007/CVE-2007-4180.md) ### [CVE-2007-4180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4180) ### Description Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbitrary local files via a .. (dot dot) in the file parameter. NOTE: CVE and a reliable third party dispute this vulnerability because the code uses a fixed argument when invoking fputs, which cannot be used to read files ### POC #### Reference - http://securityreason.com/securityalert/2973 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4181 (2007/CVE-2007-4181.md) ### [CVE-2007-4181](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4181) ### Description PHP remote file inclusion vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: A reliable third party disputes this vulnerability because the applicable include is within a function that does not receive the dir parameter from an HTTP request ### POC #### Reference - http://securityreason.com/securityalert/2973 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4182 (2007/CVE-2007-4182.md) ### [CVE-2007-4182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4182) ### Description Unrestricted file upload vulnerability in index.php in WikiWebWeaver 1.1 and earlier allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .gif.php, which is accessible from data/documents/. ### POC #### Reference - http://securityreason.com/securityalert/2972 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4183 (2007/CVE-2007-4183.md) ### [CVE-2007-4183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4183) ### Description SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4253 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4186 (2007/CVE-2007-4186.md) ### [CVE-2007-4186](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4186) ### Description PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/2979 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4187 (2007/CVE-2007-4187.md) ### [CVE-2007-4187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4187) ### Description Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1) components/com_search/views/search/tmpl/ and (2) templates/beez/html/com_search/search/. ### POC #### Reference - http://securityreason.com/securityalert/2969 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4188 (2007/CVE-2007-4188.md) ### [CVE-2007-4188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4188) ### Description Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/p1ay8y3ar/cve_monitor --- ### 2007/CVE 2007 4189 (2007/CVE-2007-4189.md) ### [CVE-2007-4189](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4189) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search, (2) com_content, and (3) mod_login components. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/p1ay8y3ar/cve_monitor --- ### 2007/CVE 2007 4190 (2007/CVE-2007-4190.md) ### [CVE-2007-4190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4190) ### Description CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/p1ay8y3ar/cve_monitor --- ### 2007/CVE 2007 4191 (2007/CVE-2007-4191.md) ### [CVE-2007-4191](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4191) ### Description Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657. ### POC #### Reference - http://securityreason.com/securityalert/2968 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4195 (2007/CVE-2007-4195.md) ### [CVE-2007-4195](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4195) ### Description Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain ext2fs files via a malformed ext2fs image. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4196 (2007/CVE-2007-4196.md) ### [CVE-2007-4196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4196) ### Description icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 misinterprets a certain memory location as the holder of a loop iteration count, which allows user-assisted remote attackers to cause a denial of service (long loop) and prevent examination of certain NTFS files via a malformed NTFS image. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4197 (2007/CVE-2007-4197.md) ### [CVE-2007-4197](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4197) ### Description icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 omits NULL pointer checks in certain code paths, which allows user-assisted remote attackers to cause a denial of service (NULL dereference and application crash) and prevent examination of certain NTFS files via a malformed NTFS image. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4198 (2007/CVE-2007-4198.md) ### [CVE-2007-4198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4198) ### Description The fs_data_put_str function in ntfs.c in fls in Brian Carrier The Sleuth Kit (TSK) before 2.09 does not validate a certain length value, which allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files via a malformed NTFS image, which triggers a buffer over-read. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4199 (2007/CVE-2007-4199.md) ### [CVE-2007-4199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4199) ### Description Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files via a malformed NTFS image that triggers (1) dereference of a certain integer value by ntfs_dent.c in fls, or (2) dereference of a certain other integer value by ntfs.c in fsstat. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4200 (2007/CVE-2007-4200.md) ### [CVE-2007-4200](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4200) ### Description ntfs.c in fsstat in Brian Carrier The Sleuth Kit (TSK) before 2.09 interprets a certain variable as a byte count rather than a count of 32-bit integers, which allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files via a malformed NTFS image. ### POC #### Reference - http://sourceforge.net/mailarchive/message.php?msg_name=A19F11EF-13CA-4940-AFF3-9BE08F67EE22%40sleuthkit.org #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4203 (2007/CVE-2007-4203.md) ### [CVE-2007-4203](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4203) ### Description Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter. ### POC #### Reference - http://securityreason.com/securityalert/2970 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4205 (2007/CVE-2007-4205.md) ### [CVE-2007-4205](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4205) ### Description XHA (Linux-HA) on the BlueCat Networks Adonis DNS/DHCP Appliance 5.0.2.8 allows remote attackers to cause a denial of service (heartbeat control process crash) via a UDP packet to port 694. NOTE: this may be the same as CVE-2006-3121. ### POC #### Reference - http://securityreason.com/securityalert/2978 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4207 (2007/CVE-2007-4207.md) ### [CVE-2007-4207](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4207) ### Description SQL injection vulnerability in admin_console/index.asp in Gallery In A Box allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: these fields might be associated with the txtUsername and txtPassword parameters. ### POC #### Reference - http://securityreason.com/securityalert/2977 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4208 (2007/CVE-2007-4208.md) ### [CVE-2007-4208](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4208) ### Description SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action. ### POC #### Reference - http://securityreason.com/securityalert/2976 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4210 (2007/CVE-2007-4210.md) ### [CVE-2007-4210](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4210) ### Description Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules. ### POC #### Reference - http://securityreason.com/securityalert/2975 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4212 (2007/CVE-2007-4212.md) ### [CVE-2007-4212](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4212) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via the META tag. ### POC #### Reference - http://securityreason.com/securityalert/2974 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4213 (2007/CVE-2007-4213.md) ### [CVE-2007-4213](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4213) ### Description Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows remote attackers to cause a denial of service (device reset or hang) via a flood of large ICMP echo requests. NOTE: this is probably a different vulnerability than CVE-2003-0293. ### POC #### Reference - http://securityreason.com/securityalert/3034 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4218 (2007/CVE-2007-4218.md) ### [CVE-2007-4218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4218) ### Description Multiple buffer overflows in the ServerProtect service (SpntSvc.exe) in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allow remote attackers to execute arbitrary code via certain RPC requests to certain TCP ports that are processed by the (1) RPCFN_ENG_NewManualScan, (2) RPCFN_ENG_TimedNewManualScan, and (3) RPCFN_SetComputerName functions in (a) StRpcSrv.dll; the (4) RPCFN_CMON_SetSvcImpersonateUser and (5) RPCFN_OldCMON_SetSvcImpersonateUser functions in (b) Stcommon.dll; the (6) RPCFN_ENG_TakeActionOnAFile and (7) RPCFN_ENG_AddTaskExportLogItem functions in (c) Eng50.dll; the (8) NTF_SetPagerNotifyConfig function in (d) Notification.dll; or the (9) RPCFN_CopyAUSrc function in the (e) ServerProtect Agent service. ### POC #### Reference - http://securityreason.com/securityalert/3052 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4219 (2007/CVE-2007-4219.md) ### [CVE-2007-4219](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4219) ### Description Integer overflow in the RPCFN_SYNC_TASK function in StRpcSrv.dll, as used by the ServerProtect service (SpntSvc.exe), in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a certain integer field in a request packet to TCP port 5168, which triggers a heap-based buffer overflow. ### POC #### Reference - http://securityreason.com/securityalert/3052 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4224 (2007/CVE-2007-4224.md) ### [CVE-2007-4224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4224) ### Description KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property. ### POC #### Reference - http://securityreason.com/securityalert/2982 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9879 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4225 (2007/CVE-2007-4225.md) ### [CVE-2007-4225](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4225) ### Description Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of whitespace in the user/password portion. ### POC #### Reference - http://securityreason.com/securityalert/2982 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4226 (2007/CVE-2007-4226.md) ### [CVE-2007-4226](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4226) ### Description Directory traversal vulnerability in the BlueCat Networks Proteus IPAM appliance 2.0.2.0 (Adonis DNS/DHCP appliance 5.0.2.8) allows remote authenticated administrators, with certain TFTP privileges, to create and overwrite arbitrary files via a .. (dot dot) in a pathname. NOTE: this can be leveraged for administrative access by overwriting /etc/shadow. ### POC #### Reference - http://securityreason.com/securityalert/2986 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4227 (2007/CVE-2007-4227.md) ### [CVE-2007-4227](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4227) ### Description Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958. ### POC #### Reference - http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4231 (2007/CVE-2007-4231.md) ### [CVE-2007-4231](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4231) ### Description PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776. ### POC #### Reference - https://www.exploit-db.com/exploits/4267 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4232 (2007/CVE-2007-4232.md) ### [CVE-2007-4232](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4232) ### Description PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4268 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4233 (2007/CVE-2007-4233.md) ### [CVE-2007-4233](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4233) ### Description Multiple unspecified vulnerabilities in Camera Life before 2.6 allow attackers to cause a denial of service via unknown vectors. ### POC #### Reference - http://sourceforge.net/forum/forum.php?forum_id=721006 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4234 (2007/CVE-2007-4234.md) ### [CVE-2007-4234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4234) ### Description Unspecified vulnerability in Camera Life before 2.6 allows remote attackers to download private photos via unspecified vectors associated with the names of the photos. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://sourceforge.net/forum/forum.php?forum_id=721006 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4235 (2007/CVE-2007-4235.md) ### [CVE-2007-4235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4235) ### Description Multiple PHP remote file inclusion vulnerabilities in VietPHP allow remote attackers to execute arbitrary PHP code via a URL in (1) the dirpath parameter to (a) _functions.php, or (2) the language parameter to (b) admin/index.php or (c) index.php. ### POC #### Reference - http://securityreason.com/securityalert/2983 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4242 (2007/CVE-2007-4242.md) ### [CVE-2007-4242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4242) ### Description The pop3 Proxy in Astaro Security Gateway (ASG) 7 does not perform virus scanning of attachments that exceed the maximum attachment size, and passes these attachments, which allows remote attackers to bypass this scanning via a large attachment. ### POC #### Reference - http://securityreason.com/securityalert/2981 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4243 (2007/CVE-2007-4243.md) ### [CVE-2007-4243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4243) ### Description Unspecified vulnerability in pfilter-reporter.pl in Astaro Security Gateway (ASG) 7 allows remote attackers to cause a denial of service (CPU consumption) via certain network traffic, as demonstrated by P2P and iTunes applications that download large amounts of data. ### POC #### Reference - http://securityreason.com/securityalert/2981 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4244 (2007/CVE-2007-4244.md) ### [CVE-2007-4244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4244) ### Description PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP code via a URL in the comPath parameter. ### POC #### Reference - http://securityreason.com/securityalert/2984 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4245 (2007/CVE-2007-4245.md) ### [CVE-2007-4245](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4245) ### Description Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2. ### POC #### Reference - http://securityreason.com/securityalert/2980 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4246 (2007/CVE-2007-4246.md) ### [CVE-2007-4246](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4246) ### Description Unspecified vulnerability, possibly a buffer overflow, in Justsystem Ichitaro 2007 and earlier allows remote attackers to execute arbitrary code via a modified document, as actively exploited in August 2007 by malware such as Tarodrop.D (Tarodrop.Q), a different vulnerability than CVE-2006-4326, CVE-2006-5424, CVE-2006-6400, and CVE-2007-1938. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4247 (2007/CVE-2007-4247.md) ### [CVE-2007-4247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4247) ### Description Windows Calendar on Microsoft Windows Vista allows remote attackers to cause a denial of service (NULL dereference and persistent application crash) via a malformed ICS file. ### POC #### Reference - http://securityreason.com/securityalert/3004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4248 (2007/CVE-2007-4248.md) ### [CVE-2007-4248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4248) ### Description The CallCmd function in toolbar_gaming.dll in the Toolbar Gaming toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4249 (2007/CVE-2007-4249.md) ### [CVE-2007-4249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4249) ### Description The isChecked function in Toolbar.DLL in the ExportNation toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4250 (2007/CVE-2007-4250.md) ### [CVE-2007-4250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4250) ### Description The isChecked function in Toolbar.DLL in Advanced Searchbar before 3.33 allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4251 (2007/CVE-2007-4251.md) ### [CVE-2007-4251](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4251) ### Description OpenOffice.org (OOo) 2.2 does not properly handle files with multiple extensions, which allows user-assisted remote attackers to cause a denial of service. ### POC #### Reference - http://securityreason.com/securityalert/3004 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4252 (2007/CVE-2007-4252.md) ### [CVE-2007-4252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4252) ### Description Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a different vulnerability than CVE-2007-3633. ### POC #### Reference - https://www.exploit-db.com/exploits/4255 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4253 (2007/CVE-2007-4253.md) ### [CVE-2007-4253](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4253) ### Description SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2005-4263. ### POC #### Reference - https://www.exploit-db.com/exploits/4256 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4254 (2007/CVE-2007-4254.md) ### [CVE-2007-4254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4254) ### Description Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method. NOTE: this may overlap CVE-2007-2885 or CVE-2005-2127. ### POC #### Reference - https://www.exploit-db.com/exploits/4259 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4255 (2007/CVE-2007-4255.md) ### [CVE-2007-4255](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4255) ### Description Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function. ### POC #### Reference - https://www.exploit-db.com/exploits/4260 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4256 (2007/CVE-2007-4256.md) ### [CVE-2007-4256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4256) ### Description Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4261 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4257 (2007/CVE-2007-4257.md) ### [CVE-2007-4257](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4257) ### Description Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate string, different vectors than CVE-2007-4140. ### POC #### Reference - https://www.exploit-db.com/exploits/4262 - https://www.exploit-db.com/exploits/4263 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4258 (2007/CVE-2007-4258.md) ### [CVE-2007-4258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4258) ### Description SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4265 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4259 (2007/CVE-2007-4259.md) ### [CVE-2007-4259](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4259) ### Description EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user interface with JavaScript disabled. ### POC #### Reference - http://securityreason.com/securityalert/2985 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4260 (2007/CVE-2007-4260.md) ### [CVE-2007-4260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4260) ### Description EZPhotoSales 1.9.3 and earlier has a default "admin" account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username. ### POC #### Reference - http://securityreason.com/securityalert/2985 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4261 (2007/CVE-2007-4261.md) ### [CVE-2007-4261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4261) ### Description EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords via a direct request for OnlineViewing/data/galleries.txt, or (2) a file containing username hashes and password hashes via a direct request for OnlineViewing/configuration/config.dat/. NOTE: vector 2 can be leveraged for administrative access because authentication does not require knowledge of cleartext values, but instead uses the username hash in the ConfigLogin parameter and the password hash in the ConfigPassword parameter. ### POC #### Reference - http://securityreason.com/securityalert/2985 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4262 (2007/CVE-2007-4262.md) ### [CVE-2007-4262](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4262) ### Description Unrestricted file upload vulnerability in EZPhotoSales 1.9.3 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP code under OnlineViewing/galleries/. ### POC #### Reference - http://securityreason.com/securityalert/2985 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4263 (2007/CVE-2007-4263.md) ### [CVE-2007-4263](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4263) ### Description Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-based IOS allows remote authenticated users to read, write or overwrite any file on the device's filesystem via unknown vectors. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070808-scp.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4279 (2007/CVE-2007-4279.md) ### [CVE-2007-4279](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4279) ### Description PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4269 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4282 (2007/CVE-2007-4282.md) ### [CVE-2007-4282](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4282) ### Description The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked. ### POC #### Reference - http://sourceforge.net/forum/forum.php?forum_id=722867 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4283 (2007/CVE-2007-4283.md) ### [CVE-2007-4283](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4283) ### Description PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter. ### POC #### Reference - http://securityreason.com/securityalert/2989 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4287 (2007/CVE-2007-4287.md) ### [CVE-2007-4287](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4287) ### Description PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the docroot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4271 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4288 (2007/CVE-2007-4288.md) ### [CVE-2007-4288](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4288) ### Description Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au. ### POC #### Reference - http://securityreason.com/securityalert/2987 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4290 (2007/CVE-2007-4290.md) ### [CVE-2007-4290](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4290) ### Description Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) entries.php, (6) index.php, (7) logout.php, or (8) settings.php in admin/. NOTE: a third party disputes this vulnerability, noting that these scripts defend against direct requests ### POC #### Reference - http://securityreason.com/securityalert/2988 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4292 (2007/CVE-2007-4292.md) ### [CVE-2007-4292](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4292) ### Description Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5781 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4297 (2007/CVE-2007-4297.md) ### [CVE-2007-4297](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4297) ### Description Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt - http://www.vupen.com/english/advisories/2007/2831 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4309 (2007/CVE-2007-4309.md) ### [CVE-2007-4309](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4309) ### Description IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696. ### POC #### Reference - http://www.heise-security.co.uk/news/92958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4312 (2007/CVE-2007-4312.md) ### [CVE-2007-4312](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4312) ### Description SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action. ### POC #### Reference - https://www.exploit-db.com/exploits/4275 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4313 (2007/CVE-2007-4313.md) ### [CVE-2007-4313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4313) ### Description PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter, a different vector than CVE-2006-2392, CVE-2006-3076, and CVE-2006-6958. ### POC #### Reference - https://www.exploit-db.com/exploits/4276 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4314 (2007/CVE-2007-4314.md) ### [CVE-2007-4314](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4314) ### Description pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote directory tree via a URL in the root parameter. NOTE: this can be leveraged for traffic amplification or other denial of service. ### POC #### Reference - https://www.exploit-db.com/exploits/4278 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4316 (2007/CVE-2007-4316.md) ### [CVE-2007-4316](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4316) ### Description The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions. ### POC #### Reference - http://securityreason.com/securityalert/3002 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4317 (2007/CVE-2007-4317.md) ### [CVE-2007-4317](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4317) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allow remote attackers to perform certain actions as administrators, as demonstrated by a request to Forms/General_1 with the (1) sysSystemName and (2) sysDomainName parameters. ### POC #### Reference - http://securityreason.com/securityalert/3002 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4318 (2007/CVE-2007-4318.md) ### [CVE-2007-4318](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4318) ### Description Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter. ### POC #### Reference - http://securityreason.com/securityalert/3002 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4319 (2007/CVE-2007-4319.md) ### [CVE-2007-4319](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4319) ### Description The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE. ### POC #### Reference - http://securityreason.com/securityalert/3002 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4320 (2007/CVE-2007-4320.md) ### [CVE-2007-4320](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4320) ### Description PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4273 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4324 (2007/CVE-2007-4324.md) ### [CVE-2007-4324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4324) ### Description ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability. ### POC #### Reference - http://scan.flashsec.org/ - http://securityreason.com/securityalert/2995 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4325 (2007/CVE-2007-4325.md) ### [CVE-2007-4325](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4325) ### Description PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter. ### POC #### Reference - http://securityreason.com/securityalert/2994 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4327 (2007/CVE-2007-4327.md) ### [CVE-2007-4327](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4327) ### Description Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php. ### POC #### Reference - http://securityreason.com/securityalert/3000 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4328 (2007/CVE-2007-4328.md) ### [CVE-2007-4328](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4328) ### Description Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. NOTE: A later report states that 1.1 is also affected, but that the filename for vector 3 is anzeigen.php. ### POC #### Reference - http://securityreason.com/securityalert/2999 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4329 (2007/CVE-2007-4329.md) ### [CVE-2007-4329](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4329) ### Description Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) news.php, or (3) feed.php. ### POC #### Reference - http://securityreason.com/securityalert/2998 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4330 (2007/CVE-2007-4330.md) ### [CVE-2007-4330](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4330) ### Description PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. ### POC #### Reference - http://securityreason.com/securityalert/2997 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4331 (2007/CVE-2007-4331.md) ### [CVE-2007-4331](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4331) ### Description PHP remote file inclusion vulnerability in index.php in FindNix allows remote attackers to include the contents of arbitrary URLs and conduct cross-site scripting (XSS) attacks via a URL in the page parameter. ### POC #### Reference - http://securityreason.com/securityalert/2992 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4336 (2007/CVE-2007-4336.md) ### [CVE-2007-4336](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4336) ### Description Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long SourceUrl property value. ### POC #### Reference - https://www.exploit-db.com/exploits/4279 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4339 (2007/CVE-2007-4339.md) ### [CVE-2007-4339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4339) ### Description Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php. ### POC #### Reference - http://securityreason.com/securityalert/3008 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4342 (2007/CVE-2007-4342.md) ### [CVE-2007-4342](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4342) ### Description PHP remote file inclusion vulnerability in include.php in PHPCentral Login 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: a third party disputes this vulnerability because of the special nature of the SERVER superglobal array. ### POC #### Reference - http://securityreason.com/securityalert/3005 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4349 (2007/CVE-2007-4349.md) ### [CVE-2007-4349](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4349) ### Description The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference. ### POC #### Reference - http://securityreason.com/securityalert/4501 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4350 (2007/CVE-2007-4350.md) ### [CVE-2007-4350](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4350) ### Description Cross-site scripting (XSS) vulnerability in the management interface in HP SiteScope 9.0 build 911 allows remote attackers to inject arbitrary web script or HTML via an SNMP trap message. ### POC #### Reference - http://securityreason.com/securityalert/4447 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4351 (2007/CVE-2007-4351.md) ### [CVE-2007-4351](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4351) ### Description Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow. ### POC #### Reference - http://www.cups.org/str.php?L2561 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4352 (2007/CVE-2007-4352.md) ### [CVE-2007-4352](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4352) ### Description Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9979 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 4358 (2007/CVE-2007-4358.md) ### [CVE-2007-4358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4358) ### Description Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containing 0x69 in the ninth byte, which triggers a "double-delete" of trace data, a different vulnerability than CVE-2005-1643. ### POC #### Reference - http://aluigi.altervista.org/adv/zoidboom2-adv.txt - http://aluigi.org/poc/zoidboom2.zip - http://securityreason.com/securityalert/3014 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4361 (2007/CVE-2007-4361.md) ### [CVE-2007-4361](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4361) ### Description NETGEAR (formerly Infrant) ReadyNAS RAIDiator before 4.00b2-p2-T1 beta creates a default SSH root password derived from the hardware serial number, which makes it easier for remote attackers to guess the password and obtain login access. ### POC #### Reference No PoCs from references. #### Github - https://github.com/battleofthebots/system-gateway --- ### 2007/CVE 2007 4362 (2007/CVE-2007-4362.md) ### [CVE-2007-4362](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4362) ### Description SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4284 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4366 (2007/CVE-2007-4366.md) ### [CVE-2007-4366](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4366) ### Description WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. ### POC #### Reference - http://securityreason.com/securityalert/3015 - https://www.exploit-db.com/exploits/4281 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4367 (2007/CVE-2007-4367.md) ### [CVE-2007-4367](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4367) ### Description Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invalid pointer." ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4368 (2007/CVE-2007-4368.md) ### [CVE-2007-4368](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4368) ### Description SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command. ### POC #### Reference - https://www.exploit-db.com/exploits/4286 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4369 (2007/CVE-2007-4369.md) ### [CVE-2007-4369](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4369) ### Description Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4282 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4370 (2007/CVE-2007-4370.md) ### [CVE-2007-4370](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4370) ### Description Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to UDP port 26000. ### POC #### Reference - https://www.exploit-db.com/exploits/4283 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4371 (2007/CVE-2007-4371.md) ### [CVE-2007-4371](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4371) ### Description Unrestricted file upload vulnerability in admin/pages/blog-add.php in Neuron Blog 1.1 allows remote attackers to upload and execute arbitrary PHP files in uploads/. ### POC #### Reference - http://securityreason.com/securityalert/3016 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4372 (2007/CVE-2007-4372.md) ### [CVE-2007-4372](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4372) ### Description Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4373 (2007/CVE-2007-4373.md) ### [CVE-2007-4373](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4373) ### Description The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remote attackers to bypass authentication by reconnecting after a connection closes. ### POC #### Reference - http://aluigi.altervista.org/adv/bv2x-adv.txt - http://securityreason.com/securityalert/3024 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4374 (2007/CVE-2007-4374.md) ### [CVE-2007-4374](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4374) ### Description Babo Violent 2 2.08.00 does not validate the sender field of a chat message composed by a client, which allows remote authenticated users to spoof messages. ### POC #### Reference - http://aluigi.altervista.org/adv/bv2x-adv.txt - http://securityreason.com/securityalert/3024 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4375 (2007/CVE-2007-4375.md) ### [CVE-2007-4375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4375) ### Description The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address. ### POC #### Reference - http://securityreason.com/securityalert/3018 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4376 (2007/CVE-2007-4376.md) ### [CVE-2007-4376](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4376) ### Description Unrestricted file upload vulnerability in banner-upload.php in Szymon Kosok Best Top List allows remote attackers to upload and execute arbitrary PHP files in banners/. ### POC #### Reference - http://securityreason.com/securityalert/3019 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4377 (2007/CVE-2007-4377.md) ### [CVE-2007-4377](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4377) ### Description Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372. ### POC #### Reference - https://www.exploit-db.com/exploits/4287 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4378 (2007/CVE-2007-4378.md) ### [CVE-2007-4378](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4378) ### Description Multiple format string vulnerabilities in Babo Violent 2 2.08.00 and earlier allow remote attackers to execute arbitrary code via format string specifiers in (1) a message or (2) certain data associated with an admin login. ### POC #### Reference - http://aluigi.altervista.org/adv/bv2x-adv.txt - http://securityreason.com/securityalert/3024 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4379 (2007/CVE-2007-4379.md) ### [CVE-2007-4379](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4379) ### Description Babo Violent 2 2.08.00 and earlier allows remote attackers to cause a denial of service (application crash) via (1) a value greater than 0x27 for the (a) 0xca, (b) 0xcb, (c) 0xcc, (d) 0xce, (e) 0xcf, or (f) 0xd0 data ID; (2) a nonexistent map name; or (3) a UDP packet that specifies a large data size. ### POC #### Reference - http://aluigi.altervista.org/adv/bv2x-adv.txt - http://securityreason.com/securityalert/3024 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4381 (2007/CVE-2007-4381.md) ### [CVE-2007-4381](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4381) ### Description Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0100.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4382 (2007/CVE-2007-4382.md) ### [CVE-2007-4382](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4382) ### Description CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. ### POC #### Reference - http://securityreason.com/securityalert/3027 - https://www.exploit-db.com/exploits/4285 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4385 (2007/CVE-2007-4385.md) ### [CVE-2007-4385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4385) ### Description OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the validation routines. ### POC #### Reference - http://o0o.nu/~meder/o0o_bypassing_servlet_input_validation_filters.txt - http://securityreason.com/securityalert/3035 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4386 (2007/CVE-2007-4386.md) ### [CVE-2007-4386](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4386) ### Description SQL injection vulnerability in search.php in GetMyOwnArcade allows remote attackers to execute arbitrary SQL commands via the query parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4291 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4396 (2007/CVE-2007-4396.md) ### [CVE-2007-4396](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4396) ### Description Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4397 (2007/CVE-2007-4397.md) ### [CVE-2007-4397](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4397) ### Description Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4398 (2007/CVE-2007-4398.md) ### [CVE-2007-4398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4398) ### Description Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4399 (2007/CVE-2007-4399.md) ### [CVE-2007-4399](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4399) ### Description CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4400 (2007/CVE-2007-4400.md) ### [CVE-2007-4400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4400) ### Description CRLF injection vulnerability in the included media script in Konversation allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4401 (2007/CVE-2007-4401.md) ### [CVE-2007-4401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4401) ### Description Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4402 (2007/CVE-2007-4402.md) ### [CVE-2007-4402](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4402) ### Description Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4403 (2007/CVE-2007-4403.md) ### [CVE-2007-4403](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4403) ### Description The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. ### POC #### Reference - http://securityreason.com/securityalert/3036 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4404 (2007/CVE-2007-4404.md) ### [CVE-2007-4404](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4404) ### Description ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a "J 0:#channel" message on a channel without an apass; and (3) allows remote authenticated operators to cause a denial of service (daemon crash) via a remote "names -D" command. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4405 (2007/CVE-2007-4405.md) ### [CVE-2007-4405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4405) ### Description ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels). ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4406 (2007/CVE-2007-4406.md) ### [CVE-2007-4406](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4406) ### Description ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4407 (2007/CVE-2007-4407.md) ### [CVE-2007-4407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4407) ### Description ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel modes via a "netriding" attack or (2) take over a channel by joining an unlinked server with the A/Upass and then setting a new Apass. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4408 (2007/CVE-2007-4408.md) ### [CVE-2007-4408](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4408) ### Description ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4409 (2007/CVE-2007-4409.md) ### [CVE-2007-4409](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4409) ### Description Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arrives. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4410 (2007/CVE-2007-4410.md) ### [CVE-2007-4410](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4410) ### Description ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote authenticated operators to prevent later kick or de-op actions from non-local ops. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4411 (2007/CVE-2007-4411.md) ### [CVE-2007-4411](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4411) ### Description ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies. ### POC #### Reference - http://securityreason.com/securityalert/3031 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4414 (2007/CVE-2007-4414.md) ### [CVE-2007-4414](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4414) ### Description Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4415 (2007/CVE-2007-4415.md) ### [CVE-2007-4415](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4415) ### Description Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4420 (2007/CVE-2007-4420.md) ### [CVE-2007-4420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4420) ### Description Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169. ### POC #### Reference - https://www.exploit-db.com/exploits/4290 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4424 (2007/CVE-2007-4424.md) ### [CVE-2007-4424](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4424) ### Description Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file is not actually launched, but as of 2007, it is generally accepted that web browsers should prompt users before saving dangerous content. ### POC #### Reference - http://securityreason.com/securityalert/3022 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4425 (2007/CVE-2007-4425.md) ### [CVE-2007-4425](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4425) ### Description Multiple buffer overflows in Live for Speed (LFS) demo, S1, and S2 allow remote authenticated users to (1) cause a denial of service (server crash) and probably execute arbitrary code via an ID 3 packet with a long nickname field, and (2) cause a denial of service (server crash) via an ID 10 packet containing a long string corresponding to an unavailable track. ### POC #### Reference - http://securityreason.com/securityalert/3030 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4426 (2007/CVE-2007-4426.md) ### [CVE-2007-4426](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4426) ### Description Live for Speed (LFS) S1 and S2 allows remote attackers to cause a denial of service (server crash) via (1) a certain 0x00 byte in a pre-login ID 3 packet, which triggers a NULL dereference; or (2) a pre-login ID 5 packet that lacks certain strings, which triggers an invalid pointer dereference. ### POC #### Reference - http://securityreason.com/securityalert/3030 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4428 (2007/CVE-2007-4428.md) ### [CVE-2007-4428](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4428) ### Description Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4429 (2007/CVE-2007-4429.md) ### [CVE-2007-4429](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4429) ### Description Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this identifier is for the en.securitylab.ru disclosure. According to the vendor, this issue is separate from the "sign-on issues" that reduced Skype service on 20070817, which appears to be a site-specific problem. As of 20070821, it is not clear whether this issue is simply a symptom of the larger sign-on problem. ### POC #### Reference - http://blogs.csoonline.com/the_skype_mystery_why_blame_the_august_windows_updates - http://en.securitylab.ru/poc/301420.php - http://en.securitylab.ru/poc/extra/301419.php - http://securityreason.com/securityalert/3032 - http://www.securitylab.ru/news/301422.php #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4430 (2007/CVE-2007-4430.md) ### [CVE-2007-4430](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4430) ### Description Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access. ### POC #### Reference - http://www.heise-security.co.uk/news/94526/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4431 (2007/CVE-2007-4431.md) ### [CVE-2007-4431](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4431) ### Description Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking." ### POC #### Reference - http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4433 (2007/CVE-2007-4433.md) ### [CVE-2007-4433](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4433) ### Description Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the Text File Search ASP.NET edition allows remote attackers to inject arbitrary web script or HTML via the search field. ### POC #### Reference - http://www.packetstormsecurity.org/0708-exploits/aspnet-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4434 (2007/CVE-2007-4434.md) ### [CVE-2007-4434](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4434) ### Description Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. ### POC #### Reference - http://www.packetstormsecurity.org/0708-exploits/tfsc-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4439 (2007/CVE-2007-4439.md) ### [CVE-2007-4439](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4439) ### Description PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4295 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4440 (2007/CVE-2007-4440.md) ### [CVE-2007-4440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4440) ### Description Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961. ### POC #### Reference - https://www.exploit-db.com/exploits/4294 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4441 (2007/CVE-2007-4441.md) ### [CVE-2007-4441](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4441) ### Description Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attackers to execute arbitrary code via a long string in the filename argument to the win_browse_file function. ### POC #### Reference - https://www.exploit-db.com/exploits/4293 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4442 (2007/CVE-2007-4442.md) ### [CVE-2007-4442](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4442) ### Description Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII. ### POC #### Reference - http://aluigi.org/adv/unrwebdos-adv.txt - http://aluigi.org/poc/unrwebdos.zip - http://securityreason.com/securityalert/3039 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4443 (2007/CVE-2007-4443.md) ### [CVE-2007-4443](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4443) ### Description The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and possibly other unspecified vectors. ### POC #### Reference - http://aluigi.org/adv/unrwebdos-adv.txt - http://aluigi.org/poc/unrwebdos.zip - http://securityreason.com/securityalert/3039 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4444 (2007/CVE-2007-4444.md) ### [CVE-2007-4444](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4444) ### Description Multiple buffer overflows in Image Space rFactor 1.250 and earlier allow remote attackers to execute arbitrary code via a packet with ID (1) 0x80 or (2) 0x88 to UDP port 34297, related to the buffer containing the server version number. ### POC #### Reference - http://aluigi.org/poc/rfactorx.zip - http://securityreason.com/securityalert/3037 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4445 (2007/CVE-2007-4445.md) ### [CVE-2007-4445](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4445) ### Description Image Space rFactor 1.250 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) an ID 0x30 packet, (2) an ID 0x38 packet, and an invalid 13-bit integer in (3) an ID 0x60 packet and (4) an ID 0x68 packet; and a denial of service (UDP port block) via (5) an ID 0x20 packet and (6) an ID 0x28 packet. ### POC #### Reference - http://aluigi.org/poc/rfactorx.zip - http://securityreason.com/securityalert/3037 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4446 (2007/CVE-2007-4446.md) ### [CVE-2007-4446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4446) ### Description Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client nickname) when entering a game. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4447 (2007/CVE-2007-4447.md) ### [CVE-2007-4447](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4447) ### Description Multiple buffer overflows in the client in Toribash 2.71 and earlier allow remote attackers to (1) execute arbitrary code via a long game command in a replay (.rpl) file and (2) cause a denial of service (application crash) via a long SAY command that omits a required LF character; and allow remote Toribash servers to execute arbitrary code via (3) a long game command and (4) a long SAY command that omits a required LF character. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4448 (2007/CVE-2007-4448.md) ### [CVE-2007-4448](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4448) ### Description The server in Toribash 2.71 and earlier does not properly handle partially joined clients that are temporarily assigned the ID of -1, which allows remote attackers to cause a denial of service (daemon crash) via a GRIP command with the ID of -1. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4449 (2007/CVE-2007-4449.md) ### [CVE-2007-4449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4449) ### Description The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (application hang) via a command without an LF character, as demonstrated by a SAY command. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4450 (2007/CVE-2007-4450.md) ### [CVE-2007-4450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4450) ### Description The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command. NOTE: the security impact of this violation is not clear, although it probably makes exploitation of CVE-2007-4449 easier. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4451 (2007/CVE-2007-4451.md) ### [CVE-2007-4451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4451) ### Description The server in Toribash 2.71 and earlier on Windows allows remote attackers to cause a denial of service (continuous beep and server hang) via certain commands that contain many 0x07 or other invalid characters. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4452 (2007/CVE-2007-4452.md) ### [CVE-2007-4452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4452) ### Description The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (disconnection) via a long (1) emote or (2) SPEC command. ### POC #### Reference - http://aluigi.org/poc/toribashish.zip - http://securityreason.com/securityalert/3033 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4454 (2007/CVE-2007-4454.md) ### [CVE-2007-4454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4454) ### Description Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code via a crafted version string, as referenced by the (1) PDO::ATTR_SERVER_VERSION or (2) PDO::ATTR_CLIENT_VERSION attribute. ### POC #### Reference - http://securityreason.com/securityalert/3038 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4456 (2007/CVE-2007-4456.md) ### [CVE-2007-4456](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4456) ### Description SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo. ### POC #### Reference - https://www.exploit-db.com/exploits/4296 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4459 (2007/CVE-2007-4459.md) ### [CVE-2007-4459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4459) ### Description Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sr-20070821-sip.shtml #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4463 (2007/CVE-2007-4463.md) ### [CVE-2007-4463](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4463) ### Description The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file. ### POC #### Reference - http://securityreason.com/securityalert/3044 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4464 (2007/CVE-2007-4464.md) ### [CVE-2007-4464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4464) ### Description CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via strings with CRLF sequences in the IMAGE_EXPORT_DIRECTORY array in a PE file, which could complicate forensics investigations. ### POC #### Reference - http://securityreason.com/securityalert/3044 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4465 (2007/CVE-2007-4465.md) ### [CVE-2007-4465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465) ### Description Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection. ### POC #### Reference - http://securityreason.com/securityalert/3113 - http://www.vupen.com/english/advisories/2008/1697 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/kasem545/vulnsearch - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 4474 (2007/CVE-2007-4474.md) ### [CVE-2007-4474](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4474) ### Description Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1. ### POC #### Reference - https://www.exploit-db.com/exploits/4818 - https://www.exploit-db.com/exploits/4820 - https://www.exploit-db.com/exploits/5111 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4476 (2007/CVE-2007-4476.md) ### [CVE-2007-4476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476) ### Description Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8599 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9336 #### Github - https://github.com/jmalicki/arsync --- ### 2007/CVE 2007 4480 (2007/CVE-2007-4480.md) ### [CVE-2007-4480](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4480) ### Description Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4481 (2007/CVE-2007-4481.md) ### [CVE-2007-4481](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4481) ### Description Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4482 (2007/CVE-2007-4482.md) ### [CVE-2007-4482](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4482) ### Description Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4483 (2007/CVE-2007-4483.md) ### [CVE-2007-4483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4483) ### Description Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4484 (2007/CVE-2007-4484.md) ### [CVE-2007-4484](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4484) ### Description PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter. ### POC #### Reference - http://securityvulns.com/Rdocument846.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4485 (2007/CVE-2007-4485.md) ### [CVE-2007-4485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4485) ### Description PHP remote file inclusion vulnerability in visitor.php in Butterfly online visitors counter 1.08, when used with certain older versions of PHP with improper SERVER superglobal handling, allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Butterfly online visitors counter. ### POC #### Reference - http://securityvulns.com/Rdocument845.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4486 (2007/CVE-2007-4486.md) ### [CVE-2007-4486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4486) ### Description Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter. ### POC #### Reference - http://securityvulns.com/Rdocument752.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4487 (2007/CVE-2007-4487.md) ### [CVE-2007-4487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4487) ### Description Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3051 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4488 (2007/CVE-2007-4488.md) ### [CVE-2007-4488](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4488) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the Siemens Gigaset SE361 WLAN router with firmware 1.00.0 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI immediately following the filename for (1) a GIF filename, which triggers display of the GIF file in text format and an unspecified denial of service (crash); or (2) the login.tri filename, which triggers a continuous loop of the browser attempting to visit the login page. ### POC #### Reference - http://securityreason.com/securityalert/3050 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4489 (2007/CVE-2007-4489.md) ### [CVE-2007-4489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4489) ### Description Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method. ### POC #### Reference - https://www.exploit-db.com/exploits/4299 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4490 (2007/CVE-2007-4490.md) ### [CVE-2007-4490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4490) ### Description Multiple buffer overflows in EarthAgent.exe in Trend Micro ServerProtect 5.58 for Windows before Security Patch 4 allow remote attackers to have an unknown impact via certain RPC function calls to (1) RPCFN_EVENTBACK_DoHotFix or (2) CMD_CHANGE_AGENT_REGISTER_INFO. ### POC #### Reference - http://securityreason.com/securityalert/3052 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4496 (2007/CVE-2007-4496.md) ### [CVE-2007-4496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4496) ### Description Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest operating system to corrupt memory and possibly execute arbitrary code on the host operating system via unspecified vectors. ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4497 (2007/CVE-2007-4497.md) ### [CVE-2007-4497](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4497) ### Description Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows users with login access to a guest operating system to cause a denial of service (guest outage and host process crash or hang) via unspecified vectors. ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4498 (2007/CVE-2007-4498.md) ### [CVE-2007-4498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4498) ### Description The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a certain "SIP/2.0 183 Session Progress" message. ### POC #### Reference - http://securityreason.com/securityalert/3059 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4502 (2007/CVE-2007-4502.md) ### [CVE-2007-4502](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4502) ### Description SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4310 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4503 (2007/CVE-2007-4503.md) ### [CVE-2007-4503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4503) ### Description SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4308 - https://www.exploit-db.com/exploits/6794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4504 (2007/CVE-2007-4504.md) ### [CVE-2007-4504](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4504) ### Description Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action. ### POC #### Reference - https://www.exploit-db.com/exploits/4307 #### Github - https://github.com/ARPSyndicate/kenzer-templates --- ### 2007/CVE 2007 4505 (2007/CVE-2007-4505.md) ### [CVE-2007-4505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4505) ### Description SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action. ### POC #### Reference - https://www.exploit-db.com/exploits/4306 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4506 (2007/CVE-2007-4506.md) ### [CVE-2007-4506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4506) ### Description SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action. ### POC #### Reference - https://www.exploit-db.com/exploits/4305 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4507 (2007/CVE-2007-4507.md) ### [CVE-2007-4507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4507) ### Description Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrary code via long arguments to the (1) ntuser_getuserlist, (2) ntuser_getuserinfo, (3) ntuser_getusergroups, or (4) ntuser_getdomaincontroller functions. ### POC #### Reference - https://www.exploit-db.com/exploits/4304 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4508 (2007/CVE-2007-4508.md) ### [CVE-2007-4508](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4508) ### Description Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query. ### POC #### Reference - http://aluigi.altervista.org/adv/asurabof-adv.txt - http://securityreason.com/securityalert/3053 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4509 (2007/CVE-2007-4509.md) ### [CVE-2007-4509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4509) ### Description SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action. ### POC #### Reference - https://www.exploit-db.com/exploits/4309 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4510 (2007/CVE-2007-4510.md) ### [CVE-2007-4510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4510) ### Description ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/3054 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4512 (2007/CVE-2007-4512.md) ### [CVE-2007-4512](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4512) ### Description Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in SavMain.exe. ### POC #### Reference - http://securityreason.com/securityalert/3107 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4515 (2007/CVE-2007-4515.md) ### [CVE-2007-4515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4515) ### Description Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://messenger.yahoo.com/security_update.php?id=082907 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4517 (2007/CVE-2007-4517.md) ### [CVE-2007-4517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4517) ### Description Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument. ### POC #### Reference - http://securityreason.com/securityalert/8524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4521 (2007/CVE-2007-4521.md) ### [CVE-2007-4521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4521) ### Description Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail. ### POC #### Reference - http://securityreason.com/securityalert/3065 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4522 (2007/CVE-2007-4522.md) ### [CVE-2007-4522](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4522) ### Description Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php. NOTE: some vectors might be reachable through the url and name parameters to (g) admin/navigation/new_nav_item.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS. ### POC #### Reference - http://securityreason.com/securityalert/3058 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4523 (2007/CVE-2007-4523.md) ### [CVE-2007-4523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4523) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS. ### POC #### Reference - http://securityreason.com/securityalert/3058 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4524 (2007/CVE-2007-4524.md) ### [CVE-2007-4524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4524) ### Description PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter. ### POC #### Reference - http://securityreason.com/securityalert/3055 - https://www.exploit-db.com/exploits/4382 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4525 (2007/CVE-2007-4525.md) ### [CVE-2007-4525](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4525) ### Description PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function ### POC #### Reference - http://securityreason.com/securityalert/3056 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4528 (2007/CVE-2007-4528.md) ### [CVE-2007-4528](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4528) ### Description The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code by loading an arbitrary DLL and calling a function, as demonstrated by kernel32.dll and the WinExec function. NOTE: this issue does not cross privilege boundaries in most contexts, so perhaps it should not be included in CVE. ### POC #### Reference - https://www.exploit-db.com/exploits/4311 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4531 (2007/CVE-2007-4531.md) ### [CVE-2007-4531](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4531) ### Description Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port. ### POC #### Reference - http://aluigi.altervista.org/adv/soldatdos-adv.txt - http://aluigi.org/poc/soldatdos.zip #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4532 (2007/CVE-2007-4532.md) ### [CVE-2007-4532](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4532) ### Description Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address. ### POC #### Reference - http://aluigi.altervista.org/adv/soldatdos-adv.txt - http://aluigi.org/poc/soldatdos.zip #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4533 (2007/CVE-2007-4533.md) ### [CVE-2007-4533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4533) ### Description Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat message, related to a call to the BroadcastPrintf function. ### POC #### Reference - http://securityreason.com/securityalert/3057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4534 (2007/CVE-2007-4534.md) ### [CVE-2007-4534](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4534) ### Description Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field. ### POC #### Reference - http://securityreason.com/securityalert/3057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4535 (2007/CVE-2007-4535.md) ### [CVE-2007-4535](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4535) ### Description The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error. ### POC #### Reference - http://securityreason.com/securityalert/3057 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4537 (2007/CVE-2007-4537.md) ### [CVE-2007-4537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4537) ### Description Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet. ### POC #### Reference - http://aluigi.altervista.org/adv/skulltaghof-adv.txt - http://securityreason.com/securityalert/3067 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4540 (2007/CVE-2007-4540.md) ### [CVE-2007-4540](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4540) ### Description Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header. ### POC #### Reference - http://securityreason.com/securityalert/3062 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4544 (2007/CVE-2007-4544.md) ### [CVE-2007-4544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4544) ### Description Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field). ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4545 (2007/CVE-2007-4545.md) ### [CVE-2007-4545](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4545) ### Description Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) ZIP or (2) RAR archive. ### POC #### Reference - http://securityreason.com/securityalert/3060 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4546 (2007/CVE-2007-4546.md) ### [CVE-2007-4546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4546) ### Description Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a user into performing a dangerous file overwrite or creation. ### POC #### Reference - http://securityreason.com/securityalert/3060 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4547 (2007/CVE-2007-4547.md) ### [CVE-2007-4547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4547) ### Description Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users. ### POC #### Reference - http://securityreason.com/securityalert/3060 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4549 (2007/CVE-2007-4549.md) ### [CVE-2007-4549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4549) ### Description Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long file-key or (2) a "Site Information and Folder entry" with a ciphertext_length value much larger than the plaintext_length value. ### POC #### Reference - http://vuln.sg/alpass27-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4550 (2007/CVE-2007-4550.md) ### [CVE-2007-4550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4550) ### Description Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field in a folder-name record in an ALPASS DB (APW) file. ### POC #### Reference - http://vuln.sg/alpass27-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4553 (2007/CVE-2007-4553.md) ### [CVE-2007-4553](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4553) ### Description The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number. ### POC #### Reference - http://securityreason.com/securityalert/3075 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4554 (2007/CVE-2007-4554.md) ### [CVE-2007-4554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4554) ### Description Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7. ### POC #### Reference - http://securityreason.com/securityalert/3064 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4555 (2007/CVE-2007-4555.md) ### [CVE-2007-4555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4555) ### Description Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin account. ### POC #### Reference - http://securityreason.com/securityalert/3068 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4556 (2007/CVE-2007-4556.md) ### [CVE-2007-4556](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4556) ### Description Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0day666/Vulnerability-verification - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/Elymaro/Struty - https://github.com/SexyBeast233/SecBooks - https://github.com/Zero094/Vulnerability-verification - https://github.com/brunsu/woodswiki - https://github.com/ice0bear14h/struts2scan - https://github.com/superlink996/chunqiuyunjingbachang - https://github.com/woods-sega/woodswiki --- ### 2007/CVE 2007 4559 (2007/CVE-2007-4559.md) ### [CVE-2007-4559](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4559) ### Description Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/BSolarV/cvedetails-summary - https://github.com/Brianpan/go-creosote - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/JamesDarf/tarpioka - https://github.com/JamesDarf/wargame-tarpioka - https://github.com/NaInSec/CVE-LIST - https://github.com/Ooscaar/MALW - https://github.com/PuddinCat/GithubRepoSpider - https://github.com/advanced-threat-research/Creosote - https://github.com/alextamkin/dabs - https://github.com/cptmorgan-rh/ocp_insights - https://github.com/davidholiday/CVE-2007-4559 - https://github.com/depers-rus/CVE-2007-4559 - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/ghostbyt3/patch-tuesday - https://github.com/luigigubello/trellix-tarslip-patch-bypass - https://github.com/m0d0ri205/wargame-tarpioka - https://github.com/snyk/zip-slip-vulnerability - https://github.com/woniwory/woniwory --- ### 2007/CVE 2007 4560 (2007/CVE-2007-4560.md) ### [CVE-2007-4560](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4560) ### Description clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail." ### POC #### Reference - http://securityreason.com/securityalert/3063 #### Github - https://github.com/0x1sac/ClamAV-Milter-Sendmail-0.91.2-Remote-Code-Execution - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/Mr-Tree-S/POC_EXP - https://github.com/Sic4rio/-Sendmail-with-clamav-milter-0.91.2---Remote-Command-Execution --- ### 2007/CVE 2007 4561 (2007/CVE-2007-4561.md) ### [CVE-2007-4561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4561) ### Description Heap-based buffer overflow in the RTSP service in Helix DNA Server before 11.1.4 allows remote attackers to execute arbitrary code via an RSTP command containing multiple Require headers. ### POC #### Reference - http://securityreason.com/securityalert/3069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4566 (2007/CVE-2007-4566.md) ### [CVE-2007-4566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4566) ### Description Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind. ### POC #### Reference - http://securityreason.com/securityalert/3061 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4571 (2007/CVE-2007-4571.md) ### [CVE-2007-4571](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4571) ### Description The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9053 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4573 (2007/CVE-2007-4573.md) ### [CVE-2007-4573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4573) ### Description The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9735 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/R0B1NL1N/linux-kernel-exploitation - https://github.com/Technoashofficial/kernel-exploitation-linux - https://github.com/kdn111/linux-kernel-exploitation - https://github.com/khanhdn111/linux-kernel-exploitation - https://github.com/khanhdz-06/linux-kernel-exploitation - https://github.com/khanhdz191/linux-kernel-exploitation - https://github.com/khanhhdz/linux-kernel-exploitation - https://github.com/khanhhdz06/linux-kernel-exploitation - https://github.com/khanhnd123/linux-kernel-exploitation - https://github.com/khnhdz/linux-kernel-exploitation - https://github.com/knd06/linux-kernel-exploitation - https://github.com/ndk06/linux-kernel-exploitation - https://github.com/ndk191/linux-kernel-exploitation - https://github.com/skbasava/Linux-Kernel-exploit - https://github.com/ssr-111/linux-kernel-exploitation - https://github.com/wkhnh06/linux-kernel-exploitation - https://github.com/xairy/linux-kernel-exploitation --- ### 2007/CVE 2007 4577 (2007/CVE-2007-4577.md) ### [CVE-2007-4577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4577) ### Description Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb"). ### POC #### Reference - http://securityreason.com/securityalert/3073 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4578 (2007/CVE-2007-4578.md) ### [CVE-2007-4578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4578) ### Description Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable. ### POC #### Reference - http://securityreason.com/securityalert/3072 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4581 (2007/CVE-2007-4581.md) ### [CVE-2007-4581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4581) ### Description SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL commands via the show parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4327 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4582 (2007/CVE-2007-4582.md) ### [CVE-2007-4582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4582) ### Description Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method. ### POC #### Reference - https://www.exploit-db.com/exploits/4322 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4583 (2007/CVE-2007-4583.md) ### [CVE-2007-4583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4583) ### Description Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4323 - https://www.exploit-db.com/exploits/4324 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4584 (2007/CVE-2007-4584.md) ### [CVE-2007-4584](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4584) ### Description Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable. ### POC #### Reference - https://www.exploit-db.com/exploits/4321 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4585 (2007/CVE-2007-4585.md) ### [CVE-2007-4585](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4585) ### Description Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4317 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4586 (2007/CVE-2007-4586.md) ### [CVE-2007-4586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4586) ### Description Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary code, probably during Unicode conversion, as demonstrated by a long string in the first argument to the iis_getservicestate function, related to the ServiceId argument to the (1) fnStartService, (2) fnGetServiceState, (3) fnStopService, and possibly other functions. ### POC #### Reference - https://www.exploit-db.com/exploits/4318 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4592 (2007/CVE-2007-4592.md) ### [CVE-2007-4592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4592) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component. ### POC #### Reference - http://securityreason.com/securityalert/3753 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4596 (2007/CVE-2007-4596.md) ### [CVE-2007-4596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4596) ### Description The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments. ### POC #### Reference - https://www.exploit-db.com/exploits/4314 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4597 (2007/CVE-2007-4597.md) ### [CVE-2007-4597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4597) ### Description SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549. ### POC #### Reference - https://www.exploit-db.com/exploits/4313 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4598 (2007/CVE-2007-4598.md) ### [CVE-2007-4598](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4598) ### Description IBM SurePOS 500 has (1) a default password of "12345" for the manager and (2) blank default passwords for operator accounts. ### POC #### Reference - http://isc.sans.org/diary.html?storyid=3323 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4600 (2007/CVE-2007-4600.md) ### [CVE-2007-4600](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4600) ### Description The "Protect Worksheet" functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element. ### POC #### Reference - http://securityreason.com/securityalert/3248 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4602 (2007/CVE-2007-4602.md) ### [CVE-2007-4602](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4602) ### Description SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4329 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4603 (2007/CVE-2007-4603.md) ### [CVE-2007-4603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4603) ### Description Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action. ### POC #### Reference - https://www.exploit-db.com/exploits/4330 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4604 (2007/CVE-2007-4604.md) ### [CVE-2007-4604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4604) ### Description SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4331 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4605 (2007/CVE-2007-4605.md) ### [CVE-2007-4605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4605) ### Description PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, and CVE-2006-1747. ### POC #### Reference - https://www.exploit-db.com/exploits/4332 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4606 (2007/CVE-2007-4606.md) ### [CVE-2007-4606](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4606) ### Description PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1602. NOTE: it is possible that this issue stems from a problem in VWar itself. ### POC #### Reference - https://www.exploit-db.com/exploits/4333 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4607 (2007/CVE-2007-4607.md) ### [CVE-2007-4607](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4607) ### Description Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15. ### POC #### Reference - https://www.exploit-db.com/exploits/4328 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/joeyrideout/CVE-2007-4607 --- ### 2007/CVE 2007 4620 (2007/CVE-2007-4620.md) ### [CVE-2007-4620](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4620) ### Description Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests. ### POC #### Reference - http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4627 (2007/CVE-2007-4627.md) ### [CVE-2007-4627](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4627) ### Description SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4338 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4628 (2007/CVE-2007-4628.md) ### [CVE-2007-4628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4628) ### Description SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4339 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4630 (2007/CVE-2007-4630.md) ### [CVE-2007-4630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4630) ### Description Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. ### POC #### Reference - http://securityreason.com/securityalert/3080 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4636 (2007/CVE-2007-4636.md) ### [CVE-2007-4636](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4636) ### Description Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4340 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4637 (2007/CVE-2007-4637.md) ### [CVE-2007-4637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4637) ### Description xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps. ### POC #### Reference - https://www.exploit-db.com/exploits/4336 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4638 (2007/CVE-2007-4638.md) ### [CVE-2007-4638](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4638) ### Description Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview. ### POC #### Reference - http://securityreason.com/securityalert/3086 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4640 (2007/CVE-2007-4640.md) ### [CVE-2007-4640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4640) ### Description Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action. ### POC #### Reference - https://www.exploit-db.com/exploits/4341 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4641 (2007/CVE-2007-4641.md) ### [CVE-2007-4641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4641) ### Description Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file. ### POC #### Reference - https://www.exploit-db.com/exploits/4341 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4642 (2007/CVE-2007-4642.md) ### [CVE-2007-4642](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4642) ### Description Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\0' character. ### POC #### Reference - http://aluigi.altervista.org/adv/dumsdei-adv.txt - http://aluigi.org/poc/dumsdei.zip - http://securityreason.com/securityalert/3084 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4643 (2007/CVE-2007-4643.md) ### [CVE-2007-4643](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4643) ### Description Integer underflow in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a PKT_CHAT packet with a data length less than 3, which triggers an erroneous malloc, possibly related to the Sv_HandlePacket function in sv_main.c. ### POC #### Reference - http://aluigi.org/poc/dumsdei.zip - http://securityreason.com/securityalert/3084 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4644 (2007/CVE-2007-4644.md) ### [CVE-2007-4644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4644) ### Description Format string vulnerability in the Cl_GetPackets function in cl_main.c in the client in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote Doomsday servers to execute arbitrary code via format string specifiers in a PSV_CONSOLE_TEXT message. ### POC #### Reference - http://aluigi.org/poc/dumsdei.zip - http://securityreason.com/securityalert/3084 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4645 (2007/CVE-2007-4645.md) ### [CVE-2007-4645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4645) ### Description SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108. ### POC #### Reference - https://www.exploit-db.com/exploits/4342 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4646 (2007/CVE-2007-4646.md) ### [CVE-2007-4646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4646) ### Description Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command. ### POC #### Reference - https://www.exploit-db.com/exploits/4344 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4647 (2007/CVE-2007-4647.md) ### [CVE-2007-4647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4647) ### Description newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi. ### POC #### Reference - https://www.exploit-db.com/exploits/4343 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4648 (2007/CVE-2007-4648.md) ### [CVE-2007-4648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4648) ### Description The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations. ### POC #### Reference - http://securityreason.com/securityalert/3087 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4649 (2007/CVE-2007-4649.md) ### [CVE-2007-4649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4649) ### Description MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe. ### POC #### Reference - http://securityreason.com/securityalert/3085 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4650 (2007/CVE-2007-4650.md) ### [CVE-2007-4650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4650) ### Description Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=191587 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4653 (2007/CVE-2007-4653.md) ### [CVE-2007-4653](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4653) ### Description SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action. ### POC #### Reference - https://www.exploit-db.com/exploits/4346 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4654 (2007/CVE-2007-4654.md) ### [CVE-2007-4654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4654) ### Description Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024. ### POC #### Reference No PoCs from references. #### Github - https://github.com/phx/cvescan --- ### 2007/CVE 2007 4662 (2007/CVE-2007-4662.md) ### [CVE-2007-4662](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4662) ### Description Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 4664 (2007/CVE-2007-4664.md) ### [CVE-2007-4664](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4664) ### Description Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4665 (2007/CVE-2007-4665.md) ### [CVE-2007-4665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4665) ### Description Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4666 (2007/CVE-2007-4666.md) ### [CVE-2007-4666](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4666) ### Description Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 - http://tracker.firebirdsql.org/browse/CORE-1397 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4667 (2007/CVE-2007-4667.md) ### [CVE-2007-4667](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4667) ### Description Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 - http://tracker.firebirdsql.org/browse/CORE-1149 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4668 (2007/CVE-2007-4668.md) ### [CVE-2007-4668](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4668) ### Description Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 - http://tracker.firebirdsql.org/browse/CORE-1312 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4669 (2007/CVE-2007-4669.md) ### [CVE-2007-4669](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4669) ### Description The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=535898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4684 (2007/CVE-2007-4684.md) ### [CVE-2007-4684](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4684) ### Description Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to the i386_set_ldt system call. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/rcvalle/vulnerabilities - https://github.com/risesecurity/vulnerabilities - https://github.com/swarna1010/Vulnerabilities --- ### 2007/CVE 2007 4686 (2007/CVE-2007-4686.md) ### [CVE-2007-4686](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4686) ### Description Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request. ### POC #### Reference - http://www.trapkit.de/advisories/TKADV2007-001.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4701 (2007/CVE-2007-4701.md) ### [CVE-2007-4701](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4701) ### Description WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 4712 (2007/CVE-2007-4712.md) ### [CVE-2007-4712](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4712) ### Description PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4356 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4714 (2007/CVE-2007-4714.md) ### [CVE-2007-4714](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4714) ### Description SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4353 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4715 (2007/CVE-2007-4715.md) ### [CVE-2007-4715](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4715) ### Description Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code via a URL in the files_dir parameter in (1) es_desp.php, (2) es_custom_menu.php, and (3) es_offer.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4352 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4716 (2007/CVE-2007-4716.md) ### [CVE-2007-4716](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4716) ### Description Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=536503 - http://sourceforge.net/project/shownotes.php?release_id=536503&group_id=170208 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4722 (2007/CVE-2007-4722.md) ### [CVE-2007-4722](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4722) ### Description Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods. ### POC #### Reference - https://www.exploit-db.com/exploits/4868 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4723 (2007/CVE-2007-4723.md) ### [CVE-2007-4723](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4723) ### Description Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page. ### POC #### Reference - http://securityreason.com/securityalert/3100 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/aabdul78/Penetration-Test - https://github.com/dusbot/cpe2cve - https://github.com/rmtec/modeswitcher - https://github.com/royans/aprober - https://github.com/xonoxitron/cpe2cve --- ### 2007/CVE 2007 4726 (2007/CVE-2007-4726.md) ### [CVE-2007-4726](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4726) ### Description Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. ### POC #### Reference - https://www.exploit-db.com/exploits/4362 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4727 (2007/CVE-2007-4727.md) ### [CVE-2007-4727](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4727) ### Description Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow." ### POC #### Reference - http://securityreason.com/securityalert/3127 - http://www.novell.com/linux/security/advisories/2007_20_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4731 (2007/CVE-2007-4731.md) ### [CVE-2007-4731](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4731) ### Description Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005. ### POC #### Reference - http://securityreason.com/securityalert/3128 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4734 (2007/CVE-2007-4734.md) ### [CVE-2007-4734](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4734) ### Description Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. ### POC #### Reference - https://www.exploit-db.com/exploits/4355 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4735 (2007/CVE-2007-4735.md) ### [CVE-2007-4735](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4735) ### Description Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. ### POC #### Reference - https://www.exploit-db.com/exploits/4354 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4736 (2007/CVE-2007-4736.md) ### [CVE-2007-4736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4736) ### Description SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4349 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4737 (2007/CVE-2007-4737.md) ### [CVE-2007-4737](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4737) ### Description Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4358 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4744 (2007/CVE-2007-4744.md) ### [CVE-2007-4744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4744) ### Description PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4365 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4745 (2007/CVE-2007-4745.md) ### [CVE-2007-4745](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4745) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function. ### POC #### Reference - http://securityreason.com/securityalert/3101 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4748 (2007/CVE-2007-4748.md) ### [CVE-2007-4748](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4748) ### Description Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4348 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4749 (2007/CVE-2007-4749.md) ### [CVE-2007-4749](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4749) ### Description The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks. ### POC #### Reference - http://securityreason.com/securityalert/3132 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4750 (2007/CVE-2007-4750.md) ### [CVE-2007-4750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4750) ### Description Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension. ### POC #### Reference - http://securityreason.com/securityalert/3150 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4751 (2007/CVE-2007-4751.md) ### [CVE-2007-4751](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4751) ### Description RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files. ### POC #### Reference - http://securityreason.com/securityalert/3150 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4752 (2007/CVE-2007-4752.md) ### [CVE-2007-4752](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4752) ### Description ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted. ### POC #### Reference - http://securityreason.com/securityalert/3126 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4753 (2007/CVE-2007-4753.md) ### [CVE-2007-4753](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4753) ### Description The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP message or (2) a SIP INVITE message with a malformed To header, different vectors than CVE-2007-4553. ### POC #### Reference - http://securityreason.com/securityalert/3104 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4754 (2007/CVE-2007-4754.md) ### [CVE-2007-4754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4754) ### Description Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname. ### POC #### Reference - http://aluigi.altervista.org/adv/aa2k7x-adv.txt - http://securityreason.com/securityalert/3105 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4755 (2007/CVE-2007-4755.md) ### [CVE-2007-4755](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4755) ### Description Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries. ### POC #### Reference - http://aluigi.altervista.org/adv/aa2k7x-adv.txt - http://securityreason.com/securityalert/3105 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4756 (2007/CVE-2007-4756.md) ### [CVE-2007-4756](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4756) ### Description Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via "..\" (dot dot backslash) sequences in a filename. NOTE: the "..\" are not displayed when the user lists files. NOTE: this can be leveraged for code execution by writing to a Startup folder. ### POC #### Reference - http://securityreason.com/securityalert/3106 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4757 (2007/CVE-2007-4757.md) ### [CVE-2007-4757](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4757) ### Description PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP code via a URL in the functions_file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4368 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4763 (2007/CVE-2007-4763.md) ### [CVE-2007-4763](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4763) ### Description PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPOF_INCLUDE_PATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4363 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4768 (2007/CVE-2007-4768.md) ### [CVE-2007-4768](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4768) ### Description Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9701 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4769 (2007/CVE-2007-4769.md) ### [CVE-2007-4769](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4769) ### Description The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9804 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/vmmaltsev/13.1 --- ### 2007/CVE 2007 4770 (2007/CVE-2007-4770.md) ### [CVE-2007-4770](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4770) ### Description libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4772 (2007/CVE-2007-4772.md) ### [CVE-2007-4772](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4772) ### Description The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2008-0009.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/vmmaltsev/13.1 --- ### 2007/CVE 2007 4776 (2007/CVE-2007-4776.md) ### [CVE-2007-4776](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4776) ### Description Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a vulnerability. ### POC #### Reference - https://www.exploit-db.com/exploits/4361 - https://www.exploit-db.com/exploits/4431 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4777 (2007/CVE-2007-4777.md) ### [CVE-2007-4777](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4777) ### Description SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778. ### POC #### Reference - http://securityreason.com/securityalert/3108 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4779 (2007/CVE-2007-4779.md) ### [CVE-2007-4779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4779) ### Description Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section. ### POC #### Reference - http://securityreason.com/securityalert/3108 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4780 (2007/CVE-2007-4780.md) ### [CVE-2007-4780](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4780) ### Description Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories. ### POC #### Reference - http://securityreason.com/securityalert/3108 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4781 (2007/CVE-2007-4781.md) ### [CVE-2007-4781](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4781) ### Description administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4350 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4782 (2007/CVE-2007-4782.md) ### [CVE-2007-4782](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4782) ### Description PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution. ### POC #### Reference - http://securityreason.com/securityalert/3109 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4783 (2007/CVE-2007-4783.md) ### [CVE-2007-4783](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4783) ### Description The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution. ### POC #### Reference - http://securityreason.com/securityalert/3115 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4784 (2007/CVE-2007-4784.md) ### [CVE-2007-4784](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4784) ### Description The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution. ### POC #### Reference - http://securityreason.com/securityalert/3114 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4785 (2007/CVE-2007-4785.md) ### [CVE-2007-4785](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4785) ### Description Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware detection by placing files in this directory. ### POC #### Reference - http://securityreason.com/securityalert/3118 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4788 (2007/CVE-2007-4788.md) ### [CVE-2007-4788](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4788) ### Description Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecified characteristics, aka CSCsd27478. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070905-csm.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4789 (2007/CVE-2007-4789.md) ### [CVE-2007-4789](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4789) ### Description Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to high network utilization, aka CSCsh57876. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20070905-csm.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4790 (2007/CVE-2007-4790.md) ### [CVE-2007-4790](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4790) ### Description Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010 - https://www.exploit-db.com/exploits/4369 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4802 (2007/CVE-2007-4802.md) ### [CVE-2007-4802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4802) ### Description Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll. ### POC #### Reference - https://www.exploit-db.com/exploits/4366 - https://www.exploit-db.com/exploits/4372 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4803 (2007/CVE-2007-4803.md) ### [CVE-2007-4803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4803) ### Description Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls file, as demonstrated by the (1) File1 and (2) Title1 fields, different vectors than CVE-2006-6287 and CVE-2007-2487. ### POC #### Reference - https://www.exploit-db.com/exploits/4364 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4804 (2007/CVE-2007-4804.md) ### [CVE-2007-4804](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4804) ### Description Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product's top-level default URI, using the pilih parameter, in some circumstances. ### POC #### Reference - https://www.exploit-db.com/exploits/4385 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4805 (2007/CVE-2007-4805.md) ### [CVE-2007-4805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4805) ### Description Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4378 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4806 (2007/CVE-2007-4806.md) ### [CVE-2007-4806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4806) ### Description PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4377 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4807 (2007/CVE-2007-4807.md) ### [CVE-2007-4807](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4807) ### Description Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakdownTime.php or (2) modules/Discipline/StudentFieldBreakdown.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4377 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4808 (2007/CVE-2007-4808.md) ### [CVE-2007-4808](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4808) ### Description Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1. ### POC #### Reference - https://www.exploit-db.com/exploits/4376 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4809 (2007/CVE-2007-4809.md) ### [CVE-2007-4809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4809) ### Description Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code via a URL in the DOC_ROOT parameter to (1) lib/functions.php or (2) lib/header.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4374 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4810 (2007/CVE-2007-4810.md) ### [CVE-2007-4810](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4810) ### Description Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php. ### POC #### Reference - http://securityreason.com/securityalert/3110 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4811 (2007/CVE-2007-4811.md) ### [CVE-2007-4811](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4811) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in an alpha.albums action, or the PATH_INFO to (2) random.php or (3) admin/hidden.php. ### POC #### Reference - http://securityreason.com/securityalert/3110 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4812 (2007/CVE-2007-4812.md) ### [CVE-2007-4812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4812) ### Description Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. NOTE: the crash might actually occur in the alert method. ### POC #### Reference - http://securityreason.com/securityalert/3111 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4814 (2007/CVE-2007-4814.md) ### [CVE-2007-4814](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4814) ### Description Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method. ### POC #### Reference - http://securityreason.com/securityalert/3112 - https://www.exploit-db.com/exploits/4379 - https://www.exploit-db.com/exploits/4398 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4815 (2007/CVE-2007-4815.md) ### [CVE-2007-4815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4815) ### Description Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code via a URL in the Codebase parameter to (1) channeledit.php, (2) post.php, (3) view.php, or (4) viewitem.php in source/mod/rss/. ### POC #### Reference - https://www.exploit-db.com/exploits/4384 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4816 (2007/CVE-2007-4816.md) ### [CVE-2007-4816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4816) ### Description Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList. ### POC #### Reference - https://www.exploit-db.com/exploits/4375 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4817 (2007/CVE-2007-4817.md) ### [CVE-2007-4817](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4817) ### Description Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/. ### POC #### Reference - https://www.exploit-db.com/exploits/4383 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4818 (2007/CVE-2007-4818.md) ### [CVE-2007-4818](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4818) ### Description Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) addons/plugin.php, (2) addons/sidebar.php, (3) mail/index.php, or (4) mail/mailbox.php in modules/. ### POC #### Reference - http://securityreason.com/securityalert/3116 - https://www.exploit-db.com/exploits/4381 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4819 (2007/CVE-2007-4819.md) ### [CVE-2007-4819](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4819) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3116 - https://www.exploit-db.com/exploits/4381 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4820 (2007/CVE-2007-4820.md) ### [CVE-2007-4820](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4820) ### Description Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4380 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4821 (2007/CVE-2007-4821.md) ### [CVE-2007-4821](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4821) ### Description Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169. ### POC #### Reference - https://www.exploit-db.com/exploits/4373 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4822 (2007/CVE-2007-4822.md) ### [CVE-2007-4822](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4822) ### Description Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filter_ip.html. ### POC #### Reference - http://securityreason.com/securityalert/3117 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4825 (2007/CVE-2007-4825.md) ### [CVE-2007-4825](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4825) ### Description Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function. ### POC #### Reference - http://securityreason.com/securityalert/3119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4827 (2007/CVE-2007-4827.md) ### [CVE-2007-4827](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4827) ### Description Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502. ### POC #### Reference - http://www.nessus.org/plugins/index.php?view=single&id=26066 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4832 (2007/CVE-2007-4832.md) ### [CVE-2007-4832](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4832) ### Description Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. ### POC #### Reference - http://aluigi.altervista.org/adv/cellfucktor-adv.txt - http://securityreason.com/securityalert/3130 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4834 (2007/CVE-2007-4834.md) ### [CVE-2007-4834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4834) ### Description Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/. ### POC #### Reference - https://www.exploit-db.com/exploits/4387 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4835 (2007/CVE-2007-4835.md) ### [CVE-2007-4835](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4835) ### Description SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action. ### POC #### Reference - http://securityreason.com/securityalert/3120 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4836 (2007/CVE-2007-4836.md) ### [CVE-2007-4836](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4836) ### Description Cross-site scripting (XSS) vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action. ### POC #### Reference - http://securityreason.com/securityalert/3120 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4837 (2007/CVE-2007-4837.md) ### [CVE-2007-4837](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4837) ### Description SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/3121 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4838 (2007/CVE-2007-4838.md) ### [CVE-2007-4838](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4838) ### Description Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. ### POC #### Reference - http://aluigi.altervista.org/adv/cellfucktor-adv.txt - http://aluigi.org/poc/cellfucktor.zip - http://securityreason.com/securityalert/3130 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4840 (2007/CVE-2007-4840.md) ### [CVE-2007-4840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4840) ### Description PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution. ### POC #### Reference - http://securityreason.com/securityalert/3122 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4841 (2007/CVE-2007-4841.md) ### [CVE-2007-4841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4841) ### Description Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4842 (2007/CVE-2007-4842.md) ### [CVE-2007-4842](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4842) ### Description Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder. ### POC #### Reference - http://securityreason.com/securityalert/3123 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4843 (2007/CVE-2007-4843.md) ### [CVE-2007-4843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4843) ### Description Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder. ### POC #### Reference - http://securityreason.com/securityalert/3125 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4844 (2007/CVE-2007-4844.md) ### [CVE-2007-4844](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4844) ### Description X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CWD /" command, which allows remote FTP servers to cause a denial of service (infinite loop) by (1) repeatedly sending a 550 error response, or (2) sending a 550 error response and then disconnecting. ### POC #### Reference - http://securityreason.com/securityalert/3125 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4845 (2007/CVE-2007-4845.md) ### [CVE-2007-4845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4845) ### Description Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4371 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4846 (2007/CVE-2007-4846.md) ### [CVE-2007-4846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4846) ### Description SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik go action. ### POC #### Reference - https://www.exploit-db.com/exploits/4370 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4872 (2007/CVE-2007-4872.md) ### [CVE-2007-4872](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4872) ### Description SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages. ### POC #### Reference - http://securityreason.com/securityalert/3174 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4873 (2007/CVE-2007-4873.md) ### [CVE-2007-4873](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4873) ### Description SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc. ### POC #### Reference - http://securityreason.com/securityalert/3173 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4874 (2007/CVE-2007-4874.md) ### [CVE-2007-4874](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4874) ### Description Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php. ### POC #### Reference - http://securityreason.com/securityalert/3166 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4879 (2007/CVE-2007-4879.md) ### [CVE-2007-4879](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4879) ### Description Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains. ### POC #### Reference - http://0x90.eu/ff_tls_poc.html - http://www.ubuntu.com/usn/usn-592-1 - https://bugzilla.mozilla.org/show_bug.cgi?id=395399 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4880 (2007/CVE-2007-4880.md) ### [CVE-2007-4880](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4880) ### Description Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905. ### POC #### Reference - http://securityreason.com/securityalert/3184 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4881 (2007/CVE-2007-4881.md) ### [CVE-2007-4881](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4881) ### Description SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter. ### POC #### Reference - http://securityreason.com/securityalert/3131 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4886 (2007/CVE-2007-4886.md) ### [CVE-2007-4886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4886) ### Description Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs. ### POC #### Reference - https://www.exploit-db.com/exploits/4390 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4887 (2007/CVE-2007-4887.md) ### [CVE-2007-4887](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4887) ### Description The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability. ### POC #### Reference - http://securityreason.com/securityalert/3133 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4889 (2007/CVE-2007-4889.md) ### [CVE-2007-4889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4889) ### Description The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997. ### POC #### Reference - http://securityreason.com/securityalert/3134 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4890 (2007/CVE-2007-4890.md) ### [CVE-2007-4890](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4890) ### Description Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method. ### POC #### Reference - https://www.exploit-db.com/exploits/4394 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4891 (2007/CVE-2007-4891.md) ### [CVE-2007-4891](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4891) ### Description A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell. ### POC #### Reference - https://www.exploit-db.com/exploits/4393 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4893 (2007/CVE-2007-4893.md) ### [CVE-2007-4893](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4893) ### Description wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4894 (2007/CVE-2007-4894.md) ### [CVE-2007-4894](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4894) ### Description Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters." ### POC #### Reference - http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 4895 (2007/CVE-2007-4895.md) ### [CVE-2007-4895](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4895) ### Description Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4386 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4897 (2007/CVE-2007-4897.md) ### [CVE-2007-4897](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4897) ### Description pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting). ### POC #### Reference - http://securityreason.com/securityalert/3138 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4899 (2007/CVE-2007-4899.md) ### [CVE-2007-4899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4899) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search. ### POC #### Reference - http://securityreason.com/securityalert/3139 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4900 (2007/CVE-2007-4900.md) ### [CVE-2007-4900](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4900) ### Description Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field. ### POC #### Reference - http://securityreason.com/securityalert/3137 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4901 (2007/CVE-2007-4901.md) ### [CVE-2007-4901](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4901) ### Description The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC. ### POC #### Reference - http://securityreason.com/securityalert/3136 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4902 (2007/CVE-2007-4902.md) ### [CVE-2007-4902](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4902) ### Description Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4388 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4903 (2007/CVE-2007-4903.md) ### [CVE-2007-4903](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4903) ### Description Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method. ### POC #### Reference - https://www.exploit-db.com/exploits/4389 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4905 (2007/CVE-2007-4905.md) ### [CVE-2007-4905](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4905) ### Description Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/. ### POC #### Reference - https://www.exploit-db.com/exploits/4390 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4906 (2007/CVE-2007-4906.md) ### [CVE-2007-4906](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4906) ### Description PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. ### POC #### Reference - http://securityreason.com/securityalert/3142 - https://www.exploit-db.com/exploits/4395 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4907 (2007/CVE-2007-4907.md) ### [CVE-2007-4907](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4907) ### Description Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and (6) admin/auth.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4396 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4908 (2007/CVE-2007-4908.md) ### [CVE-2007-4908](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4908) ### Description Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4390 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4909 (2007/CVE-2007-4909.md) ### [CVE-2007-4909](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4909) ### Description Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015. ### POC #### Reference - http://securityreason.com/securityalert/3141 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4911 (2007/CVE-2007-4911.md) ### [CVE-2007-4911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4911) ### Description JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4403 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4915 (2007/CVE-2007-4915.md) ### [CVE-2007-4915](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4915) ### Description The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request. ### POC #### Reference - http://securityreason.com/securityalert/3151 - https://www.exploit-db.com/exploits/4542 #### Github - https://github.com/Knighthana/YABWF --- ### 2007/CVE 2007 4916 (2007/CVE-2007-4916.md) ### [CVE-2007-4916](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4916) ### Description Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument. ### POC #### Reference - http://securityreason.com/securityalert/3143 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4917 (2007/CVE-2007-4917.md) ### [CVE-2007-4917](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4917) ### Description Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334. ### POC #### Reference - http://securityreason.com/securityalert/3149 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4918 (2007/CVE-2007-4918.md) ### [CVE-2007-4918](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4918) ### Description SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php. ### POC #### Reference - http://securityreason.com/securityalert/3148 - https://www.exploit-db.com/exploits/4410 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4919 (2007/CVE-2007-4919.md) ### [CVE-2007-4919](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4919) ### Description Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4408 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4920 (2007/CVE-2007-4920.md) ### [CVE-2007-4920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4920) ### Description SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4407 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4921 (2007/CVE-2007-4921.md) ### [CVE-2007-4921](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4921) ### Description PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4405 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4922 (2007/CVE-2007-4922.md) ### [CVE-2007-4922](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4922) ### Description SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4400 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4923 (2007/CVE-2007-4923.md) ### [CVE-2007-4923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4923) ### Description PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4401 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4924 (2007/CVE-2007-4924.md) ### [CVE-2007-4924](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4924) ### Description The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address." ### POC #### Reference - https://www.exploit-db.com/exploits/9240 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4926 (2007/CVE-2007-4926.md) ### [CVE-2007-4926](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4926) ### Description The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors. ### POC #### Reference - http://securityreason.com/securityalert/3145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4927 (2007/CVE-2007-4927.md) ### [CVE-2007-4927](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4927) ### Description axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action. ### POC #### Reference - http://securityreason.com/securityalert/3145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4928 (2007/CVE-2007-4928.md) ### [CVE-2007-4928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4928) ### Description The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information. ### POC #### Reference - http://securityreason.com/securityalert/3145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4929 (2007/CVE-2007-4929.md) ### [CVE-2007-4929](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4929) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4930 (2007/CVE-2007-4930.md) ### [CVE-2007-4930](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4930) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml. ### POC #### Reference - http://securityreason.com/securityalert/3145 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4931 (2007/CVE-2007-4931.md) ### [CVE-2007-4931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4931) ### Description HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 4932 (2007/CVE-2007-4932.md) ### [CVE-2007-4932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4932) ### Description admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel. ### POC #### Reference - https://www.exploit-db.com/exploits/4419 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4933 (2007/CVE-2007-4933.md) ### [CVE-2007-4933](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4933) ### Description Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4419 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4934 (2007/CVE-2007-4934.md) ### [CVE-2007-4934](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4934) ### Description Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4406 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4937 (2007/CVE-2007-4937.md) ### [CVE-2007-4937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4937) ### Description CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php. ### POC #### Reference - http://securityreason.com/securityalert/3147 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4938 (2007/CVE-2007-4938.md) ### [CVE-2007-4938](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4938) ### Description Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value. ### POC #### Reference - http://securityreason.com/securityalert/3144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4939 (2007/CVE-2007-4939.md) ### [CVE-2007-4939](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4939) ### Description Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with an "indx truck size" of 0xffffffff, and certain wLongsPerEntry and nEntriesInuse values. ### POC #### Reference - http://securityreason.com/securityalert/3144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4940 (2007/CVE-2007-4940.md) ### [CVE-2007-4940](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4940) ### Description Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values. ### POC #### Reference - http://securityreason.com/securityalert/3144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4941 (2007/CVE-2007-4941.md) ### [CVE-2007-4941](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4941) ### Description KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values. ### POC #### Reference - http://securityreason.com/securityalert/3144 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4943 (2007/CVE-2007-4943.md) ### [CVE-2007-4943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4943) ### Description Multiple buffer overflows in a certain ActiveX control in sparser.dll in Baofeng Storm 2.8 and earlier allow remote attackers to execute arbitrary code via malformed input in an unknown set of arguments or property values, a different DLL than CVE-2007-4816. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 4952 (2007/CVE-2007-4952.md) ### [CVE-2007-4952](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4952) ### Description SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917. ### POC #### Reference - https://www.exploit-db.com/exploits/4418 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4953 (2007/CVE-2007-4953.md) ### [CVE-2007-4953](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4953) ### Description SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action. ### POC #### Reference - https://www.exploit-db.com/exploits/4417 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4954 (2007/CVE-2007-4954.md) ### [CVE-2007-4954](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4954) ### Description PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4416 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4955 (2007/CVE-2007-4955.md) ### [CVE-2007-4955](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4955) ### Description PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4415 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4956 (2007/CVE-2007-4956.md) ### [CVE-2007-4956](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4956) ### Description Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module. ### POC #### Reference - https://www.exploit-db.com/exploits/4412 - https://www.exploit-db.com/exploits/4413 - https://www.exploit-db.com/exploits/4414 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4957 (2007/CVE-2007-4957.md) ### [CVE-2007-4957](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4957) ### Description Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4411 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4960 (2007/CVE-2007-4960.md) ### [CVE-2007-4960](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4960) ### Description Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, allows remote attackers to obtain sensitive information via a '" ' (double-quote space) sequence followed by the -autologin and -loginuri arguments, which cause the handler to post login credentials and software installation details to an arbitrary URL. ### POC #### Reference - http://www.gnucitizen.org/blog/ie-pwns-secondlife #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4961 (2007/CVE-2007-4961.md) ### [CVE-2007-4961](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4961) ### Description The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server. ### POC #### Reference - http://www.gnucitizen.org/blog/ie-pwns-secondlife #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4962 (2007/CVE-2007-4962.md) ### [CVE-2007-4962](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4962) ### Description Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder. ### POC #### Reference - http://securityreason.com/securityalert/3140 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4963 (2007/CVE-2007-4963.md) ### [CVE-2007-4963](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4963) ### Description Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of space characters in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged with a separate directory traversal vulnerability to trick a careful user into overwriting arbitrary files. ### POC #### Reference - http://securityreason.com/securityalert/3140 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4964 (2007/CVE-2007-4964.md) ### [CVE-2007-4964](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4964) ### Description WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file. ### POC #### Reference - http://securityreason.com/securityalert/3140 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4965 (2007/CVE-2007-4965.md) ### [CVE-2007-4965](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4965) ### Description Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=192876 - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 4966 (2007/CVE-2007-4966.md) ### [CVE-2007-4966](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4966) ### Description SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4404 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4975 (2007/CVE-2007-4975.md) ### [CVE-2007-4975](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4975) ### Description Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter. ### POC #### Reference - http://securityreason.com/securityalert/3155 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4976 (2007/CVE-2007-4976.md) ### [CVE-2007-4976](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4976) ### Description Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter. ### POC #### Reference - http://securityreason.com/securityalert/3152 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4977 (2007/CVE-2007-4977.md) ### [CVE-2007-4977](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4977) ### Description Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter. ### POC #### Reference - http://securityreason.com/securityalert/3152 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4978 (2007/CVE-2007-4978.md) ### [CVE-2007-4978](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4978) ### Description Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/. ### POC #### Reference - https://www.exploit-db.com/exploits/4421 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4979 (2007/CVE-2007-4979.md) ### [CVE-2007-4979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4979) ### Description SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2. ### POC #### Reference - https://www.exploit-db.com/exploits/4422 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4980 (2007/CVE-2007-4980.md) ### [CVE-2007-4980](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4980) ### Description The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError. ### POC #### Reference - http://securityreason.com/securityalert/3154 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4981 (2007/CVE-2007-4981.md) ### [CVE-2007-4981](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4981) ### Description Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a document. NOTE: because the details of the attack are uncertain, it is unclear whether this crosses privilege boundaries. ### POC #### Reference - http://securityreason.com/securityalert/3153 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4982 (2007/CVE-2007-4982.md) ### [CVE-2007-4982](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4982) ### Description Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4420 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4983 (2007/CVE-2007-4983.md) ### [CVE-2007-4983](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4983) ### Description Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call. ### POC #### Reference - https://www.exploit-db.com/exploits/4427 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4984 (2007/CVE-2007-4984.md) ### [CVE-2007-4984](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4984) ### Description SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4425 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4985 (2007/CVE-2007-4985.md) ### [CVE-2007-4985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4985) ### Description ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls. ### POC #### Reference - http://www.imagemagick.org/script/changelog.php - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10869 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4986 (2007/CVE-2007-4986.md) ### [CVE-2007-4986](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4986) ### Description Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow. ### POC #### Reference - http://www.imagemagick.org/script/changelog.php - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9963 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4987 (2007/CVE-2007-4987.md) ### [CVE-2007-4987](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4987) ### Description Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address. ### POC #### Reference - http://www.imagemagick.org/script/changelog.php #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4988 (2007/CVE-2007-4988.md) ### [CVE-2007-4988](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4988) ### Description Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow. ### POC #### Reference - http://www.imagemagick.org/script/changelog.php - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9656 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 4995 (2007/CVE-2007-4995.md) ### [CVE-2007-4995](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4995) ### Description Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0964.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 5000 (2007/CVE-2007-5000.md) ### [CVE-2007-5000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000) ### Description Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html - http://www.vupen.com/english/advisories/2008/1697 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9539 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/kasem545/vulnsearch - https://github.com/krlabs/apache-vulnerabilities - https://github.com/masterkillah2009/Port-Scanner - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 5009 (2007/CVE-2007-5009.md) ### [CVE-2007-5009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5009) ### Description PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4434 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5015 (2007/CVE-2007-5015.md) ### [CVE-2007-5015](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5015) ### Description Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support. ### POC #### Reference - https://www.exploit-db.com/exploits/4430 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5016 (2007/CVE-2007-5016.md) ### [CVE-2007-5016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5016) ### Description SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4433 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5017 (2007/CVE-2007-5017.md) ### [CVE-2007-5017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5017) ### Description Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4428 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5018 (2007/CVE-2007-5018.md) ### [CVE-2007-5018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5018) ### Description Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211. ### POC #### Reference - https://www.exploit-db.com/exploits/4429 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5019 (2007/CVE-2007-5019.md) ### [CVE-2007-5019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5019) ### Description Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method. ### POC #### Reference - https://www.exploit-db.com/exploits/4432 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5020 (2007/CVE-2007-5020.md) ### [CVE-2007-5020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5020) ### Description Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher. ### POC #### Reference - http://www.gnucitizen.org/blog/0day-pdf-pwns-windows #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 5023 (2007/CVE-2007-5023.md) ### [CVE-2007-5023](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5023) ### Description Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder. ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5024 (2007/CVE-2007-5024.md) ### [CVE-2007-5024](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5024) ### Description EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2005-3620. ### POC #### Reference - http://www.vmware.com/support/server/doc/releasenotes_server.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5025 (2007/CVE-2007-5025.md) ### [CVE-2007-5025](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5025) ### Description Unspecified vulnerability in EMC VMware ACE before 1.0.3 Build 54075 allows attackers to have an unknown impact via an unspecified manipulation of "images stored in virtual machines downloaded by the user." ### POC #### Reference - http://www.vmware.com/support/ace/doc/releasenotes_ace.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5026 (2007/CVE-2007-5026.md) ### [CVE-2007-5026](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5026) ### Description dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb. ### POC #### Reference - http://securityreason.com/securityalert/3156 - http://www.waraxe.us/advisory-52.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5027 (2007/CVE-2007-5027.md) ### [CVE-2007-5027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5027) ### Description Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter. ### POC #### Reference - http://securityreason.com/securityalert/3159 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5032 (2007/CVE-2007-5032.md) ### [CVE-2007-5032](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5032) ### Description Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters. ### POC #### Reference - http://securityreason.com/securityalert/3157 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5033 (2007/CVE-2007-5033.md) ### [CVE-2007-5033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5033) ### Description Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action. ### POC #### Reference - http://securityreason.com/securityalert/3158 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5034 (2007/CVE-2007-5034.md) ### [CVE-2007-5034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5034) ### Description ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https. ### POC #### Reference - http://www.ubuntu.com/usn/usn-519-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5036 (2007/CVE-2007-5036.md) ### [CVE-2007-5036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5036) ### Description Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter." ### POC #### Reference - https://www.exploit-db.com/exploits/4426 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2007/CVE 2007 5039 (2007/CVE-2007-5039.md) ### [CVE-2007-5039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5039) ### Description Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4) NtSetSystemInformation, and (5) NtSetValueKey kernel SSDT hooks. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5040 (2007/CVE-2007-5040.md) ### [CVE-2007-5040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5040) ### Description Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtCreateThread, (3) NtDeleteValueKey, (4) NtQueryValueKey, (5) NtSetSystemInformation, and (6) NtSetValueKey kernel SSDT hooks. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5041 (2007/CVE-2007-5041.md) ### [CVE-2007-5041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5041) ### Description G DATA InternetSecurity 2007 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey and (2) NtOpenProcess kernel SSDT hooks. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5042 (2007/CVE-2007-5042.md) ### [CVE-2007-5042](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5042) ### Description Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenProcess, (5) NtOpenSection, (6) NtOpenThread, and (7) NtUnloadDriver kernel SSDT hooks, a partial regression of CVE-2006-7160. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5043 (2007/CVE-2007-5043.md) ### [CVE-2007-5043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5043) ### Description Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service (avp.exe service outage) via the NtLoadDriver kernel SSDT hook. NOTE: this issue may partially overlap CVE-2006-3074. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5044 (2007/CVE-2007-5044.md) ### [CVE-2007-5044](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5044) ### Description ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel SSDT hooks, a partial regression of CVE-2007-2083. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5045 (2007/CVE-2007-5045.md) ### [CVE-2007-5045](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5045) ### Description Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670. ### POC #### Reference - http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5047 (2007/CVE-2007-5047.md) ### [CVE-2007-5047](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5047) ### Description Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-2007-1793. ### POC #### Reference - http://securityreason.com/securityalert/3161 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5050 (2007/CVE-2007-5050.md) ### [CVE-2007-5050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5050) ### Description Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4439 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5052 (2007/CVE-2007-5052.md) ### [CVE-2007-5052](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5052) ### Description Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module with (1) the title parameter or (2) a "title=" sequence in the PATH_INFO, or a request to the download module with (3) the cat parameter or (4) a "cat=" sequence in the PATH_INFO. ### POC #### Reference - http://securityreason.com/securityalert/3162 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5053 (2007/CVE-2007-5053.md) ### [CVE-2007-5053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5053) ### Description Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php; or a URL in the language_home parameter to (3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, or (7) links/submit_links.php in modules/; related to missing checks in (a) modules/moduleSec.php and (b) include/includeSec.php for inclusion of certain URLs, as demonstrated by an ftps:// URL. ### POC #### Reference - https://www.exploit-db.com/exploits/4441 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5054 (2007/CVE-2007-5054.md) ### [CVE-2007-5054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5054) ### Description Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4) links/showlinks.php, or (5) links/submit_links.php in modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/4441 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5055 (2007/CVE-2007-5055.md) ### [CVE-2007-5055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5055) ### Description Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4441 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5056 (2007/CVE-2007-5056.md) ### [CVE-2007-5056](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5056) ### Description Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4442 - https://www.exploit-db.com/exploits/5090 - https://www.exploit-db.com/exploits/5091 - https://www.exploit-db.com/exploits/5097 - https://www.exploit-db.com/exploits/5098 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5057 (2007/CVE-2007-5057.md) ### [CVE-2007-5057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5057) ### Description NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager. ### POC #### Reference - http://securityreason.com/securityalert/3163 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5058 (2007/CVE-2007-5058.md) ### [CVE-2007-5058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5058) ### Description Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open. ### POC #### Reference - http://securityreason.com/securityalert/3164 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5060 (2007/CVE-2007-5060.md) ### [CVE-2007-5060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5060) ### Description Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values. ### POC #### Reference - http://securityreason.com/securityalert/3165 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5061 (2007/CVE-2007-5061.md) ### [CVE-2007-5061](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5061) ### Description SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3249 - https://www.exploit-db.com/exploits/4443 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5062 (2007/CVE-2007-5062.md) ### [CVE-2007-5062](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5062) ### Description account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action. ### POC #### Reference - https://www.exploit-db.com/exploits/4435 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5063 (2007/CVE-2007-5063.md) ### [CVE-2007-5063](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5063) ### Description Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt. ### POC #### Reference - https://www.exploit-db.com/exploits/4436 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5065 (2007/CVE-2007-5065.md) ### [CVE-2007-5065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5065) ### Description PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4440 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5067 (2007/CVE-2007-5067.md) ### [CVE-2007-5067](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5067) ### Description Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe. ### POC #### Reference - https://www.exploit-db.com/exploits/4450 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5068 (2007/CVE-2007-5068.md) ### [CVE-2007-5068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5068) ### Description SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL commands via the mod parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4449 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5069 (2007/CVE-2007-5069.md) ### [CVE-2007-5069](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5069) ### Description Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4447 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5070 (2007/CVE-2007-5070.md) ### [CVE-2007-5070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5070) ### Description Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail MessagePrinter Object allows remote attackers to execute arbitrary code via a long string in the first argument to the SetFont method. ### POC #### Reference - https://www.exploit-db.com/exploits/4445 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5078 (2007/CVE-2007-5078.md) ### [CVE-2007-5078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5078) ### Description Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied input" to (1) center.exe or (2) Index.exe. ### POC #### Reference - http://securityreason.com/securityalert/3192 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5089 (2007/CVE-2007-5089.md) ### [CVE-2007-5089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5089) ### Description PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SKIN_URL parameter. ### POC #### Reference - http://securityreason.com/securityalert/3168 - https://www.exploit-db.com/exploits/4454 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5092 (2007/CVE-2007-5092.md) ### [CVE-2007-5092](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5092) ### Description Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php. ### POC #### Reference - http://securityreason.com/securityalert/3169 - http://www.waraxe.us/advisory-54.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5094 (2007/CVE-2007-5094.md) ### [CVE-2007-5094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5094) ### Description Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in the header, and a long Content-Transfer-Encoding header line. ### POC #### Reference - http://pstgroup.blogspot.com/2007/09/exploitimail-iaspamdll-80x-remote-heap.html - https://www.exploit-db.com/exploits/4438 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5095 (2007/CVE-2007-5095.md) ### [CVE-2007-5095](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5095) ### Description Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file. ### POC #### Reference - http://www.gnucitizen.org/blog/backdooring-windows-media-files #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5098 (2007/CVE-2007-5098.md) ### [CVE-2007-5098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5098) ### Description Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the set_depth parameter to (1) app.lib/product.control/core.php/product.control.config.php, or (2) customer.browse.list.php or (3) customer.browse.search.php in app.lib/product.control/core.php/customer.area/. ### POC #### Reference - https://www.exploit-db.com/exploits/4451 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5099 (2007/CVE-2007-5099.md) ### [CVE-2007-5099](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5099) ### Description PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4448 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5102 (2007/CVE-2007-5102.md) ### [CVE-2007-5102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5102) ### Description PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4446 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5103 (2007/CVE-2007-5103.md) ### [CVE-2007-5103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5103) ### Description Directory traversal vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4446 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5105 (2007/CVE-2007-5105.md) ### [CVE-2007-5105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5105) ### Description Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter. ### POC #### Reference - http://securityreason.com/securityalert/3175 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 5106 (2007/CVE-2007-5106.md) ### [CVE-2007-5106](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5106) ### Description Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter. ### POC #### Reference - http://securityreason.com/securityalert/3175 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 5107 (2007/CVE-2007-5107.md) ### [CVE-2007-5107](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5107) ### Description Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. NOTE: some of these details are obtained from third party information. NOTE: the researcher claims that this is the same as CVE-2007-5108, but there is insufficient detail for CVE-2007-5108 to be certain. ### POC #### Reference - https://www.exploit-db.com/exploits/4452 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5109 (2007/CVE-2007-5109.md) ### [CVE-2007-5109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5109) ### Description Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object to automatically make the request. ### POC #### Reference - http://securityreason.com/securityalert/3176 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5110 (2007/CVE-2007-5110.md) ### [CVE-2007-5110](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5110) ### Description Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4453 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5111 (2007/CVE-2007-5111.md) ### [CVE-2007-5111](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5111) ### Description A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (crash) via a string argument to the AddString method. ### POC #### Reference - https://www.exploit-db.com/exploits/4453 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5112 (2007/CVE-2007-5112.md) ### [CVE-2007-5112](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5112) ### Description Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers that support remembered (auto-completed) passwords. ### POC #### Reference - http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/ - http://securityreason.com/securityalert/3177 - http://www.gnucitizen.org/blog/google-urchin-password-theft-madness #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5117 (2007/CVE-2007-5117.md) ### [CVE-2007-5117](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5117) ### Description Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279. ### POC #### Reference - https://www.exploit-db.com/exploits/4456 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5119 (2007/CVE-2007-5119.md) ### [CVE-2007-5119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5119) ### Description JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/. ### POC #### Reference - http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/066096.html - http://securityreason.com/securityalert/3167 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5120 (2007/CVE-2007-5120.md) ### [CVE-2007-5120](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5120) ### Description Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp. ### POC #### Reference - http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/066096.html - http://securityreason.com/securityalert/3167 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5121 (2007/CVE-2007-5121.md) ### [CVE-2007-5121](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5121) ### Description Cross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to wiki-3/Login.jsp and unspecified other components. ### POC #### Reference - http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/066096.html - http://securityreason.com/securityalert/3167 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5122 (2007/CVE-2007-5122.md) ### [CVE-2007-5122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5122) ### Description SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4457 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5123 (2007/CVE-2007-5123.md) ### [CVE-2007-5123](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5123) ### Description SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the nota_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4458 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5127 (2007/CVE-2007-5127.md) ### [CVE-2007-5127](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5127) ### Description Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php. ### POC #### Reference - http://securityreason.com/securityalert/3171 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5128 (2007/CVE-2007-5128.md) ### [CVE-2007-5128](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5128) ### Description SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows. ### POC #### Reference - http://securityreason.com/securityalert/3174 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5130 (2007/CVE-2007-5130.md) ### [CVE-2007-5130](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5130) ### Description SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reveals the path in various error messages. ### POC #### Reference - http://securityreason.com/securityalert/3172 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5131 (2007/CVE-2007-5131.md) ### [CVE-2007-5131](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5131) ### Description SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4459 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5134 (2007/CVE-2007-5134.md) ### [CVE-2007-5134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5134) ### Description Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5135 (2007/CVE-2007-5135.md) ### [CVE-2007-5135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5135) ### Description Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible. ### POC #### Reference - http://securityreason.com/securityalert/3179 - http://www.novell.com/linux/security/advisories/2007_20_sr.html - http://www.redhat.com/support/errata/RHSA-2007-0964.html #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 5137 (2007/CVE-2007-5137.md) ### [CVE-2007-5137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5137) ### Description Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first. NOTE: this issue is due to an incorrect patch for CVE-2007-5378. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_20_sr.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9540 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5138 (2007/CVE-2007-5138.md) ### [CVE-2007-5138](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5138) ### Description PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4461 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5139 (2007/CVE-2007-5139.md) ### [CVE-2007-5139](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5139) ### Description PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4462 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5140 (2007/CVE-2007-5140.md) ### [CVE-2007-5140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5140) ### Description PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4463 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5141 (2007/CVE-2007-5141.md) ### [CVE-2007-5141](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5141) ### Description SQL injection vulnerability in search.php in SiteX CMS 0.7.3 Beta allows remote attackers to execute arbitrary SQL commands via the search parameter. ### POC #### Reference - http://securityreason.com/securityalert/3178 - http://www.waraxe.us/advisory-55.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5149 (2007/CVE-2007-5149.md) ### [CVE-2007-5149](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5149) ### Description PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the indir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4465 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5150 (2007/CVE-2007-5150.md) ### [CVE-2007-5150](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5150) ### Description SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125. ### POC #### Reference - http://securityreason.com/securityalert/3181 - http://www.waraxe.us/advisory-56.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5151 (2007/CVE-2007-5151.md) ### [CVE-2007-5151](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5151) ### Description SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie. ### POC #### Reference - http://www.waraxe.us/advisory-58.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5155 (2007/CVE-2007-5155.md) ### [CVE-2007-5155](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5155) ### Description IceGUI.DLL in ICEOWS 4.20b invokes a function with incorrect arguments, which allows user-assisted remote attackers to execute arbitrary code via a long filename in the header of an ACE archive, which triggers a stack-based buffer overflow. ### POC #### Reference - http://vuln.sg/iceows420b-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5156 (2007/CVE-2007-5156.md) ### [CVE-2007-5156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5156) ### Description Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529. ### POC #### Reference - http://securityreason.com/securityalert/3182 - http://www.securityfocus.com/archive/1/480830/100/0/threaded - http://www.waraxe.us/advisory-57.html - https://www.exploit-db.com/exploits/5618 - https://www.exploit-db.com/exploits/5688 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5157 (2007/CVE-2007-5157.md) ### [CVE-2007-5157](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5157) ### Description PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFidoNode allows remote attackers to execute arbitrary PHP code via a URL in the SRC_PATH parameter to phfito-post. ### POC #### Reference - https://www.exploit-db.com/exploits/4464 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5161 (2007/CVE-2007-5161.md) ### [CVE-2007-5161](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5161) ### Description Cross-zone scripting vulnerability in the internal browser in i-Systems Feedreader 3.10 allows remote attackers to inject arbitrary web script or HTML via an item in a feed, as demonstrated by a WordPress blog update. NOTE: this was originally reported as XSS. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119115897930583&w=2 - http://securityreason.com/securityalert/3183 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5162 (2007/CVE-2007-5162.md) ### [CVE-2007-5162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5162) ### Description The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site. ### POC #### Reference - http://securityreason.com/securityalert/3180 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5169 (2007/CVE-2007-5169.md) ### [CVE-2007-5169](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5169) ### Description Stack-based buffer overflow in MAIPM6.dll in Adobe PageMaker 7.0.1 and 7.0.2 on Windows allows user-assisted remote attackers to execute arbitrary code via a long font name in a .PMD file. ### POC #### Reference - http://vuln.sg/pagemaker701-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5173 (2007/CVE-2007-5173.md) ### [CVE-2007-5173](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5173) ### Description PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4471 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5174 (2007/CVE-2007-5174.md) ### [CVE-2007-5174](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5174) ### Description Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the do parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4472 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5175 (2007/CVE-2007-5175.md) ### [CVE-2007-5175](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5175) ### Description PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the BaseCfg[BaseDir] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4473 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5177 (2007/CVE-2007-5177.md) ### [CVE-2007-5177](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5177) ### Description SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4469 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5178 (2007/CVE-2007-5178.md) ### [CVE-2007-5178](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5178) ### Description contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter, which allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via a URL in the mx_root_path parameter. NOTE: some sources incorrectly state that phpbb_root_path is the affected parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4470 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5180 (2007/CVE-2007-5180.md) ### [CVE-2007-5180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5180) ### Description Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp. ### POC #### Reference - http://packetstormsecurity.org/0709-exploits/ohesa-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5181 (2007/CVE-2007-5181.md) ### [CVE-2007-5181](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5181) ### Description SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL commands via the ilan_id parameter. ### POC #### Reference - http://packetstormsecurity.org/0709-exploits/netkamp-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5182 (2007/CVE-2007-5182.md) ### [CVE-2007-5182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5182) ### Description Cross-site scripting (XSS) vulnerability in mail.asp in Netkamp Emlak Scripti allows remote attackers to inject arbitrary web script or HTML via the (1) Email parameter, and possibly the (2) Ad, (3) Soyad, (4) Konu, and (5) Mesaj parameters to iletisim.asp. ### POC #### Reference - http://packetstormsecurity.org/0709-exploits/netkamp-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5183 (2007/CVE-2007-5183.md) ### [CVE-2007-5183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5183) ### Description Cross-site scripting (XSS) vulnerability in Mailbox.mws in OdysseySuite, possibly 4.0.729, allows remote attackers to inject arbitrary web script or HTML via the idkey parameter. ### POC #### Reference - http://pridels-team.blogspot.com/2007/10/odysseysuite-internet-banking-vuln.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5184 (2007/CVE-2007-5184.md) ### [CVE-2007-5184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5184) ### Description Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name. ### POC #### Reference - https://www.exploit-db.com/exploits/4478 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5185 (2007/CVE-2007-5185.md) ### [CVE-2007-5185](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5185) ### Description Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/. ### POC #### Reference - https://www.exploit-db.com/exploits/4477 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5186 (2007/CVE-2007-5186.md) ### [CVE-2007-5186](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5186) ### Description PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter, a different vector than CVE-2006-5497. NOTE: this issue was disputed, but the dispute was retracted after additional analysis. ### POC #### Reference - https://www.exploit-db.com/exploits/4476 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5187 (2007/CVE-2007-5187.md) ### [CVE-2007-5187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5187) ### Description SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4475 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5189 (2007/CVE-2007-5189.md) ### [CVE-2007-5189](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5189) ### Description Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters. ### POC #### Reference - http://securityreason.com/securityalert/3186 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5191 (2007/CVE-2007-5191.md) ### [CVE-2007-5191](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5191) ### Description mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Shubhamthakur1997/CICD-Demo - https://github.com/dcambronero/CloudGuard-ShiftLeft-CICD-AWS - https://github.com/jaydenaung/CloudGuard-ShiftLeft-CICD-AWS --- ### 2007/CVE 2007 5195 (2007/CVE-2007-5195.md) ### [CVE-2007-5195](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5195) ### Description Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5196. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_20_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5196 (2007/CVE-2007-5196.md) ### [CVE-2007-5196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5196) ### Description Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_20_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5200 (2007/CVE-2007-5200.md) ### [CVE-2007-5200](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5200) ### Description hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file. ### POC #### Reference - http://www.novell.com/linux/security/advisories/2007_20_sr.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5212 (2007/CVE-2007-5212.md) ### [CVE-2007-5212](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5212) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings. ### POC #### Reference - http://securityreason.com/securityalert/3188 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5213 (2007/CVE-2007-5213.md) ### [CVE-2007-5213](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5213) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page. ### POC #### Reference - http://securityreason.com/securityalert/3188 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5214 (2007/CVE-2007-5214.md) ### [CVE-2007-5214](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5214) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to the default URI associated with a directory, as demonstrated by (a) the root directory and (b) the view/ directory; (2) parameters associated with saved settings, as demonstrated by (c) the conf_Network_HostName parameter on the Network page and (d) the conf_Layout_OwnTitle parameter to ServerManager.srv; and (3) the query string to ServerManager.srv, which is displayed on the logs page. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings. ### POC #### Reference - http://securityreason.com/securityalert/3188 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5218 (2007/CVE-2007-5218.md) ### [CVE-2007-5218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5218) ### Description Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web script or HTML via the action parameter. ### POC #### Reference - http://securityreason.com/securityalert/3190 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5219 (2007/CVE-2007-5219.md) ### [CVE-2007-5219](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5219) ### Description Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method. ### POC #### Reference - https://www.exploit-db.com/exploits/4479 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5220 (2007/CVE-2007-5220.md) ### [CVE-2007-5220](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5220) ### Description SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters. ### POC #### Reference - http://securityreason.com/securityalert/3189 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5221 (2007/CVE-2007-5221.md) ### [CVE-2007-5221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5221) ### Description PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the form parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4481 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5222 (2007/CVE-2007-5222.md) ### [CVE-2007-5222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5222) ### Description SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/4467 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5223 (2007/CVE-2007-5223.md) ### [CVE-2007-5223](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5223) ### Description Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified impact, related to incorrect input validation or other defects involving (1) admin/backupstart.php, (2) a .sql filename under admin/admin/dump/, (3) a .sql filename in the fl parameter to admin/downloadbackup.php, and (4) a .. (dot dot) in the fl parameter to admin/downloadbackup.php. ### POC #### Reference - http://securityreason.com/securityalert/3191 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5224 (2007/CVE-2007-5224.md) ### [CVE-2007-5224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5224) ### Description inc/exif.inc.php in Original Photo Gallery 0.11.2 and earlier allows remote attackers to execute arbitrary programs via the exif_prog parameter, which is specified in an exec function call. ### POC #### Reference - http://securityreason.com/securityalert/3187 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5225 (2007/CVE-2007-5225.md) ### [CVE-2007-5225](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5225) ### Description Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl. ### POC #### Reference - https://www.exploit-db.com/exploits/4516 - https://www.exploit-db.com/exploits/5227 #### Github - https://github.com/0xdea/exploits --- ### 2007/CVE 2007 5229 (2007/CVE-2007-5229.md) ### [CVE-2007-5229](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5229) ### Description Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url and (2) feedburner_comments_url parameters. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119145344606493&w=2 - https://www.exploit-db.com/exploits/30637/ #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 5230 (2007/CVE-2007-5230.md) ### [CVE-2007-5230](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5230) ### Description admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231. ### POC #### Reference - https://www.exploit-db.com/exploits/4466 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5231 (2007/CVE-2007-5231.md) ### [CVE-2007-5231](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5231) ### Description Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230. ### POC #### Reference - https://www.exploit-db.com/exploits/4466 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5232 (2007/CVE-2007-5232.md) ### [CVE-2007-5232](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5232) ### Description Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0963.html - http://www.redhat.com/support/errata/RHSA-2008-0100.html - http://www.redhat.com/support/errata/RHSA-2008-0156.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9331 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5233 (2007/CVE-2007-5233.md) ### [CVE-2007-5233](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5233) ### Description SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action. ### POC #### Reference - https://www.exploit-db.com/exploits/4482 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5234 (2007/CVE-2007-5234.md) ### [CVE-2007-5234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5234) ### Description PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers to execute arbitrary PHP code via a URL in the level parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4483 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5238 (2007/CVE-2007-5238.md) ### [CVE-2007-5238](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5238) ### Description Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities." ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0963.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5239 (2007/CVE-2007-5239.md) ### [CVE-2007-5239](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5239) ### Description Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0963.html - http://www.redhat.com/support/errata/RHSA-2008-0100.html - http://www.redhat.com/support/errata/RHSA-2008-0156.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5240 (2007/CVE-2007-5240.md) ### [CVE-2007-5240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5240) ### Description Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2007-0963.html - http://www.redhat.com/support/errata/RHSA-2008-0100.html - http://www.redhat.com/support/errata/RHSA-2008-0156.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5243 (2007/CVE-2007-5243.md) ### [CVE-2007-5243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5243) ### Description Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/rcvalle/vulnerabilities - https://github.com/risesecurity/vulnerabilities - https://github.com/swarna1010/Vulnerabilities --- ### 2007/CVE 2007 5244 (2007/CVE-2007-5244.md) ### [CVE-2007-5244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5244) ### Description Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the open_marker_file function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/rcvalle/vulnerabilities - https://github.com/risesecurity/vulnerabilities - https://github.com/swarna1010/Vulnerabilities --- ### 2007/CVE 2007 5245 (2007/CVE-2007-5245.md) ### [CVE-2007-5245](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5245) ### Description Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the SVC_attach function or (2) unspecified vectors involving the INET_connect function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/rcvalle/vulnerabilities - https://github.com/risesecurity/vulnerabilities - https://github.com/swarna1010/Vulnerabilities --- ### 2007/CVE 2007 5246 (2007/CVE-2007-5246.md) ### [CVE-2007-5246](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5246) ### Description Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitrary code via (1) a long attach request on TCP port 3050 to the isc_attach_database function or (2) a long create request on TCP port 3050 to the isc_create_database function. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/rcvalle/vulnerabilities - https://github.com/risesecurity/vulnerabilities - https://github.com/swarna1010/Vulnerabilities --- ### 2007/CVE 2007 5247 (2007/CVE-2007-5247.md) ### [CVE-2007-5247](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5247) ### Description Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server on UDP port 27888 or (2) a PB_U packet to UCON on UDP port 27888, different vectors than CVE-2004-1500. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain. ### POC #### Reference - http://aluigi.altervista.org/adv/fearfspb-adv.txt - http://aluigi.org/poc/fearfspb.zip - http://securityreason.com/securityalert/3197 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5248 (2007/CVE-2007-5248.md) ### [CVE-2007-5248](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5248) ### Description Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain. ### POC #### Reference - http://aluigi.altervista.org/adv/d3engfspb-adv.txt - http://aluigi.org/poc/d3engfspb.zip - http://securityreason.com/securityalert/3196 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5249 (2007/CVE-2007-5249.md) ### [CVE-2007-5249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5249) ### Description Multiple buffer overflows in the logging function in the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to cause a denial of service (daemon crash) via a long (1) PB_Y packet to the YPG server on UDP port 1716 or (2) PB_U packet to UCON on UDP port 1716, different vectors than CVE-2007-4442. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain. ### POC #### Reference - http://aluigi.altervista.org/adv/aaboompb-adv.txt - http://aluigi.org/poc/aaboompb.zip - http://securityreason.com/securityalert/3193 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5250 (2007/CVE-2007-5250.md) ### [CVE-2007-5250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5250) ### Description The Windows dedicated server for the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allows remote attackers to cause a denial of service (server hang) via packets containing 0x07 characters or other unspecified invalid characters. NOTE: this issue may overlap CVE-2007-4443. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain. ### POC #### Reference - http://aluigi.altervista.org/adv/aaboompb-adv.txt - http://aluigi.org/poc/aaboompb.zip - http://securityreason.com/securityalert/3193 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5252 (2007/CVE-2007-5252.md) ### [CVE-2007-5252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5252) ### Description Buffer overflow in NetSupport Manager (NSM) Client 10.00 and 10.20, and NetSupport School Student (NSS) 9.00, allows remote NSM servers to cause a denial of service or possibly execute arbitrary code via crafted data in the configuration exchange phase of an initial connection setup. NOTE: a vendor statement, which is too vague to be sure that it is for this particular issue, says that only a denial of service is possible. ### POC #### Reference - http://securityreason.com/securityalert/3198 #### Github - https://github.com/gellanyhassan1/maadi_attacks --- ### 2007/CVE 2007 5253 (2007/CVE-2007-5253.md) ### [CVE-2007-5253](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5253) ### Description c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability. ### POC #### Reference - http://securityreason.com/securityalert/3194 - https://www.exploit-db.com/exploits/30639/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5255 (2007/CVE-2007-5255.md) ### [CVE-2007-5255](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5255) ### Description Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitrary web script or HTML via the ie parameter to the /search URI. ### POC #### Reference - http://websecurity.com.ua/1368/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5256 (2007/CVE-2007-5256.md) ### [CVE-2007-5256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5256) ### Description Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary code via a long HELP command on TCP port 3010 to the sysuser::exechelp function in sysuser.cc and (2) remote authenticated users to execute arbitrary code via long commands on TCP port 6809 to the servinterface::sendmulticast function in servinterface.cc, as demonstrated by a PIcallsign command. ### POC #### Reference - http://securityreason.com/securityalert/3195 - https://www.exploit-db.com/exploits/4484 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5257 (2007/CVE-2007-5257.md) ### [CVE-2007-5257](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5257) ### Description Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169. ### POC #### Reference - https://www.exploit-db.com/exploits/4474 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5260 (2007/CVE-2007-5260.md) ### [CVE-2007-5260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5260) ### Description ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request for mdb-database/ASP-CMS_v100.mdb. ### POC #### Reference - http://securityreason.com/securityalert/3199 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5261 (2007/CVE-2007-5261.md) ### [CVE-2007-5261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5261) ### Description Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4480 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5262 (2007/CVE-2007-5262.md) ### [CVE-2007-5262](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5262) ### Description Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username, (2) password, and (3) nickname fields in a "0x01" packet. ### POC #### Reference - http://aluigi.altervista.org/adv/dropteamz-adv.txt - http://securityreason.com/securityalert/3202 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5263 (2007/CVE-2007-5263.md) ### [CVE-2007-5263](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5263) ### Description Multiple buffer overflows in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via (1) a crafted "0x5c" packet or (2) many 32-bit numbers in a "0x18" packet, or cause a denial of service (crash) via (3) a large "0x4b" packet. ### POC #### Reference - http://aluigi.altervista.org/adv/dropteamz-adv.txt - http://securityreason.com/securityalert/3202 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5264 (2007/CVE-2007-5264.md) ### [CVE-2007-5264](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5264) ### Description Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information. ### POC #### Reference - http://aluigi.altervista.org/adv/dropteamz-adv.txt - http://securityreason.com/securityalert/3202 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5266 (2007/CVE-2007-5266.md) ### [CVE-2007-5266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5266) ### Description Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name field from being NULL terminated. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=195261 - http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.com - http://www.coresecurity.com/?action=item&id=2148 - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5267 (2007/CVE-2007-5267.md) ### [CVE-2007-5267](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5267) ### Description Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image, due to an incorrect fix for CVE-2007-5266. ### POC #### Reference - http://www.coresecurity.com/?action=item&id=2148 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5268 (2007/CVE-2007-5268.md) ### [CVE-2007-5268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5268) ### Description pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=195261 - http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0709140846k24e9a040r81623783b6b1c00f%40mail.gmail.com - http://www.coresecurity.com/?action=item&id=2148 - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5269 (2007/CVE-2007-5269.md) ### [CVE-2007-5269](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5269) ### Description Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL (png_handle_sCAL), (3) tEXt (png_push_read_tEXt), (4) iTXt (png_handle_iTXt), and (5) ztXT (png_handle_ztXt) chunking in PNG images, which trigger out-of-bounds read operations. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=195261 - http://www.coresecurity.com/?action=item&id=2148 - http://www.vmware.com/security/advisories/VMSA-2008-0014.html - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5271 (2007/CVE-2007-5271.md) ### [CVE-2007-5271](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5271) ### Description Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the bField[bf_data] parameter to (1) interface/editors/-custom.php or (2) interface/editors/custom.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4485 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5272 (2007/CVE-2007-5272.md) ### [CVE-2007-5272](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5272) ### Description SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action. ### POC #### Reference - https://www.exploit-db.com/exploits/4486 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5273 (2007/CVE-2007-5273.md) ### [CVE-2007-5273](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5273) ### Description Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf - http://www.redhat.com/support/errata/RHSA-2007-0963.html - http://www.redhat.com/support/errata/RHSA-2008-0100.html - http://www.redhat.com/support/errata/RHSA-2008-0156.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5274 (2007/CVE-2007-5274.md) ### [CVE-2007-5274](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5274) ### Description Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf - http://www.redhat.com/support/errata/RHSA-2007-0963.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5275 (2007/CVE-2007-5275.md) ### [CVE-2007-5275](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5275) ### Description The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf - http://www.vupen.com/english/advisories/2008/1697 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9250 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5276 (2007/CVE-2007-5276.md) ### [CVE-2007-5276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5276) ### Description Opera 9 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5277 (2007/CVE-2007-5277.md) ### [CVE-2007-5277](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5277) ### Description Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80, a different issue than CVE-2006-4560. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5278 (2007/CVE-2007-5278.md) ### [CVE-2007-5278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5278) ### Description Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable. ### POC #### Reference - https://www.exploit-db.com/exploits/4466 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5293 (2007/CVE-2007-5293.md) ### [CVE-2007-5293](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5293) ### Description Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4495 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5294 (2007/CVE-2007-5294.md) ### [CVE-2007-5294](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5294) ### Description PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4495 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5298 (2007/CVE-2007-5298.md) ### [CVE-2007-5298](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5298) ### Description Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[document_uri] parameter to (1) _administration/securite.php and (2) _administration/gestion_configurations/save_config.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4491 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5299 (2007/CVE-2007-5299.md) ### [CVE-2007-5299](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5299) ### Description Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. (dot dot) in the view_mode parameter to (1) featured_list.php and (2) online_list.php in member/. ### POC #### Reference - https://www.exploit-db.com/exploits/4493 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5300 (2007/CVE-2007-5300.md) ### [CVE-2007-5300](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5300) ### Description Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4498 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5301 (2007/CVE-2007-5301.md) ### [CVE-2007-5301](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5301) ### Description Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments. ### POC #### Reference - https://www.exploit-db.com/exploits/5424 #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 5308 (2007/CVE-2007-5308.md) ### [CVE-2007-5308](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5308) ### Description SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. ### POC #### Reference - https://www.exploit-db.com/exploits/4501 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5309 (2007/CVE-2007-5309.md) ### [CVE-2007-5309](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5309) ### Description PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - http://www.attrition.org/pipermail/vim/2007-October/001823.html - http://www.attrition.org/pipermail/vim/2007-October/001824.html - https://www.exploit-db.com/exploits/4496 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5310 (2007/CVE-2007-5310.md) ### [CVE-2007-5310](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5310) ### Description PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4497 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5311 (2007/CVE-2007-5311.md) ### [CVE-2007-5311](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5311) ### Description Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4500 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5312 (2007/CVE-2007-5312.md) ### [CVE-2007-5312](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5312) ### Description Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat parameter to browse.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4500 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5313 (2007/CVE-2007-5313.md) ### [CVE-2007-5313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5313) ### Description PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4492 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5314 (2007/CVE-2007-5314.md) ### [CVE-2007-5314](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5314) ### Description PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4502 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5315 (2007/CVE-2007-5315.md) ### [CVE-2007-5315](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5315) ### Description PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the livealbum_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4503 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5316 (2007/CVE-2007-5316.md) ### [CVE-2007-5316](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5316) ### Description SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4504 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5320 (2007/CVE-2007-5320.md) ### [CVE-2007-5320](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5320) ### Description Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll). ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5321 (2007/CVE-2007-5321.md) ### [CVE-2007-5321](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5321) ### Description Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4494 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5322 (2007/CVE-2007-5322.md) ### [CVE-2007-5322](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5322) ### Description Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function. ### POC #### Reference - https://www.exploit-db.com/exploits/4506 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5333 (2007/CVE-2007-5333.md) ### [CVE-2007-5333](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5333) ### Description Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5334 (2007/CVE-2007-5334.md) ### [CVE-2007-5334](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5334) ### Description Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5337 (2007/CVE-2007-5337.md) ### [CVE-2007-5337](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5337) ### Description Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5338 (2007/CVE-2007-5338.md) ### [CVE-2007-5338](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5338) ### Description Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5339 (2007/CVE-2007-5339.md) ### [CVE-2007-5339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5339) ### Description Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5340 (2007/CVE-2007-5340.md) ### [CVE-2007-5340](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5340) ### Description Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3544 - http://www.vupen.com/english/advisories/2008/0083 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9622 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5342 (2007/CVE-2007-5342.md) ### [CVE-2007-5342](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5342) ### Description The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0862.html - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5344 (2007/CVE-2007-5344.md) ### [CVE-2007-5344](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5344) ### Description Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a variant of "Uninitialized Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5347 (2007/CVE-2007-5347.md) ### [CVE-2007-5347](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5347) ### Description Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5348 (2007/CVE-2007-5348.md) ### [CVE-2007-5348](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5348) ### Description Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-052 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5350 (2007/CVE-2007-5350.md) ### [CVE-2007-5350](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5350) ### Description Unspecified vulnerability in the Windows Advanced Local Procedure Call (ALPC) in the kernel in Microsoft Windows Vista allows local users to gain privileges via unspecified vectors involving "legacy reply paths." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-066 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5351 (2007/CVE-2007-5351.md) ### [CVE-2007-5351](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5351) ### Description Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-063 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5352 (2007/CVE-2007-5352.md) ### [CVE-2007-5352](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5352) ### Description Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-002 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5358 (2007/CVE-2007-5358.md) ### [CVE-2007-5358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5358) ### Description Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5361 (2007/CVE-2007-5361.md) ### [CVE-2007-5361](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5361) ### Description The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename. ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/alcatel_omnipcx_enterprise_audio_rerouting_vulnerability_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5364 (2007/CVE-2007-5364.md) ### [CVE-2007-5364](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5364) ### Description Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for payments/ideal_process.php ### POC #### Reference - http://securityreason.com/securityalert/3212 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5365 (2007/CVE-2007-5365.md) ### [CVE-2007-5365](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5365) ### Description Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU. ### POC #### Reference - http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1962 - https://www.exploit-db.com/exploits/4601 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5371 (2007/CVE-2007-5371.md) ### [CVE-2007-5371](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5371) ### Description Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter. ### POC #### Reference - http://securityreason.com/securityalert/3215 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5374 (2007/CVE-2007-5374.md) ### [CVE-2007-5374](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5374) ### Description cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account. ### POC #### Reference - https://www.exploit-db.com/exploits/4505 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5375 (2007/CVE-2007-5375.md) ### [CVE-2007-5375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5375) ### Description Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM. ### POC #### Reference - http://crypto.stanford.edu/dns/dns-rebinding.pdf #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5378 (2007/CVE-2007-5378.md) ### [CVE-2007-5378](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5378) ### Description Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2008-0009.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9480 - https://sourceforge.net/tracker/?func=detail&atid=112997&aid=1458234&group_id=12997 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5381 (2007/CVE-2007-5381.md) ### [CVE-2007-5381](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5381) ### Description Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5383 (2007/CVE-2007-5383.md) ### [CVE-2007-5383](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5383) ### Description The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues. ### POC #### Reference - http://www.theregister.co.uk/2007/10/09/bt_home_hub_vuln/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5384 (2007/CVE-2007-5384.md) ### [CVE-2007-5384](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5384) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on TCP port 51003. NOTE: an authentication bypass can be leveraged to exploit this in the absence of an existing administrative session. NOTE: SpeedTouch 780 might also be affected by some of these issues. ### POC #### Reference - http://www.theregister.co.uk/2007/10/09/bt_home_hub_vuln/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5385 (2007/CVE-2007-5385.md) ### [CVE-2007-5385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5385) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://www.theregister.co.uk/2007/10/09/bt_home_hub_vuln/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5387 (2007/CVE-2007-5387.md) ### [CVE-2007-5387](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5387) ### Description PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4519 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5388 (2007/CVE-2007-5388.md) ### [CVE-2007-5388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5388) ### Description Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4518 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5390 (2007/CVE-2007-5390.md) ### [CVE-2007-5390](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5390) ### Description PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4520 #### Github - https://github.com/rnbochsr/yr_of_the_jellyfish --- ### 2007/CVE 2007 5392 (2007/CVE-2007-5392.md) ### [CVE-2007-5392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5392) ### Description Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 5393 (2007/CVE-2007-5393.md) ### [CVE-2007-5393](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393) ### Description Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9839 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 5395 (2007/CVE-2007-5395.md) ### [CVE-2007-5395](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5395) ### Description Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows remote attackers to execute arbitrary code via a long word, as reachable through the separate_sentence function. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=196803 - https://bugzilla.redhat.com/show_bug.cgi?id=371221 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5398 (2007/CVE-2007-5398.md) ### [CVE-2007-5398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398) ### Description Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request. ### POC #### Reference - http://securityreason.com/securityalert/3372 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5399 (2007/CVE-2007-5399.md) ### [CVE-2007-5399](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5399) ### Description Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority header; (10) a long string at the beginning of an RFC2047 encoded-word in a header; (11) a long text string in an RFC2047 encoded-word in a header; or (12) a long Subject header, related to creation of an associated filename. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5400 (2007/CVE-2007-5400.md) ### [CVE-2007-5400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5400) ### Description Heap-based buffer overflow in the Shockwave Flash (SWF) frame handling in RealNetworks RealPlayer 10.5 Build 6.0.12.1483 might allow remote attackers to execute arbitrary code via a crafted SWF file. ### POC #### Reference - http://securityreason.com/securityalert/4048 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5405 (2007/CVE-2007-5405.md) ### [CVE-2007-5405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5405) ### Description Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5407 (2007/CVE-2007-5407.md) ### [CVE-2007-5407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5407) ### Description Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and (4) register.php, in view/; and (5) list.sub.html.php, (6) list.user.sub.html.php, and (7) reports.html.php in views/. ### POC #### Reference - https://www.exploit-db.com/exploits/4508 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5408 (2007/CVE-2007-5408.md) ### [CVE-2007-5408](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5408) ### Description SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4511 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5409 (2007/CVE-2007-5409.md) ### [CVE-2007-5409](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5409) ### Description PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the nuseo_dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4512 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5412 (2007/CVE-2007-5412.md) ### [CVE-2007-5412](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5412) ### Description Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5416 (2007/CVE-2007-5416.md) ### [CVE-2007-5416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5416) ### Description Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal. ### POC #### Reference - http://securityvulns.ru/Sdocument137.html - https://www.exploit-db.com/exploits/4510 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5417 (2007/CVE-2007-5417.md) ### [CVE-2007-5417](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5417) ### Description Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. ### POC #### Reference - http://securityvulns.com/Sdocument42.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5418 (2007/CVE-2007-5418.md) ### [CVE-2007-5418](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5418) ### Description Multiple PHP remote file inclusion vulnerabilities in CARE2X 2G 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) en_copyrite.php, (2) vi_copyrite.php, and (3) ar_copyrite.php in language/ directories; (4) class_access.php, (5) class_department.php, (6) class_config.php, (7) class_image.php, (8) class_ward.php, and (9) class_product.php in include/care_api_classes/; (10) gui/smarty_template/smarty_care.class.php; and possibly other components, different vectors than CVE-2007-1458. ### POC #### Reference - http://securityvulns.com/Rdocument960.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5423 (2007/CVE-2007-5423.md) ### [CVE-2007-5423](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5423) ### Description tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. ### POC #### Reference - http://securityvulns.ru/Sdocument162.html - https://www.exploit-db.com/exploits/4509 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5438 (2007/CVE-2007-5438.md) ### [CVE-2007-5438](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5438) ### Description Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 might allow local users to cause a denial of service to the Virtual Disk Mount Service (vmount2.exe), related to the ConnectPopulatedDiskEx function. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2008-0014.html - http://www.vmware.com/support/ace/doc/releasenotes_ace.html - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5440 (2007/CVE-2007-5440.md) ### [CVE-2007-5440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5440) ### Description Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) index.php or (2) login.php. NOTE: this issue is disputed by CVE, since DOCUMENT_ROOT cannot be modified by an attacker ### POC #### Reference - http://securityvulns.com/Rdocument959.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5446 (2007/CVE-2007-5446.md) ### [CVE-2007-5446](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5446) ### Description Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method. ### POC #### Reference - https://www.exploit-db.com/exploits/4526 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5447 (2007/CVE-2007-5447.md) ### [CVE-2007-5447](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5447) ### Description ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function. ### POC #### Reference - https://www.exploit-db.com/exploits/4517 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5449 (2007/CVE-2007-5449.md) ### [CVE-2007-5449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5449) ### Description SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4527 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5450 (2007/CVE-2007-5450.md) ### [CVE-2007-5450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5450) ### Description Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of service (application crash), and enable filesystem browsing by the local user, via a certain TIFF file. ### POC #### Reference - https://www.exploit-db.com/exploits/4522 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5451 (2007/CVE-2007-5451.md) ### [CVE-2007-5451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5451) ### Description PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5452 (2007/CVE-2007-5452.md) ### [CVE-2007-5452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5452) ### Description Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4513 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5453 (2007/CVE-2007-5453.md) ### [CVE-2007-5453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5453) ### Description Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php, (3) download.php, and unspecified other files, as demonstrated by modifying _options through a backup restore action in admin.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4513 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5455 (2007/CVE-2007-5455.md) ### [CVE-2007-5455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5455) ### Description Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4529 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5456 (2007/CVE-2007-5456.md) ### [CVE-2007-5456](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5456) ### Description Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, as demonstrated by (1) .txt, (2) .cda, (3) .log, (4) .dif, (5) .sol, (6) .htt, (7) .itpc, (8) .itms, (9) .dvr-ms, (10) .dib, (11) .asf, (12) .tif, and unspecified other extensions, a different issue than CVE-2004-1331. NOTE: this issue might not cross privilege boundaries, although it does bypass an intended protection mechanism. ### POC #### Reference - http://securityreason.com/securityalert/3222 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5457 (2007/CVE-2007-5457.md) ### [CVE-2007-5457](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5457) ### Description Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) install.joomla_flash_uploader.php and (2) uninstall.joomla_flash_uploader.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4521 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5458 (2007/CVE-2007-5458.md) ### [CVE-2007-5458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5458) ### Description SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4523 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5461 (2007/CVE-2007-5461.md) ### [CVE-2007-5461](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5461) ### Description Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0862.html - http://www.vmware.com/security/advisories/VMSA-2009-0016.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202 - https://www.exploit-db.com/exploits/4530 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5464 (2007/CVE-2007-5464.md) ### [CVE-2007-5464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5464) ### Description Stack-based buffer overflow in Live for Speed 0.5X10 and earlier allows remote authenticated users to cause a denial of service (client crash) and possibly execute arbitrary code via a long skin name. ### POC #### Reference - http://aluigi.altervista.org/adv/lfscbof-adv.txt - http://securityreason.com/securityalert/3234 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5465 (2007/CVE-2007-5465.md) ### [CVE-2007-5465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5465) ### Description Directory traversal vulnerability in doop CMS 1.3.7 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter to an unspecified component. ### POC #### Reference - https://www.exploit-db.com/exploits/4536 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5466 (2007/CVE-2007-5466.md) ### [CVE-2007-5466](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5466) ### Description Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function. ### POC #### Reference - http://www.digit-labs.org/files/exploits/extremail-v8.pl - https://www.exploit-db.com/exploits/4533 - https://www.exploit-db.com/exploits/4534 - https://www.exploit-db.com/exploits/4535 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5467 (2007/CVE-2007-5467.md) ### [CVE-2007-5467](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5467) ### Description Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078. ### POC #### Reference - http://www.digit-labs.org/files/exploits/extremail-v3.pl - https://www.exploit-db.com/exploits/4532 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5474 (2007/CVE-2007-5474.md) ### [CVE-2007-5474](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5474) ### Description The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via an Atheros information element with an invalid length, as demonstrated by an element that is too long. ### POC #### Reference - http://securityreason.com/securityalert/4226 #### Github - https://github.com/0xd012/wifuzzit - https://github.com/84KaliPleXon3/wifuzzit - https://github.com/HectorTa1989/802.11-Wireless-Fuzzer - https://github.com/PleXone2019/wifuzzit - https://github.com/flowerhack/wifuzzit - https://github.com/sececter/wifuzzit --- ### 2007/CVE 2007 5475 (2007/CVE-2007-5475.md) ### [CVE-2007-5475](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5475) ### Description Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code via an association request with long (1) rates, (2) extended rates, and unspecified other information elements. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xd012/wifuzzit - https://github.com/84KaliPleXon3/wifuzzit - https://github.com/HectorTa1989/802.11-Wireless-Fuzzer - https://github.com/PleXone2019/wifuzzit - https://github.com/flowerhack/wifuzzit - https://github.com/sececter/wifuzzit --- ### 2007/CVE 2007 5481 (2007/CVE-2007-5481.md) ### [CVE-2007-5481](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5481) ### Description Distributed Checksum Clearinghouse (DCC) 1.3.65 allows remote attackers to cause a denial of service (crash) via a "SOCKS flood." ### POC #### Reference - http://www.rhyolite.com/anti-spam/dcc/CHANGES #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5484 (2007/CVE-2007-5484.md) ### [CVE-2007-5484](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5484) ### Description Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah. ### POC #### Reference - https://www.exploit-db.com/exploits/4529 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5485 (2007/CVE-2007-5485.md) ### [CVE-2007-5485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5485) ### Description SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the album parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4528 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5486 (2007/CVE-2007-5486.md) ### [CVE-2007-5486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5486) ### Description dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://docs.dotproject.net/index.php/Closed_Issues_/_Feature_Requests_-_2.1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5487 (2007/CVE-2007-5487.md) ### [CVE-2007-5487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5487) ### Description Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an EXTM3U section of a .m3u file. ### POC #### Reference - https://www.exploit-db.com/exploits/4531 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5489 (2007/CVE-2007-5489.md) ### [CVE-2007-5489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5489) ### Description Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4538 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5490 (2007/CVE-2007-5490.md) ### [CVE-2007-5490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5490) ### Description SQL injection vulnerability in default.asp in Okul Otomasyon Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4539 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5495 (2007/CVE-2007-5495.md) ### [CVE-2007-5495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5495) ### Description sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5498 (2007/CVE-2007-5498.md) ### [CVE-2007-5498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5498) ### Description The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifies a large number of blocks. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9452 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5500 (2007/CVE-2007-5500.md) ### [CVE-2007-5500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5500) ### Description The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9868 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5502 (2007/CVE-2007-5502.md) ### [CVE-2007-5502](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5502) ### Description The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 5503 (2007/CVE-2007-5503.md) ### [CVE-2007-5503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5503) ### Description Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image with large width and height values, which is not properly handled by the read_png function. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=201860 - http://www.vmware.com/security/advisories/VMSA-2008-0014.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5504 (2007/CVE-2007-5504.md) ### [CVE-2007-5504](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5504) ### Description Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+ and 10.1.0.5 unknown impact and remote attack vectors, related to (1) Import (DB01) and (2) Advanced Queuing (DB25). NOTE: as of 20071108, Oracle has not disputed reliable researcher claims that DB25 is for a buffer overflow in the DBLINK_INFO procedure in the DBMS_AQADM_SYS package. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5505 (2007/CVE-2007-5505.md) ### [CVE-2007-5505](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5505) ### Description Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to (1) the Export component (DB02), (2) Oracle Text (DB04), (3) Oracle Text (DB05), (4) Spatial component (DB07), and (5) Advanced Security Option (DB19). ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5506 (2007/CVE-2007-5506.md) ### [CVE-2007-5506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5506) ### Description The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (CPU consumption) via a crafted type 6 Data packet, aka DB20. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5507 (2007/CVE-2007-5507.md) ### [CVE-2007-5507](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5507) ### Description The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a connect GIOP packet with an invalid data size, which triggers a buffer over-read, aka DB22. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5508 (2007/CVE-2007-5508.md) ### [CVE-2007-5508](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5508) ### Description Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5509 (2007/CVE-2007-5509.md) ### [CVE-2007-5509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5509) ### Description Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5510 (2007/CVE-2007-5510.md) ### [CVE-2007-5510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5510) ### Description Multiple unspecified vulnerabilities in the Workspace Manager component in Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 have unknown impact and remote attack vectors, aka (1) DB08, (2) DB09, (3) DB10, (4) DB11, (5) DB12, (6) DB13, (7) DB14, (8) DB15, (9) DB16, (10) DB17, and (11) DB18. NOTE: one of these issues is probably CVE-2007-5511, but there are insufficient details to be certain. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5511 (2007/CVE-2007-5511.md) ### [CVE-2007-5511](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5511) ### Description SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 - https://www.exploit-db.com/exploits/4570 - https://www.exploit-db.com/exploits/4571 - https://www.exploit-db.com/exploits/4572 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5512 (2007/CVE-2007-5512.md) ### [CVE-2007-5512](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5512) ### Description Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10.2.0.3 has unknown impact and remote attack vectors, aka DB21. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5513 (2007/CVE-2007-5513.md) ### [CVE-2007-5513](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5513) ### Description The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in the USERID column in which (1) long usernames are trimmed to 5 characters, or (2) short entries contain any extra characters from usernames in previous entries, aka DB23. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5514 (2007/CVE-2007-5514.md) ### [CVE-2007-5514](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5514) ### Description Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and attack vectors related to (1) Database Vault component (DB24) and (2) SQL Execution component (DB26). ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5515 (2007/CVE-2007-5515.md) ### [CVE-2007-5515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5515) ### Description Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB27. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5516 (2007/CVE-2007-5516.md) ### [CVE-2007-5516](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5516) ### Description Unspecified vulnerability in the Oracle Process Mgmt & Notification component in Oracle Application Server 10.1.3.3 has unknown impact and remote attack vectors, aka AS01. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5517 (2007/CVE-2007-5517.md) ### [CVE-2007-5517](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5517) ### Description Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2 and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS02. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5518 (2007/CVE-2007-5518.md) ### [CVE-2007-5518](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5518) ### Description Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 10.1.3.2 has unknown impact and remote attack vectors, aka AS03. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5519 (2007/CVE-2007-5519.md) ### [CVE-2007-5519](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5519) ### Description Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS04. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5520 (2007/CVE-2007-5520.md) ### [CVE-2007-5520](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5520) ### Description Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8 and 9.2.0.8DV, and Oracle Application Server 9.0.4.3, 10.1.3.0.0 up to 10.1.3.3.0, and 10.1.2.0.1 up to 10.1.2.2.0, has unknown impact and remote attack vectors, aka AS05. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5521 (2007/CVE-2007-5521.md) ### [CVE-2007-5521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5521) ### Description Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5522 (2007/CVE-2007-5522.md) ### [CVE-2007-5522](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5522) ### Description Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.4.1 has unknown impact and remote attack vectors, aka AS07. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5523 (2007/CVE-2007-5523.md) ### [CVE-2007-5523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5523) ### Description Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS08. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5524 (2007/CVE-2007-5524.md) ### [CVE-2007-5524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5524) ### Description Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS09 or AS9. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5525 (2007/CVE-2007-5525.md) ### [CVE-2007-5525](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5525) ### Description Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0.1; Collaboration Suite 10.1.2; and Enterprise Manager 10.1.2 has unknown impact and remote attack vectors, aka AS10. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5526 (2007/CVE-2007-5526.md) ### [CVE-2007-5526](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5526) ### Description Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2, 10.1.2.2, and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS11. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5527 (2007/CVE-2007-5527.md) ### [CVE-2007-5527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5527) ### Description Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and remote attack vectors, related to (1) Application Object Library component (APP01), (2) Contracts Integration (APP02), (3) Applications Manager (APP04), (4) Marketing component (APP05), and (5) Exchange component (APP07). ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5528 (2007/CVE-2007-5528.md) ### [CVE-2007-5528](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5528) ### Description Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.2 have unknown impact and attack vectors related to (1) Public Sector Human Resources (APP03) and (2) Quoting component (APP06). ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5529 (2007/CVE-2007-5529.md) ### [CVE-2007-5529](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5529) ### Description Unspecified vulnerability in the Oracle Self-Service Web Applications component in client-only installations of Oracle E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka APP08. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5530 (2007/CVE-2007-5530.md) ### [CVE-2007-5530](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5530) ### Description Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3, and Enterprise Manager, has unknown impact and remote attack vectors, aka EM01. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5531 (2007/CVE-2007-5531.md) ### [CVE-2007-5531](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5531) ### Description Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5532 (2007/CVE-2007-5532.md) ### [CVE-2007-5532](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5532) ### Description Unspecified vulnerability in the People Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.17, 8.47.14, 8.48.13, 8.49.05 has unknown impact and remote attack vectors, aka PSE01. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5533 (2007/CVE-2007-5533.md) ### [CVE-2007-5533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5533) ### Description Unspecified vulnerability in the People Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.14, 8.48.13, 8.49.05 has unknown impact and remote attack vectors, aka PSE02. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5534 (2007/CVE-2007-5534.md) ### [CVE-2007-5534](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5534) ### Description Unspecified vulnerability in the HCM component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 Bundle 13 9.0 Bundle 3 has unknown impact and remote attack vectors, aka PSE_HCM01. ### POC #### Reference - http://www.vupen.com/english/advisories/2007/3524 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5536 (2007/CVE-2007-5536.md) ### [CVE-2007-5536](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5536) ### Description Unspecified vulnerability in OpenSSL before A.00.09.07l on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to cause a denial of service via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Live-Hack-CVE/CVE-2007-5536 - https://github.com/chnzzh/OpenSSL-CVE-lib --- ### 2007/CVE 2007 5542 (2007/CVE-2007-5542.md) ### [CVE-2007-5542](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5542) ### Description Stack-based buffer overflow in Miranda IM 0.6.8 allows remote attackers to execute arbitrary code via a crafted Yahoo! Messenger packet. NOTE: this might overlap CVE-2007-5590. ### POC #### Reference - http://packetstormsecurity.org/0710-advisories/mirandaim-overflows.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5543 (2007/CVE-2007-5543.md) ### [CVE-2007-5543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5543) ### Description Stack-based buffer overflow in Miranda IM 0.6.8 and 0.7.0 allows remote attackers to execute arbitrary code via a crafted Yahoo! Messenger packet. NOTE: this might overlap CVE-2007-5590. ### POC #### Reference - http://packetstormsecurity.org/0710-advisories/mirandaim-overflows.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5568 (2007/CVE-2007-5568.md) ### [CVE-2007-5568](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5568) ### Description Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM). ### POC #### Reference - https://exchange.xforce.ibmcloud.com/vulnerabilities/37259 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5573 (2007/CVE-2007-5573.md) ### [CVE-2007-5573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5573) ### Description PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4544 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5574 (2007/CVE-2007-5574.md) ### [CVE-2007-5574](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5574) ### Description PHP remote file inclusion vulnerability in djpage.php in PHPDJ 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4543 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5576 (2007/CVE-2007-5576.md) ### [CVE-2007-5576](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5576) ### Description BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands. ### POC #### Reference - http://dev2dev.bea.com/pub/advisory/226 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5577 (2007/CVE-2007-5577.md) ### [CVE-2007-5577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5577) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item. ### POC #### Reference No PoCs from references. #### Github - https://github.com/p1ay8y3ar/cve_monitor --- ### 2007/CVE 2007 5580 (2007/CVE-2007-5580.md) ### [CVE-2007-5580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5580) ### Description Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5581 (2007/CVE-2007-5581.md) ### [CVE-2007-5581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5581) ### Description Multiple cross-site scripting (XSS) vulnerabilities in mpweb/scripts/mpx.dll in Cisco Unified MeetingPlace 5.4 and earlier and 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) FirstName and (2) LastName parameters. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sr-20071107-mp.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5582 (2007/CVE-2007-5582.md) ### [CVE-2007-5582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5582) ### Description Cross-site scripting (XSS) vulnerability in the login page in Cisco CiscoWorks Server (CS), possibly 2.6 and earlier, when using CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sr-20071205-cw.shtml #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5583 (2007/CVE-2007-5583.md) ### [CVE-2007-5583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5583) ### Description Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability than CVE-2007-4459. ### POC #### Reference - https://www.exploit-db.com/exploits/4692 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5591 (2007/CVE-2007-5591.md) ### [CVE-2007-5591](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5591) ### Description The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11C Chassis and Cabinet, and Meridian-Core-Option 51C, 61C, and 81C allows remote attackers to cause a denial of service (telephony application outage) via a flood of packets to Embedded LAN (ELAN) ports. ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/nortel_telephony_server_denial_of_service_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5592 (2007/CVE-2007-5592.md) ### [CVE-2007-5592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5592) ### Description Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Setting[OPT_includepath] parameter to (1) adminhelp.php; and (2) admin.incl.php, (3) reg.incl.php, (4) help.incl.php, (5) gbook.incl.php, and (6) core/core.incl.php in modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/4545 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5593 (2007/CVE-2007-5593.md) ### [CVE-2007-5593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5593) ### Description install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified. ### POC #### Reference - http://www.securityfocus.com/bid/26119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5594 (2007/CVE-2007-5594.md) ### [CVE-2007-5594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5594) ### Description Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. ### POC #### Reference - http://www.securityfocus.com/bid/26119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5595 (2007/CVE-2007-5595.md) ### [CVE-2007-5595](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5595) ### Description CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. ### POC #### Reference - http://www.securityfocus.com/bid/26119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5596 (2007/CVE-2007-5596.md) ### [CVE-2007-5596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5596) ### Description The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files. ### POC #### Reference - http://www.securityfocus.com/bid/26119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5597 (2007/CVE-2007-5597.md) ### [CVE-2007-5597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5597) ### Description The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions. ### POC #### Reference - http://www.securityfocus.com/bid/26119 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5600 (2007/CVE-2007-5600.md) ### [CVE-2007-5600](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5600) ### Description Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftps, (3) ssh2.sftp, or (4) ssh2.scp URL, in the page parameter, for which PHP remote file inclusion is blocked only for http, https, and ftp URLs. ### POC #### Reference - https://www.exploit-db.com/exploits/4538 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5603 (2007/CVE-2007-5603.md) ### [CVE-2007-5603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5603) ### Description Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method. ### POC #### Reference - http://securityreason.com/securityalert/3342 - https://www.exploit-db.com/exploits/4594 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5604 (2007/CVE-2007-5604.md) ### [CVE-2007-5604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5604) ### Description Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5605 (2007/CVE-2007-5605.md) ### [CVE-2007-5605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5605) ### Description Buffer overflow in the GetFileTime function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5606, and CVE-2007-5607. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5606 (2007/CVE-2007-5606.md) ### [CVE-2007-5606](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5606) ### Description Buffer overflow in the MoveFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5607. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5607 (2007/CVE-2007-5607.md) ### [CVE-2007-5607](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5607) ### Description Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5608 (2007/CVE-2007-5608.md) ### [CVE-2007-5608](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5608) ### Description The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to force a download of an arbitrary file onto a client machine via a URL in the first argument and a destination filename in the second argument, a different vulnerability than CVE-2008-0952 and CVE-2008-0953. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5610 (2007/CVE-2007-5610.md) ### [CVE-2007-5610](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5610) ### Description The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1740/references #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5617 (2007/CVE-2007-5617.md) ### [CVE-2007-5617](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5617) ### Description Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images. ### POC #### Reference - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5618 (2007/CVE-2007-5618.md) ### [CVE-2007-5618](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5618) ### Description Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs. ### POC #### Reference - http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html - http://www.vmware.com/support/player/doc/releasenotes_player.html - http://www.vmware.com/support/player2/doc/releasenotes_player2.html - http://www.vmware.com/support/server/doc/releasenotes_server.html - http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html - http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5619 (2007/CVE-2007-5619.md) ### [CVE-2007-5619](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5619) ### Description Unspecified vulnerability in VMware Server before 1.0.4 causes user passwords to be recorded in cleartext in server logs, which might allow local users to gain privileges. ### POC #### Reference - http://www.vmware.com/support/server/doc/releasenotes_server.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5620 (2007/CVE-2007-5620.md) ### [CVE-2007-5620](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5620) ### Description Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4546 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5625 (2007/CVE-2007-5625.md) ### [CVE-2007-5625](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5625) ### Description Cross-site scripting (XSS) vulnerability in filename.asp in ASP Site Search SearchSimon Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter. ### POC #### Reference - http://securityreason.com/securityalert/3275 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5627 (2007/CVE-2007-5627.md) ### [CVE-2007-5627](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5627) ### Description PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to execute arbitrary PHP code via a URL in the __SOCKETMAIL_ROOT parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4554 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5628 (2007/CVE-2007-5628.md) ### [CVE-2007-5628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5628) ### Description PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the pageHeaderFile parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4555 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5630 (2007/CVE-2007-5630.md) ### [CVE-2007-5630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5630) ### Description SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action. ### POC #### Reference - https://www.exploit-db.com/exploits/4550 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5631 (2007/CVE-2007-5631.md) ### [CVE-2007-5631](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5631) ### Description Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the current_blockmodule_path parameter to (1) AudiosMediaGalleryModule/AudiosMediaGalleryModule.php, (2) ImagesMediaGalleryModule/ImagesMediaGalleryModule.php, (3) MembersFacewallModule/MembersFacewallModule.php, (4) NewestGroupsModule/NewestGroupsModule.php, (5) UploadMediaModule/UploadMediaModule.php, and (6) VideosMediaGalleryModule/VideosMediaGalleryModule.php in BetaBlockModules/; and (7) the path_prefix parameter to several components. ### POC #### Reference - https://www.exploit-db.com/exploits/4551 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5632 (2007/CVE-2007-5632.md) ### [CVE-2007-5632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5632) ### Description Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3027 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5633 (2007/CVE-2007-5633.md) ### [CVE-2007-5633](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5633) ### Description Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to \Device\speedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR. ### POC #### Reference - http://www.bugtrack.almico.com/view.php?id=987 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5634 (2007/CVE-2007-5634.md) ### [CVE-2007-5634](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5634) ### Description Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors. ### POC #### Reference - http://www.bugtrack.almico.com/view.php?id=987 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5635 (2007/CVE-2007-5635.md) ### [CVE-2007-5635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5635) ### Description Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=547027 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5636 (2007/CVE-2007-5636.md) ### [CVE-2007-5636](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5636) ### Description Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute arbitrary code via a flood of invalid characters to the RTCP port (5678/udp) that triggers a Windows error message, aka "extraneous messaging." ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/nortel_UNIStim_IP_softphone_buffer-overflow_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5637 (2007/CVE-2007-5637.md) ### [CVE-2007-5637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5637) ### Description The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier. ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_surveillance_mode_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5638 (2007/CVE-2007-5638.md) ### [CVE-2007-5638](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5638) ### Description The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to guess the RUDP ID and spoof messages. NOTE: this can be leveraged for an eavesdropping attack by sending many Open Audio Stream messages. ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_surveillance_mode_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5639 (2007/CVE-2007-5639.md) ### [CVE-2007-5639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5639) ### Description The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling Server. ### POC #### Reference - http://securityreason.com/securityalert/3273 - http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_flooding_denial_of_service_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5640 (2007/CVE-2007-5640.md) ### [CVE-2007-5640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5640) ### Description The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration. ### POC #### Reference - http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_forced_re-authentication_v1.0.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5641 (2007/CVE-2007-5641.md) ### [CVE-2007-5641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5641) ### Description Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the full_path parameter to (1) certinfo/index.php, (2) emails/index.php, (3) events/index.php, (4) fax/index.php, (5) files/index.php, (6) files/list.php, (7) groupadm/index.php, (8) history/index.php, (9) info/index.php, (10) log/index.php, (11) mail/index.php, (12) messages/index.php, (13) organizations/index.php, (14) phones/index.php, (15) presence/index.php, (16) projects/index.php, (17) projects/summary.inc.php, (18) projects/list.php, (19) reports/index.php, (20) search/index.php, (21) snf/index.php, (22) syslog/index.php, (23) tasks/searchsimilar.php, (24) tasks/index.php, (25) tasks/summary.inc.php, and (26) useradm/index.php in modules; (27) /ajax/loadsplash.php; (28) /blocks/birthday.php; (29) /blocks/events.php; and (30) /blocks/help.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4549 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5642 (2007/CVE-2007-5642.md) ### [CVE-2007-5642](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5642) ### Description Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the def_lang parameter to modules/files/list.php; the m_path parameter to (2) modules/projects/summary.inc.php or (3) modules/tasks/summary.inc.php; (4) the module parameter to modules/projects/list.php; or the module parameter to index.php in the (5) certinfo, (6) emails, (7) events, (8) fax, (9) files, (10) groupadm, (11) history, (12) info, (13) log, (14) mail, (15) messages, (16) organizations, (17) phones, (18) presence, (19) projects, (20) reports, (21) search, (22) snf, (23) syslog, (24) tasks, or (25) useradm subdirectory of modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/4549 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5643 (2007/CVE-2007-5643.md) ### [CVE-2007-5643](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5643) ### Description Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortcategories.php or (2) an unspecified vector to ajax/sortroles.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4548 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5644 (2007/CVE-2007-5644.md) ### [CVE-2007-5644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5644) ### Description Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities. ### POC #### Reference - https://www.exploit-db.com/exploits/4548 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5646 (2007/CVE-2007-5646.md) ### [CVE-2007-5646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5646) ### Description SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php. ### POC #### Reference - http://www.simplemachines.org/community/index.php?topic=196380.0 - https://www.exploit-db.com/exploits/4547 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5647 (2007/CVE-2007-5647.md) ### [CVE-2007-5647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5647) ### Description Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) art_id or (2) node parameter in an article action to the default URI. ### POC #### Reference - http://packetstormsecurity.org/0710-exploits/socketkb-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5649 (2007/CVE-2007-5649.md) ### [CVE-2007-5649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5649) ### Description Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter. ### POC #### Reference - http://packetstormsecurity.org/0710-exploits/socketmail-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5650 (2007/CVE-2007-5650.md) ### [CVE-2007-5650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5650) ### Description Directory traversal vulnerability in system.php in ReloadCMS 1.2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php. ### POC #### Reference - http://securityreason.com/securityalert/3285 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5651 (2007/CVE-2007-5651.md) ### [CVE-2007-5651](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5651) ### Description Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP devices), IOS 12.1 and 12.2 on Cisco switches (Wired EAP devices), and CatOS 6.x through 8.x on Cisco switches allows remote attackers to cause a denial of service (device reload) via a crafted EAP Response Identity packet. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xd012/wifuzzit - https://github.com/84KaliPleXon3/wifuzzit - https://github.com/HectorTa1989/802.11-Wireless-Fuzzer - https://github.com/PleXone2019/wifuzzit - https://github.com/flowerhack/wifuzzit - https://github.com/sececter/wifuzzit --- ### 2007/CVE 2007 5653 (2007/CVE-2007-5653.md) ### [CVE-2007-5653](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5653) ### Description The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function. ### POC #### Reference - https://www.exploit-db.com/exploits/4553 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5654 (2007/CVE-2007-5654.md) ### [CVE-2007-5654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5654) ### Description LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection." ### POC #### Reference - https://www.exploit-db.com/exploits/4556 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5655 (2007/CVE-2007-5655.md) ### [CVE-2007-5655](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5655) ### Description TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers. ### POC #### Reference - http://www.tibco.com/mk/advisory.jsp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5656 (2007/CVE-2007-5656.md) ### [CVE-2007-5656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5656) ### Description TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory. ### POC #### Reference - http://www.tibco.com/mk/advisory.jsp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5657 (2007/CVE-2007-5657.md) ### [CVE-2007-5657](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5657) ### Description TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets. ### POC #### Reference - http://www.tibco.com/mk/advisory.jsp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5658 (2007/CVE-2007-5658.md) ### [CVE-2007-5658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5658) ### Description Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow. ### POC #### Reference - http://www.tibco.com/mk/advisory.jsp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5659 (2007/CVE-2007-5659.md) ### [CVE-2007-5659](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659) ### Description Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9813 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/todb-cisa/kev-cwes --- ### 2007/CVE 2007 5663 (2007/CVE-2007-5663.md) ### [CVE-2007-5663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5663) ### Description Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9928 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 5671 (2007/CVE-2007-5671.md) ### [CVE-2007-5671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5671) ### Description HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges. ### POC #### Reference - http://securityreason.com/securityalert/3922 - http://www.vmware.com/security/advisories/VMSA-2008-0009.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5674 (2007/CVE-2007-5674.md) ### [CVE-2007-5674](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5674) ### Description Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4558 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5676 (2007/CVE-2007-5676.md) ### [CVE-2007-5676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5676) ### Description PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP code via a URL in the nuke_bb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4563 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5678 (2007/CVE-2007-5678.md) ### [CVE-2007-5678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5678) ### Description SQL injection vulnerability in the Music module in phpBasic allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to the default URI. ### POC #### Reference - http://securityreason.com/securityalert/3305 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5679 (2007/CVE-2007-5679.md) ### [CVE-2007-5679](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5679) ### Description SQL injection vulnerability in index.php in DeeEmm.com DM CMS 0.7.0.Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in the media page (build_media_content.php). NOTE: it was later reported that 0.7.4 is also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/6250 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5686 (2007/CVE-2007-5686.md) ### [CVE-2007-5686](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5686) ### Description initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/Dalifo/wik-dvs-tp02 - https://github.com/Dariani223/DevOpsFinal - https://github.com/Giovanni26101982/Grupo4_Docker_Tarea3 - https://github.com/GrigGM/05-virt-04-docker-hw - https://github.com/Myash-New/05-virt-04-docker-in-practice - https://github.com/Oscar112248/Grupo4_Docker_Tarea3 - https://github.com/PajakAlexandre/wik-dps-tp02 - https://github.com/PaulJara84/Grupo4_Docker_Tarea3 - https://github.com/Telooss/TP-WIK-DPS-TP02 - https://github.com/TinchoXD/Grupo4_Docker_Tarea3 - https://github.com/cdupuis/image-api - https://github.com/drewtwitchell/scancompare - https://github.com/flyrev/security-scan-ci-presentation - https://github.com/fokypoky/places-list - https://github.com/garethr/snykout - https://github.com/jasona7/ChatCVE - https://github.com/joelckwong/anchore - https://github.com/mauraneh/WIK-DPS-TP02 - https://github.com/mmbazm/secure_license_server - https://github.com/oportero/Grupo4_Docker_Tarea3 - https://github.com/poikl246/DevSecOps-2024-v2 - https://github.com/raph-rcn/devsecops-juice-shop - https://github.com/testing-felickz/docker-scout-demo - https://github.com/valancej/anchore-five-minutes --- ### 2007/CVE 2007 5689 (2007/CVE-2007-5689.md) ### [CVE-2007-5689](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5689) ### Description The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9898 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5696 (2007/CVE-2007-5696.md) ### [CVE-2007-5696](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5696) ### Description PHP remote file inclusion vulnerability in includes.php in phpBasic allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, possibly related to the Music module. ### POC #### Reference - http://securityreason.com/securityalert/3305 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5697 (2007/CVE-2007-5697.md) ### [CVE-2007-5697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5697) ### Description Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the xarg parameter to (1) xarg_corner.php, (2) xarg_corner_bottom.php, and (3) xarg_corner_top.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4565 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5699 (2007/CVE-2007-5699.md) ### [CVE-2007-5699](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5699) ### Description Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data on TCP port 10616 that results in a long argument to the SEARCHREPORT command, a different vector than CVE-2007-2059. ### POC #### Reference - https://www.exploit-db.com/exploits/4566 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5702 (2007/CVE-2007-5702.md) ### [CVE-2007-5702](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5702) ### Description Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://swamp.svn.sourceforge.net/viewvc/swamp/trunk/swamp/webapps/webswamp/src/java/de/suse/swamp/modules/actions/LoginActions.java?r1=666&r2=700 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5707 (2007/CVE-2007-5707.md) ### [CVE-2007-5707](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5707) ### Description OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. NOTE: this has been reported as a double free, but the reports are inconsistent. ### POC #### Reference No PoCs from references. #### Github - https://github.com/1karu32s/dagda_offline - https://github.com/MrE-Fog/dagda - https://github.com/bharatsunny/dagda - https://github.com/dbeltran24/Dagda - https://github.com/eliasgranderubio/dagda - https://github.com/man151098/dagda --- ### 2007/CVE 2007 5708 (2007/CVE-2007-5708.md) ### [CVE-2007-5708](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5708) ### Description slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors that prevent the array from being null terminated. ### POC #### Reference No PoCs from references. #### Github - https://github.com/1karu32s/dagda_offline - https://github.com/MrE-Fog/dagda - https://github.com/bharatsunny/dagda - https://github.com/dbeltran24/Dagda - https://github.com/eliasgranderubio/dagda - https://github.com/man151098/dagda --- ### 2007/CVE 2007 5709 (2007/CVE-2007-5709.md) ### [CVE-2007-5709](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5709) ### Description Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file. ### POC #### Reference - https://www.exploit-db.com/exploits/4583 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5710 (2007/CVE-2007-5710.md) ### [CVE-2007-5710](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5710) ### Description Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter. ### POC #### Reference - http://www.waraxe.us/advisory-59.html #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 5711 (2007/CVE-2007-5711.md) ### [CVE-2007-5711](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5711) ### Description Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed assertion and daemon crash) via a large packet to TCP or UDP port 48000. ### POC #### Reference - http://aluigi.altervista.org/adv/wicassert-adv.txt - http://aluigi.org/poc/wicassert.zip #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5719 (2007/CVE-2007-5719.md) ### [CVE-2007-5719](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5719) ### Description SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4587 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5720 (2007/CVE-2007-5720.md) ### [CVE-2007-5720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5720) ### Description Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile. ### POC #### Reference - https://www.exploit-db.com/exploits/4586 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5721 (2007/CVE-2007-5721.md) ### [CVE-2007-5721](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5721) ### Description PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the rootBase parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4585 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5728 (2007/CVE-2007-5728.md) ### [CVE-2007-5728](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5728) ### Description Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/gnarkill78/CSA_S2_2024 --- ### 2007/CVE 2007 5731 (2007/CVE-2007-5731.md) ### [CVE-2007-5731](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5731) ### Description Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461. ### POC #### Reference - https://www.exploit-db.com/exploits/4567 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5753 (2007/CVE-2007-5753.md) ### [CVE-2007-5753](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5753) ### Description Unspecified vulnerability in Light FMan PHP (lfman or lightfman) before 2.0rc1 has unknown impact and attack vectors related to "actions." ### POC #### Reference - http://sourceforge.net/forum/forum.php?forum_id=749157 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5754 (2007/CVE-2007-5754.md) ### [CVE-2007-5754](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5754) ### Description PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the dir_ws parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4588 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5755 (2007/CVE-2007-5755.md) ### [CVE-2007-5755](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5755) ### Description Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5759 (2007/CVE-2007-5759.md) ### [CVE-2007-5759](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5759) ### Description ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6335. Reason: This candidate is a duplicate of CVE-2007-6335. Notes: All CVE users should reference CVE-2007-6335 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. ### POC #### Reference No PoCs from references. #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 5771 (2007/CVE-2007-5771.md) ### [CVE-2007-5771](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5771) ### Description Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/4562 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5772 (2007/CVE-2007-5772.md) ### [CVE-2007-5772](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5772) ### Description Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue. ### POC #### Reference - https://www.exploit-db.com/exploits/4562 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5773 (2007/CVE-2007-5773.md) ### [CVE-2007-5773](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5773) ### Description Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4561 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5774 (2007/CVE-2007-5774.md) ### [CVE-2007-5774](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5774) ### Description index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message. ### POC #### Reference - https://www.exploit-db.com/exploits/4561 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5779 (2007/CVE-2007-5779.md) ### [CVE-2007-5779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5779) ### Description Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method. ### POC #### Reference - https://www.exploit-db.com/exploits/4579 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5780 (2007/CVE-2007-5780.md) ### [CVE-2007-5780](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5780) ### Description PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4582 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5781 (2007/CVE-2007-5781.md) ### [CVE-2007-5781](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5781) ### Description PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PATH parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4581 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5782 (2007/CVE-2007-5782.md) ### [CVE-2007-5782](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5782) ### Description Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4580 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5783 (2007/CVE-2007-5783.md) ### [CVE-2007-5783](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5783) ### Description SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4578 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5784 (2007/CVE-2007-5784.md) ### [CVE-2007-5784](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5784) ### Description PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4577 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5785 (2007/CVE-2007-5785.md) ### [CVE-2007-5785](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5785) ### Description SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4576 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5786 (2007/CVE-2007-5786.md) ### [CVE-2007-5786](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5786) ### Description Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php in include/; (5) inc_group.php; (6) inc_manager.php; (7) inc_newgroup.php; (8) inc_smb_conf.php; (9) inc_user.php; or (10) main.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4575 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5800 (2007/CVE-2007-5800.md) ### [CVE-2007-5800](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5800) ### Description Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other unspecified scripts under plugins/BackUp/Archive/. ### POC #### Reference - https://www.exploit-db.com/exploits/4593 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 5802 (2007/CVE-2007-5802.md) ### [CVE-2007-5802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5802) ### Description Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function declaration. ### POC #### Reference - http://securityreason.com/securityalert/3335 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5803 (2007/CVE-2007-5803.md) ### [CVE-2007-5803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5803) ### Description Multiple cross-site scripting (XSS) vulnerabilities in CGI programs in Nagios before 2.12 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-5624 and CVE-2008-1360. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=600377 - http://sourceforge.net/project/shownotes.php?release_id=600377&group_id=26589 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5806 (2007/CVE-2007-5806.md) ### [CVE-2007-5806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5806) ### Description Cross-site scripting (XSS) vulnerability in Services/Utilities/classes/class.ilUtil.php in ILIAS 3.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via attributes inside a domain-name string in the (1) mailing or (2) forum component, as demonstrated using the style and onmouseover HTML attributes. ### POC #### Reference - http://securityreason.com/securityalert/3340 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5811 (2007/CVE-2007-5811.md) ### [CVE-2007-5811](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5811) ### Description Directory traversal vulnerability in PageTraiteDownload.php in phpMyConferences 8.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter. NOTE: this issue is disputed for 8.0.2 by a reliable third party, who notes that the PHP code is syntactically incorrect and cannot be executed ### POC #### Reference - https://www.exploit-db.com/exploits/4590 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5812 (2007/CVE-2007-5812.md) ### [CVE-2007-5812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5812) ### Description Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4591 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5813 (2007/CVE-2007-5813.md) ### [CVE-2007-5813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5813) ### Description Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4592 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5814 (2007/CVE-2007-5814.md) ### [CVE-2007-5814](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5814) ### Description Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote attackers to execute arbitrary code via a long (1) serverAddress, (2) sessionId, (3) clientIPLower, (4) clientIPHigher, (5) userName, (6) domainName, or (7) dnsSuffix Unicode property value. NOTE: the AddRouteEntry vector is covered by CVE-2007-5603. ### POC #### Reference - http://securityreason.com/securityalert/3342 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5815 (2007/CVE-2007-5815.md) ### [CVE-2007-5815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5815) ### Description Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitrary files via a full pathname in the argument to the FileDelete method. ### POC #### Reference - http://securityreason.com/securityalert/3342 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5816 (2007/CVE-2007-5816.md) ### [CVE-2007-5816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5816) ### Description dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editauthor action, then reading the value of the newlocalpassword password input field in the HTML source of the resulting page. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0710-exploits/contentcustom-disclose.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5817 (2007/CVE-2007-5817.md) ### [CVE-2007-5817](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5817) ### Description dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) and possibly other attacks. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0710-exploits/contentcustom-disclose.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5820 (2007/CVE-2007-5820.md) ### [CVE-2007-5820](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5820) ### Description Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4599 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5821 (2007/CVE-2007-5821.md) ### [CVE-2007-5821](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5821) ### Description Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lng parameter to (a) guestbook.php, (b) admin/admin.guestbook.php, or (c) auto/glob_new.php; or (2) the lngdefault parameter to auto/ch_lng.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4597 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5822 (2007/CVE-2007-5822.md) ### [CVE-2007-5822](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5822) ### Description Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a certain file in regged/ via the username parameter in a Register action, possibly related to the register function in forumfunctions.php. ### POC #### Reference - http://securityreason.com/securityalert/3339 - https://www.exploit-db.com/exploits/4596 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5823 (2007/CVE-2007-5823.md) ### [CVE-2007-5823](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5823) ### Description Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the username parameter in a Register action. ### POC #### Reference - http://securityreason.com/securityalert/3339 - https://www.exploit-db.com/exploits/4596 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5824 (2007/CVE-2007-5824.md) ### [CVE-2007-5824](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5824) ### Description webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=98211&release_id=548679 - https://www.exploit-db.com/exploits/4600 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5825 (2007/CVE-2007-5825.md) ### [CVE-2007-5825](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5825) ### Description Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=98211&release_id=548679 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5826 (2007/CVE-2007-5826.md) ### [CVE-2007-5826](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5826) ### Description Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420. ### POC #### Reference - https://www.exploit-db.com/exploits/4598 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5828 (2007/CVE-2007-5828.md) ### [CVE-2007-5828](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5828) ### Description Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module ### POC #### Reference - http://securityreason.com/securityalert/3338 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5838 (2007/CVE-2007-5838.md) ### [CVE-2007-5838](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5838) ### Description Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment server" browser option, a different issue than CVE-2007-4380. ### POC #### Reference - http://www.symantec.com/avcenter/security/Content/2007.10.31a.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5840 (2007/CVE-2007-5840.md) ### [CVE-2007-5840](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5840) ### Description PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter, a different vector than CVE-2006-4920.2. ### POC #### Reference - https://www.exploit-db.com/exploits/4607 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5841 (2007/CVE-2007-5841.md) ### [CVE-2007-5841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5841) ### Description PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4606 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5842 (2007/CVE-2007-5842.md) ### [CVE-2007-5842](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5842) ### Description Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter to (1) admincp/auth/secure.php or (2) admincp/auth/checklogin.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4605 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5843 (2007/CVE-2007-5843.md) ### [CVE-2007-5843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5843) ### Description PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the pathdot parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4604 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5844 (2007/CVE-2007-5844.md) ### [CVE-2007-5844](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5844) ### Description Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin parameter to index.php. NOTE: this can be leveraged for remote file inclusion by including inc/boxleft.inc and specifying a URL in the xposbox[L][] array parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4602 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5845 (2007/CVE-2007-5845.md) ### [CVE-2007-5845](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5845) ### Description Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: this can be leveraged to bypass authentication and upload arbitrary files by including admin/inc/upload.inc and specifying certain multipart/form-data input for admin/inc/upload.inc. ### POC #### Reference - https://www.exploit-db.com/exploits/3221 - https://www.exploit-db.com/exploits/4602 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5846 (2007/CVE-2007-5846.md) ### [CVE-2007-5846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846) ### Description The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value. ### POC #### Reference - https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5849 (2007/CVE-2007-5849.md) ### [CVE-2007-5849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5849) ### Description Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow. ### POC #### Reference - http://www.cups.org/str.php?L2589 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5887 (2007/CVE-2007-5887.md) ### [CVE-2007-5887](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5887) ### Description SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4609 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5889 (2007/CVE-2007-5889.md) ### [CVE-2007-5889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5889) ### Description Multiple PHP remote file inclusion vulnerabilities in IDMOS 1.0 Alpha (aka Phoenix) allow remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter to (1) admin.php, (2) menu_add.php, and (3) menu_operation.php in administrator/, different vectors than CVE-2007-5294. ### POC #### Reference - http://securityreason.com/securityalert/3345 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5898 (2007/CVE-2007-5898.md) ### [CVE-2007-5898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5898) ### Description The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0546.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5899 (2007/CVE-2007-5899.md) ### [CVE-2007-5899](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5899) ### Description The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0546.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5901 (2007/CVE-2007-5901.md) ### [CVE-2007-5901](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5901) ### Description Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199214 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5902 (2007/CVE-2007-5902.md) ### [CVE-2007-5902](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5902) ### Description Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199214 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5904 (2007/CVE-2007-5904.md) ### [CVE-2007-5904](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5904) ### Description Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9901 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5907 (2007/CVE-2007-5907.md) ### [CVE-2007-5907](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5907) ### Description Xen 3.1.1 does not prevent modification of the CR4 TSC from applications, which allows pv guests to cause a denial of service (crash). ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0957.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5909 (2007/CVE-2007-5909.md) ### [CVE-2007-5909](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5909) ### Description Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910. ### POC #### Reference - http://vuln.sg/lotusnotes702doc-en.html - http://vuln.sg/lotusnotes702mif-en.html - http://vuln.sg/lotusnotes702sam-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5910 (2007/CVE-2007-5910.md) ### [CVE-2007-5910](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5910) ### Description Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file. ### POC #### Reference - http://vuln.sg/lotusnotes702wpd-en.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5911 (2007/CVE-2007-5911.md) ### [CVE-2007-5911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5911) ### Description Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote attackers to execute arbitrary code via a long string argument to the (1) BroadcastKey, (2) BroadcastKeyFileURL, (3) Component, (4) ComponentClassID, (5) ComponentFileName, (6) ExtraProperty, (7) Properties, (8) RequiredVersions, (9) Source, or (10) XMLText method. ### POC #### Reference - https://www.exploit-db.com/exploits/4610 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5912 (2007/CVE-2007-5912.md) ### [CVE-2007-5912](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5912) ### Description SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4611 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5913 (2007/CVE-2007-5913.md) ### [CVE-2007-5913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5913) ### Description dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4608 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5914 (2007/CVE-2007-5914.md) ### [CVE-2007-5914](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5914) ### Description Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing config.inc.php. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2007-5913. ### POC #### Reference - https://www.exploit-db.com/exploits/4608 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5919 (2007/CVE-2007-5919.md) ### [CVE-2007-5919](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5919) ### Description MyWebFTP, possibly 5.3.2, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain an MD5 password hash via a direct request for pass/pass.txt. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Farrhouq/Inpt-report --- ### 2007/CVE 2007 5920 (2007/CVE-2007-5920.md) ### [CVE-2007-5920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5920) ### Description index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative scripts. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/rnbochsr/yr_of_the_jellyfish --- ### 2007/CVE 2007 5925 (2007/CVE-2007-5925.md) ### [CVE-2007-5925](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5925) ### Description The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=198988 #### Github - https://github.com/lekctut/sdb-hw-13-01 - https://github.com/pedr0alencar/vlab-metasploitable2 --- ### 2007/CVE 2007 5926 (2007/CVE-2007-5926.md) ### [CVE-2007-5926](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5926) ### Description OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures. ### POC #### Reference - http://www.netragard.com/pdfs/research/NETRAGARD-20070313-OPENBASE.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5927 (2007/CVE-2007-5927.md) ### [CVE-2007-5927](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5927) ### Description Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926. ### POC #### Reference - http://www.netragard.com/pdfs/research/NETRAGARD-20070313-OPENBASE.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5928 (2007/CVE-2007-5928.md) ### [CVE-2007-5928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5928) ### Description OpenBase 10.0.5 and earlier allows remote authenticated users to trigger a free of an arbitrary memory location via long strings in a SELECT statement. NOTE: this might be a buffer overflow, but it is not clear. ### POC #### Reference - http://www.netragard.com/pdfs/research/NETRAGARD-20070313-OPENBASE.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5929 (2007/CVE-2007-5929.md) ### [CVE-2007-5929](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5929) ### Description Buffer overflow in OpenBase 10.0.5 and earlier might allow remote authenticated users to execute arbitrary code or cause a denial of service (daemon crash) by creating a stored procedure with a long name and invoking this procedure, which triggers heap corruption. ### POC #### Reference - http://www.netragard.com/pdfs/research/NETRAGARD-20070313-OPENBASE.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5938 (2007/CVE-2007-5938.md) ### [CVE-2007-5938](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5938) ### Description The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode return value without checking for NULL, which might allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors during module initialization. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199209 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10787 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5941 (2007/CVE-2007-5941.md) ### [CVE-2007-5941](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5941) ### Description Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method. ### POC #### Reference - https://www.exploit-db.com/exploits/4613 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5947 (2007/CVE-2007-5947.md) ### [CVE-2007-5947](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947) ### Description The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI. ### POC #### Reference - http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues - http://www.mozilla.org/security/announce/2007/mfsa2007-37.html - http://www.vupen.com/english/advisories/2008/0083 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9873 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5958 (2007/CVE-2007-5958.md) ### [CVE-2007-5958](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958) ### Description X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists. ### POC #### Reference - https://www.exploit-db.com/exploits/5152 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5959 (2007/CVE-2007-5959.md) ### [CVE-2007-5959](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5959) ### Description Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/0083 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5960 (2007/CVE-2007-5960.md) ### [CVE-2007-5960](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5960) ### Description Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/0083 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5962 (2007/CVE-2007-5962.md) ### [CVE-2007-5962](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5962) ### Description Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option. ### POC #### Reference - https://www.exploit-db.com/exploits/5814 #### Github - https://github.com/CVEDB/awesome-cve-repo - https://github.com/antogit-sys/CVE-2007-5962 --- ### 2007/CVE 2007 5966 (2007/CVE-2007-5966.md) ### [CVE-2007-5966](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5966) ### Description Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code or cause a denial of service (panic) via a large relative timeout value. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2009-1193.html - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5969 (2007/CVE-2007-5969.md) ### [CVE-2007-5969](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5969) ### Description MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ptester36-zz/netology_ib_networks_lesson_9 - https://github.com/ptester36/netology_ib_networks_lesson_9 --- ### 2007/CVE 2007 5973 (2007/CVE-2007-5973.md) ### [CVE-2007-5973](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5973) ### Description SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4614 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5974 (2007/CVE-2007-5974.md) ### [CVE-2007-5974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5974) ### Description SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4611 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5979 (2007/CVE-2007-5979.md) ### [CVE-2007-5979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5979) ### Description Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter. ### POC #### Reference - http://securityreason.com/securityalert/3364 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5980 (2007/CVE-2007-5980.md) ### [CVE-2007-5980](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5980) ### Description Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=155425&release_id=553433 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5982 (2007/CVE-2007-5982.md) ### [CVE-2007-5982](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5982) ### Description Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to help/index.php, or the (3) INSTALL_X7CHATVERSION parameter to upgradev1.php. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0711-exploits/x7-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5983 (2007/CVE-2007-5983.md) ### [CVE-2007-5983](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5983) ### Description Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). ### POC #### Reference - http://securityreason.com/securityalert/3360 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5984 (2007/CVE-2007-5984.md) ### [CVE-2007-5984](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5984) ### Description classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation." ### POC #### Reference - http://securityreason.com/securityalert/3360 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5985 (2007/CVE-2007-5985.md) ### [CVE-2007-5985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5985) ### Description Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?group_id=146822&release_id=552477 - http://sourceforge.net/tracker/index.php?func=detail&aid=1753797&group_id=146822&atid=766508 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5989 (2007/CVE-2007-5989.md) ### [CVE-2007-5989](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5989) ### Description Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 5992 (2007/CVE-2007-5992.md) ### [CVE-2007-5992](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5992) ### Description SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page. ### POC #### Reference - https://www.exploit-db.com/exploits/4622 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5993 (2007/CVE-2007-5993.md) ### [CVE-2007-5993](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5993) ### Description Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter. ### POC #### Reference - http://securityreason.com/securityalert/3369 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5994 (2007/CVE-2007-5994.md) ### [CVE-2007-5994](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5994) ### Description PHP remote file inclusion vulnerability in check_noimage.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the config[path_src_include] parameter. ### POC #### Reference - http://packetstormsecurity.org/0711-exploits/yappa-ng-rfi.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5995 (2007/CVE-2007-5995.md) ### [CVE-2007-5995](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5995) ### Description PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the example parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4621 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5996 (2007/CVE-2007-5996.md) ### [CVE-2007-5996](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5996) ### Description SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449. ### POC #### Reference - https://www.exploit-db.com/exploits/4620 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5997 (2007/CVE-2007-5997.md) ### [CVE-2007-5997](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5997) ### Description SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4619 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5998 (2007/CVE-2007-5998.md) ### [CVE-2007-5998](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5998) ### Description SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4618 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 5999 (2007/CVE-2007-5999.md) ### [CVE-2007-5999](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5999) ### Description SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4617 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6000 (2007/CVE-2007-6000.md) ### [CVE-2007-6000](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6000) ### Description KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. ### POC #### Reference - http://securityreason.com/securityalert/3370 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6004 (2007/CVE-2007-6004.md) ### [CVE-2007-6004](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6004) ### Description Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an artikel action or (2) the katid parameter in a produk action. ### POC #### Reference - https://www.exploit-db.com/exploits/4623 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6005 (2007/CVE-2007-6005.md) ### [CVE-2007-6005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6005) ### Description Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119498701505838&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6012 (2007/CVE-2007-6012.md) ### [CVE-2007-6012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6012) ### Description SQL injection vulnerability in SearchR.asp in DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary SQL commands via the artnr parameter (aka the search section). NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/3374 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6013 (2007/CVE-2007-6013.md) ### [CVE-2007-6013](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6013) ### Description Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash. ### POC #### Reference - http://securityreason.com/securityalert/3375 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 6015 (2007/CVE-2007-6015.md) ### [CVE-2007-6015](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015) ### Description Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=200773 #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- - https://github.com/victorialugi/nmap --- ### 2007/CVE 2007 6016 (2007/CVE-2007-6016.md) ### [CVE-2007-6016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6016) ### Description Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control. ### POC #### Reference - https://www.exploit-db.com/exploits/5205 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6017 (2007/CVE-2007-6017.md) ### [CVE-2007-6017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6017) ### Description The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary files, via string values of the (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, and (19) _MonthText11 properties. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control. ### POC #### Reference - http://support.veritas.com/docs/300471 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6019 (2007/CVE-2007-6019.md) ### [CVE-2007-6019](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6019) ### Description Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1697 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6020 (2007/CVE-2007-6020.md) ### [CVE-2007-6020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6020) ### Description Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6026 (2007/CVE-2007-6026.md) ### [CVE-2007-6026](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6026) ### Description Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944. ### POC #### Reference - http://securityreason.com/securityalert/3376 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6027 (2007/CVE-2007-6027.md) ### [CVE-2007-6027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6027) ### Description PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4626 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6028 (2007/CVE-2007-6028.md) ### [CVE-2007-6028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6028) ### Description Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119517573408574&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6029 (2007/CVE-2007-6029.md) ### [CVE-2007-6029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6029) ### Description Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. ### POC #### Reference - http://wabisabilabi.blogspot.com/2007/11/focus-on-clamav-remote-code-execution.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6032 (2007/CVE-2007-6032.md) ### [CVE-2007-6032](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6032) ### Description SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter. ### POC #### Reference - http://packetstormsecurity.org/0710-exploits/aleris-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6033 (2007/CVE-2007-6033.md) ### [CVE-2007-6033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6033) ### Description Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs. ### POC #### Reference - http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6036 (2007/CVE-2007-6036.md) ### [CVE-2007-6036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6036) ### Description The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, which causes a negative number to be used during memory allocation. ### POC #### Reference - http://aluigi.altervista.org/adv/live555x-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6037 (2007/CVE-2007-6037.md) ### [CVE-2007-6037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6037) ### Description Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters. ### POC #### Reference - http://securityreason.com/securityalert/3377 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6038 (2007/CVE-2007-6038.md) ### [CVE-2007-6038](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6038) ### Description PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4636 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6039 (2007/CVE-2007-6039.md) ### [CVE-2007-6039](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6039) ### Description PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution. ### POC #### Reference - http://securityreason.com/securityalert/3365 - http://securityreason.com/securityalert/3366 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6041 (2007/CVE-2007-6041.md) ### [CVE-2007-6041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6041) ### Description Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code by sending a nickname, then a vehicle name in a MSG2_USE_VEHICLE message, in which the combined length triggers the overflow. ### POC #### Reference - http://aluigi.altervista.org/adv/rorbof-adv.txt - http://aluigi.org/poc/rorbof.zip #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6043 (2007/CVE-2007-6043.md) ### [CVE-2007-6043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6043) ### Description The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898. ### POC #### Reference - http://www.computerworld.com.au/index.php/id%3B1165210682%3Bfp%3B2%3Bfpid%3B1 - http://www.computerworld.com.au/index.php/id;1165210682;fp;2;fpid;1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6055 (2007/CVE-2007-6055.md) ### [CVE-2007-6055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6055) ### Description Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date. ### POC #### Reference - http://securityreason.com/securityalert/3379 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6057 (2007/CVE-2007-6057.md) ### [CVE-2007-6057](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6057) ### Description PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4628 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6058 (2007/CVE-2007-6058.md) ### [CVE-2007-6058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6058) ### Description Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module. ### POC #### Reference - https://www.exploit-db.com/exploits/4627 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6063 (2007/CVE-2007-6063.md) ### [CVE-2007-6063](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6063) ### Description Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9846 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6078 (2007/CVE-2007-6078.md) ### [CVE-2007-6078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6078) ### Description Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.asp, possibly involving a parameter passed from cp_main.asp; (3) inc_profile_functions.asp; or (4) inc_SUBSCRIPTIONS.asp; or the (5) Avatar_URL, (6) LINK1, or (7) LINK2 parameter to cp_main.asp in an EditIt action. ### POC #### Reference - https://www.exploit-db.com/exploits/4638 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6079 (2007/CVE-2007-6079.md) ### [CVE-2007-6079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6079) ### Description Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file. ### POC #### Reference - https://www.exploit-db.com/exploits/4637 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6080 (2007/CVE-2007-6080.md) ### [CVE-2007-6080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6080) ### Description SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4637 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6082 (2007/CVE-2007-6082.md) ### [CVE-2007-6082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6082) ### Description Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4635 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6083 (2007/CVE-2007-6083.md) ### [CVE-2007-6083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6083) ### Description SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/4634 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6084 (2007/CVE-2007-6084.md) ### [CVE-2007-6084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6084) ### Description SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4633 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6085 (2007/CVE-2007-6085.md) ### [CVE-2007-6085](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6085) ### Description Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module. ### POC #### Reference - https://www.exploit-db.com/exploits/4632 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6086 (2007/CVE-2007-6086.md) ### [CVE-2007-6086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6086) ### Description Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4632 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6087 (2007/CVE-2007-6087.md) ### [CVE-2007-6087](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6087) ### Description Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module. ### POC #### Reference - https://www.exploit-db.com/exploits/4632 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6088 (2007/CVE-2007-6088.md) ### [CVE-2007-6088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6088) ### Description PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4631 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6089 (2007/CVE-2007-6089.md) ### [CVE-2007-6089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6089) ### Description PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4630 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6103 (2007/CVE-2007-6103.md) ### [CVE-2007-6103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6103) ### Description I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size field in its header, which is improperly handled by the Receiver::processPacket function; and (2) a denial of service (daemon crash) via an (a) IHU_INFO_INIT or a (b) IHU_INFO_RING packet that does not specify the mode, which is improperly handled by the Player::ring function in Player.cpp. ### POC #### Reference - http://aluigi.altervista.org/adv/ihudos-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6105 (2007/CVE-2007-6105.md) ### [CVE-2007-6105](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6105) ### Description Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to comments-display-tpl.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4640 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6106 (2007/CVE-2007-6106.md) ### [CVE-2007-6106](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6106) ### Description SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action. ### POC #### Reference - https://www.exploit-db.com/exploits/4641 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6110 (2007/CVE-2007-6110.md) ### [CVE-2007-6110](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6110) ### Description Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6111 (2007/CVE-2007-6111.md) ### [CVE-2007-6111](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6111) ### Description Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9048 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6112 (2007/CVE-2007-6112.md) ### [CVE-2007-6112](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6112) ### Description Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9772 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6113 (2007/CVE-2007-6113.md) ### [CVE-2007-6113](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6113) ### Description Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - http://securityreason.com/securityalert/3095 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9841 - https://www.exploit-db.com/exploits/4347 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6114 (2007/CVE-2007-6114.md) ### [CVE-2007-6114](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6114) ### Description Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) the SSL dissector or (2) the iSeries (OS/400) Communication trace file parser. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6115 (2007/CVE-2007-6115.md) ### [CVE-2007-6115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6115) ### Description Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9726 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6116 (2007/CVE-2007-6116.md) ### [CVE-2007-6116](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6116) ### Description The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9799 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6117 (2007/CVE-2007-6117.md) ### [CVE-2007-6117](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6117) ### Description Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6118 (2007/CVE-2007-6118.md) ### [CVE-2007-6118](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6118) ### Description The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6119 (2007/CVE-2007-6119.md) ### [CVE-2007-6119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6119) ### Description The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9880 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6120 (2007/CVE-2007-6120.md) ### [CVE-2007-6120](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6120) ### Description The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9488 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6121 (2007/CVE-2007-6121.md) ### [CVE-2007-6121](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6121) ### Description Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6124 (2007/CVE-2007-6124.md) ### [CVE-2007-6124](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6124) ### Description Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4660 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6125 (2007/CVE-2007-6125.md) ### [CVE-2007-6125](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6125) ### Description SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4660 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6126 (2007/CVE-2007-6126.md) ### [CVE-2007-6126](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6126) ### Description Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4655 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6127 (2007/CVE-2007-6127.md) ### [CVE-2007-6127](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6127) ### Description Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4655 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6128 (2007/CVE-2007-6128.md) ### [CVE-2007-6128](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6128) ### Description SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL commands via the idevent parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4653 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6129 (2007/CVE-2007-6129.md) ### [CVE-2007-6129](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6129) ### Description Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL. ### POC #### Reference - https://www.exploit-db.com/exploits/4652 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6133 (2007/CVE-2007-6133.md) ### [CVE-2007-6133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6133) ### Description PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the kfm_base_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4642 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6134 (2007/CVE-2007-6134.md) ### [CVE-2007-6134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6134) ### Description SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article action to include.php, a different vector than CVE-2006-1773. ### POC #### Reference - https://www.exploit-db.com/exploits/4646 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6135 (2007/CVE-2007-6135.md) ### [CVE-2007-6135](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6135) ### Description Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file. ### POC #### Reference - http://www.packetstormsecurity.org/0711-exploits/phpslideshow-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6137 (2007/CVE-2007-6137.md) ### [CVE-2007-6137](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6137) ### Description SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4645 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6139 (2007/CVE-2007-6139.md) ### [CVE-2007-6139](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6139) ### Description PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4650 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6140 (2007/CVE-2007-6140.md) ### [CVE-2007-6140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6140) ### Description Multiple SQL injection vulnerabilities in Dora Emlak 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) emlak_detay.asp and (b) haber_detay.asp, the (2) kategori parameter to (c) kategorisirala.asp, and the (3) tip parameter to (d) tipsirala.asp. ### POC #### Reference - http://www.packetstormsecurity.org/0711-exploits/dora-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6144 (2007/CVE-2007-6144.md) ### [CVE-2007-6144](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6144) ### Description Heap-based buffer overflow in the PPlayer.XPPlayer.1 ActiveX control in pplayer.dll_1_work in Xunlei Thunder 5.7.4.401 allows remote attackers to execute arbitrary code via a long string in a FlvPlayerUrl property value. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6147 (2007/CVE-2007-6147.md) ### [CVE-2007-6147](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6147) ### Description Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/. ### POC #### Reference - https://www.exploit-db.com/exploits/4659 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6151 (2007/CVE-2007-6151.md) ### [CVE-2007-6151](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6151) ### Description The isdn_ioctl function in isdn_common.c in Linux kernel 2.6.23 allows local users to cause a denial of service via a crafted ioctl struct in which iocts is not null terminated, which triggers a buffer overflow. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6159 (2007/CVE-2007-6159.md) ### [CVE-2007-6159](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6159) ### Description SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500. ### POC #### Reference - http://securityreason.com/securityalert/3402 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6160 (2007/CVE-2007-6160.md) ### [CVE-2007-6160](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6160) ### Description Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a yeardetail action. ### POC #### Reference - http://securityreason.com/securityalert/3402 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6161 (2007/CVE-2007-6161.md) ### [CVE-2007-6161](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6161) ### Description index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search action, which reveals the path. ### POC #### Reference - http://securityreason.com/securityalert/3402 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6164 (2007/CVE-2007-6164.md) ### [CVE-2007-6164](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6164) ### Description Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) reviews.php, (2) links.php and (3) articles.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4665 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6165 (2007/CVE-2007-6165.md) ### [CVE-2007-6165](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6165) ### Description Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395. ### POC #### Reference - http://www.heise-security.co.uk/news/99257 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6166 (2007/CVE-2007-6166.md) ### [CVE-2007-6166](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166) ### Description Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header. ### POC #### Reference - http://securityreason.com/securityalert/3410 - http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control - https://www.exploit-db.com/exploits/4648 - https://www.exploit-db.com/exploits/6013 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6172 (2007/CVE-2007-6172.md) ### [CVE-2007-6172](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6172) ### Description Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4668 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6176 (2007/CVE-2007-6176.md) ### [CVE-2007-6176](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6176) ### Description kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action. ### POC #### Reference - https://www.exploit-db.com/exploits/4647 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6177 (2007/CVE-2007-6177.md) ### [CVE-2007-6177](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6177) ### Description PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the webappcfg[APPPATH] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4670 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6178 (2007/CVE-2007-6178.md) ### [CVE-2007-6178](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6178) ### Description Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/. ### POC #### Reference - https://www.exploit-db.com/exploits/4671 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6179 (2007/CVE-2007-6179.md) ### [CVE-2007-6179](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6179) ### Description Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_library_path parameter to (1) markdown.php and (2) gallery.php in decoder/. ### POC #### Reference - https://www.exploit-db.com/exploits/4672 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6181 (2007/CVE-2007-6181.md) ### [CVE-2007-6181](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6181) ### Description Heap-based buffer overflow in cygwin1.dll in Cygwin 1.5.7 and earlier allows context-dependent attackers to execute arbitrary code via a filename with a certain length, as demonstrated by a remote authenticated user who uses the SCP protocol to send a file to the Cygwin machine, and thereby causes scp.exe on this machine to execute, and then overwrite heap memory with characters from the filename. NOTE: it is also reported that a related issue might exist in 1.5.7 through 1.5.19. ### POC #### Reference - http://securityreason.com/securityalert/3406 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6183 (2007/CVE-2007-6183.md) ### [CVE-2007-6183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6183) ### Description Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows context-dependent attackers to execute arbitrary code via format string specifiers in the message parameter. ### POC #### Reference - http://securityreason.com/securityalert/3407 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6184 (2007/CVE-2007-6184.md) ### [CVE-2007-6184](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6184) ### Description Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4669 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6185 (2007/CVE-2007-6185.md) ### [CVE-2007-6185](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6185) ### Description Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a download action, as demonstrated by a certain PHP file containing database credentials. ### POC #### Reference - http://securityreason.com/securityalert/3408 - https://www.exploit-db.com/exploits/4666 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6187 (2007/CVE-2007-6187.md) ### [CVE-2007-6187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6187) ### Description Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filepath parameter to (1) css_file.php, (2) js_file.php, or (3) xml_file.php in noah/modules/nosystem/templates/. ### POC #### Reference - https://www.exploit-db.com/exploits/4675 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6188 (2007/CVE-2007-6188.md) ### [CVE-2007-6188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6188) ### Description Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4674 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6189 (2007/CVE-2007-6189.md) ### [CVE-2007-6189](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6189) ### Description A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow. ### POC #### Reference - http://securityreason.com/securityalert/3405 - https://www.exploit-db.com/exploits/4663 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6191 (2007/CVE-2007-6191.md) ### [CVE-2007-6191](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6191) ### Description Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incphp/globals.php or (2) plugins/export/mc_table.php. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in p.mapper. ### POC #### Reference - http://www.packetstormsecurity.org/0711-exploits/pmapper-rfi.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6195 (2007/CVE-2007-6195.md) ### [CVE-2007-6195](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6195) ### Description Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5710 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6202 (2007/CVE-2007-6202.md) ### [CVE-2007-6202](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6202) ### Description SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4678 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6203 (2007/CVE-2007-6203.md) ### [CVE-2007-6203](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6203) ### Description Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/kasem545/vulnsearch - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6204 (2007/CVE-2007-6204.md) ### [CVE-2007-6204](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6204) ### Description Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe. ### POC #### Reference - https://www.exploit-db.com/exploits/4724 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6207 (2007/CVE-2007-6207.md) ### [CVE-2007-6207](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6207) ### Description Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9471 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6212 (2007/CVE-2007-6212.md) ### [CVE-2007-6212](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6212) ### Description Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4679 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6213 (2007/CVE-2007-6213.md) ### [CVE-2007-6213](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6213) ### Description Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4677 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6214 (2007/CVE-2007-6214.md) ### [CVE-2007-6214](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6214) ### Description Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter. NOTE: exploitation requires that the product is configured, but has zero files in the database. ### POC #### Reference - https://www.exploit-db.com/exploits/4680 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6215 (2007/CVE-2007-6215.md) ### [CVE-2007-6215](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6215) ### Description Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (2) bookid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4676 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6217 (2007/CVE-2007-6217.md) ### [CVE-2007-6217](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6217) ### Description Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username) and (2) password parameters. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4649 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6218 (2007/CVE-2007-6218.md) ### [CVE-2007-6218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6218) ### Description Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234. ### POC #### Reference - http://www.packetstormsecurity.org/0711-exploits/ossigeno22-rfi.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6223 (2007/CVE-2007-6223.md) ### [CVE-2007-6223](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6223) ### Description SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode. ### POC #### Reference - https://www.exploit-db.com/exploits/4686 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6224 (2007/CVE-2007-6224.md) ### [CVE-2007-6224](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6224) ### Description The RealNetworks RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll, as shipped with RealPlayer 11, allows remote attackers to cause a denial of service (browser crash) via a certain argument to the GetSourceTransport method. ### POC #### Reference - http://securityreason.com/securityalert/3415 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6229 (2007/CVE-2007-6229.md) ### [CVE-2007-6229](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6229) ### Description PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[site][project_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4685 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6230 (2007/CVE-2007-6230.md) ### [CVE-2007-6230](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6230) ### Description Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CFG[site][project_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4685 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6231 (2007/CVE-2007-6231.md) ### [CVE-2007-6231](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6231) ### Description Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server. ### POC #### Reference - https://www.exploit-db.com/exploits/4684 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6232 (2007/CVE-2007-6232.md) ### [CVE-2007-6232](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6232) ### Description Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action. ### POC #### Reference - https://www.exploit-db.com/exploits/4681 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6233 (2007/CVE-2007-6233.md) ### [CVE-2007-6233](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6233) ### Description Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL. ### POC #### Reference - https://www.exploit-db.com/exploits/4681 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6234 (2007/CVE-2007-6234.md) ### [CVE-2007-6234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6234) ### Description index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account. ### POC #### Reference - https://www.exploit-db.com/exploits/4681 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6235 (2007/CVE-2007-6235.md) ### [CVE-2007-6235](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6235) ### Description A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. NOTE: this might be related to CVE-2007-4904. ### POC #### Reference - https://www.exploit-db.com/exploits/4683 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6236 (2007/CVE-2007-6236.md) ### [CVE-2007-6236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6236) ### Description Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff. ### POC #### Reference - https://www.exploit-db.com/exploits/4682 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6237 (2007/CVE-2007-6237.md) ### [CVE-2007-6237](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6237) ### Description cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php. ### POC #### Reference - http://securityreason.com/securityalert/3416 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6238 (2007/CVE-2007-6238.md) ### [CVE-2007-6238](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6238) ### Description Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the organization has stated that this is different than CVE-2007-6166. ### POC #### Reference - http://wabisabilabi.blogspot.com/2007/11/quicktime-zeroday-vulnerability-still.html #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6240 (2007/CVE-2007-6240.md) ### [CVE-2007-6240](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6240) ### Description SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4687 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6242 (2007/CVE-2007-6242.md) ### [CVE-2007-6242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6242) ### Description Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors." ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9188 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6243 (2007/CVE-2007-6243.md) ### [CVE-2007-6243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6243) ### Description Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks. ### POC #### Reference - http://www.securityfocus.com/bid/26929 - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6244 (2007/CVE-2007-6244.md) ### [CVE-2007-6244](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6244) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer. ### POC #### Reference - http://www.securityfocus.com/bid/26929 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6245 (2007/CVE-2007-6245.md) ### [CVE-2007-6245](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6245) ### Description Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks. ### POC #### Reference - http://www.securityfocus.com/bid/26929 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9546 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6246 (2007/CVE-2007-6246.md) ### [CVE-2007-6246](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6246) ### Description Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges. ### POC #### Reference - http://www.securityfocus.com/bid/26929 #### Github - https://github.com/thomasbiege/Publications --- ### 2007/CVE 2007 6250 (2007/CVE-2007-6250.md) ### [CVE-2007-6250](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6250) ### Description Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6254 (2007/CVE-2007-6254.md) ### [CVE-2007-6254](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6254) ### Description Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before CHF74 allows remote attackers to execute arbitrary code via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6255 (2007/CVE-2007-6255.md) ### [CVE-2007-6255](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6255) ### Description Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6258 (2007/CVE-2007-6258.md) ### [CVE-2007-6258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6258) ### Description Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header. ### POC #### Reference - http://www.ioactive.com/vulnerabilities/mod_jk2LegacyBufferOverflowAdvisory.pdf - https://www.exploit-db.com/exploits/5330 - https://www.exploit-db.com/exploits/5386 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6261 (2007/CVE-2007-6261.md) ### [CVE-2007-6261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6261) ### Description Integer overflow in the load_threadstack function in the Mach-O loader (mach_loader.c) in the xnu kernel in Apple Mac OS X 10.4 through 10.5.1 allows local users to cause a denial of service (infinite loop) via a crafted Mach-O binary. ### POC #### Reference - http://www.digit-labs.org/files/exploits/xnu-macho-dos.c #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6262 (2007/CVE-2007-6262.md) ### [CVE-2007-6262](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6262) ### Description A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability." ### POC #### Reference - http://securityreason.com/securityalert/3420 - http://www.coresecurity.com/?action=item&id=2035 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6268 (2007/CVE-2007-6268.md) ### [CVE-2007-6268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6268) ### Description Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter. ### POC #### Reference - http://marc.info/?l=bugtraq&m=119678724111351&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6269 (2007/CVE-2007-6269.md) ### [CVE-2007-6269](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6269) ### Description Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters. ### POC #### Reference - http://marc.info/?l=bugtraq&m=119678724111351&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6270 (2007/CVE-2007-6270.md) ### [CVE-2007-6270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6270) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx. ### POC #### Reference - http://marc.info/?l=bugtraq&m=119678724111351&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6271 (2007/CVE-2007-6271.md) ### [CVE-2007-6271](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6271) ### Description Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message. ### POC #### Reference - http://securityreason.com/securityalert/3421 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6272 (2007/CVE-2007-6272.md) ### [CVE-2007-6272](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6272) ### Description Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search action to the com_search component. ### POC #### Reference - http://securityreason.com/securityalert/3422 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6273 (2007/CVE-2007-6273.md) ### [CVE-2007-6273](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6273) ### Description Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in the (1) Hostname tag or the (2) name attribute in the Connection tag. NOTE: there might not be any realistic circumstances in which this issue crosses privilege boundaries. ### POC #### Reference - http://marc.info/?l=bugtraq&m=119678272603064&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6276 (2007/CVE-2007-6276.md) ### [CVE-2007-6276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6276) ### Description The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112. ### POC #### Reference - https://www.exploit-db.com/exploits/4690 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6282 (2007/CVE-2007-6282.md) ### [CVE-2007-6282](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6282) ### Description The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV. ### POC #### Reference - http://www.ubuntu.com/usn/usn-625-1 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6283 (2007/CVE-2007-6283.md) ### [CVE-2007-6283](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6283) ### Description Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9977 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6286 (2007/CVE-2007-6286.md) ### [CVE-2007-6286](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6286) ### Description Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6289 (2007/CVE-2007-6289.md) ### [CVE-2007-6289](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6289) ### Description Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SERWEB[configdir] parameter to load_lang.php, (2) _SERWEB[functionsdir] parameter to main_prepend.php, and the (3) _PHPLIB[libdir] parameter to load_phplib.php, different vectors than CVE-2007-3359 and CVE-2007-3358. ### POC #### Reference - https://www.exploit-db.com/exploits/4696 - https://www.exploit-db.com/exploits/9284 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6290 (2007/CVE-2007-6290.md) ### [CVE-2007-6290](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6290) ### Description Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod and (2) js parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4696 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6292 (2007/CVE-2007-6292.md) ### [CVE-2007-6292](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6292) ### Description SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6296 (2007/CVE-2007-6296.md) ### [CVE-2007-6296](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6296) ### Description PHP remote file inclusion vulnerability in users_popupL.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the From parameter. ### POC #### Reference - http://securityreason.com/securityalert/3426 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6297 (2007/CVE-2007-6297.md) ### [CVE-2007-6297](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6297) ### Description Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML via the (1) LIMIT parameter to chat/deluser.php3, the (2) Link parameter to chat/edituser.php3, or the (3) LastCheck or (4) B parameter to chat/users_popupL.php3. NOTE: the FontName vectors for start_page.css.php3 and style.css.php3 are already covered by CVE-2005-1619. The medium vectors for start_page.css.php3 (start_page.css.php) and style.css.php3 (style.css.php), and the From vector for users_popupL.php3 (users_popupL.php), are already covered by CVE-2005-3991. ### POC #### Reference - http://securityreason.com/securityalert/3426 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6301 (2007/CVE-2007-6301.md) ### [CVE-2007-6301](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6301) ### Description Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter. ### POC #### Reference - http://securityreason.com/securityalert/3427 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6303 (2007/CVE-2007-6303.md) ### [CVE-2007-6303](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6303) ### Description MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement. ### POC #### Reference No PoCs from references. #### Github - https://github.com/CoolerVoid/Vision - https://github.com/CoolerVoid/Vision2 - https://github.com/hack-parthsharma/Vision - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 6304 (2007/CVE-2007-6304.md) ### [CVE-2007-6304](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6304) ### Description The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns. ### POC #### Reference No PoCs from references. #### Github - https://github.com/CoolerVoid/Vision - https://github.com/hack-parthsharma/Vision - https://github.com/tomwillfixit/alpine-cvecheck --- ### 2007/CVE 2007 6307 (2007/CVE-2007-6307.md) ### [CVE-2007-6307](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6307) ### Description Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header. ### POC #### Reference - http://securityreason.com/securityalert/3431 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6310 (2007/CVE-2007-6310.md) ### [CVE-2007-6310](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6310) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbitrary web script or HTML via the handler parameter to (1) index.php and possibly (2) admin/index.php, and (3) the topic parameter to modules/feed/feed.php (aka modules/feed.php). ### POC #### Reference - https://www.exploit-db.com/exploits/4711 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6311 (2007/CVE-2007-6311.md) ### [CVE-2007-6311](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6311) ### Description SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4711 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6318 (2007/CVE-2007-6318.md) ### [CVE-2007-6318](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6318) ### Description SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character. ### POC #### Reference - http://securityreason.com/securityalert/3433 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 6321 (2007/CVE-2007-6321.md) ### [CVE-2007-6321](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6321) ### Description Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands. ### POC #### Reference - http://securityreason.com/securityalert/3435 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6322 (2007/CVE-2007-6322.md) ### [CVE-2007-6322](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6322) ### Description Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4729 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6323 (2007/CVE-2007-6323.md) ### [CVE-2007-6323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6323) ### Description Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) get_image.php or (2) get_file.php in mms_template/. ### POC #### Reference - https://www.exploit-db.com/exploits/4728 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6324 (2007/CVE-2007-6324.md) ### [CVE-2007-6324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6324) ### Description PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4726 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6325 (2007/CVE-2007-6325.md) ### [CVE-2007-6325](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6325) ### Description PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fsBase] parameter, a different vector than CVE-2006-2726. ### POC #### Reference - https://www.exploit-db.com/exploits/4725 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6326 (2007/CVE-2007-6326.md) ### [CVE-2007-6326](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6326) ### Description Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI. ### POC #### Reference - https://www.exploit-db.com/exploits/4717 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6327 (2007/CVE-2007-6327.md) ### [CVE-2007-6327](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6327) ### Description Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method. ### POC #### Reference - https://www.exploit-db.com/exploits/4716 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6328 (2007/CVE-2007-6328.md) ### [CVE-2007-6328](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6328) ### Description DOSBox 0.72 and earlier allows local users to obtain access to the filesystem on the host operating system via the mount command. NOTE: the researcher reports a vendor response stating that this is not a security problem ### POC #### Reference - http://aluigi.org/poc/dosboxxx.zip - http://securityreason.com/securityalert/3442 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6329 (2007/CVE-2007-6329.md) ### [CVE-2007-6329](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6329) ### Description Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container. ### POC #### Reference - http://securityreason.com/securityalert/3443 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6331 (2007/CVE-2007-6331.md) ### [CVE-2007-6331](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6331) ### Description Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista. ### POC #### Reference - https://www.exploit-db.com/exploits/4720 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6332 (2007/CVE-2007-6332.md) ### [CVE-2007-6332](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6332) ### Description The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method. ### POC #### Reference - https://www.exploit-db.com/exploits/4720 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6333 (2007/CVE-2007-6333.md) ### [CVE-2007-6333](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6333) ### Description The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method. ### POC #### Reference - https://www.exploit-db.com/exploits/4720 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6335 (2007/CVE-2007-6335.md) ### [CVE-2007-6335](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6335) ### Description Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow. ### POC #### Reference - https://www.exploit-db.com/exploits/4862 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6338 (2007/CVE-2007-6338.md) ### [CVE-2007-6338](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6338) ### Description SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0712-exploits/trivantis-sql.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6340 (2007/CVE-2007-6340.md) ### [CVE-2007-6340](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6340) ### Description Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords. ### POC #### Reference - http://securityreason.com/securityalert/3611 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6344 (2007/CVE-2007-6344.md) ### [CVE-2007-6344](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6344) ### Description Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4719 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6347 (2007/CVE-2007-6347.md) ### [CVE-2007-6347](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6347) ### Description PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4722 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6348 (2007/CVE-2007-6348.md) ### [CVE-2007-6348](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6348) ### Description SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code. ### POC #### Reference - http://marc.info/?l=squirrelmail-devel&m=119765235203392&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6351 (2007/CVE-2007-6351.md) ### [CVE-2007-6351](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6351) ### Description libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9420 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6357 (2007/CVE-2007-6357.md) ### [CVE-2007-6357](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6357) ### Description Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944. ### POC #### Reference - http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9052538&source=rss_topic17 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6358 (2007/CVE-2007-6358.md) ### [CVE-2007-6358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6358) ### Description pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 6359 (2007/CVE-2007-6359.md) ### [CVE-2007-6359](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6359) ### Description The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL. ### POC #### Reference - http://digit-labs.org/files/exploits/xnu-superblob-dos.c - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6362 (2007/CVE-2007-6362.md) ### [CVE-2007-6362](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6362) ### Description SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action. ### POC #### Reference - https://www.exploit-db.com/exploits/4691 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6366 (2007/CVE-2007-6366.md) ### [CVE-2007-6366](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6366) ### Description Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators. ### POC #### Reference - https://www.exploit-db.com/exploits/4693 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6367 (2007/CVE-2007-6367.md) ### [CVE-2007-6367](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6367) ### Description Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comment (commento) field, different vectors than CVE-2007-2357. ### POC #### Reference - https://www.exploit-db.com/exploits/4693 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6368 (2007/CVE-2007-6368.md) ### [CVE-2007-6368](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6368) ### Description Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4694 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6369 (2007/CVE-2007-6369.md) ### [CVE-2007-6369](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6369) ### Description Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) size or (2) path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4695 #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 6377 (2007/CVE-2007-6377.md) ### [CVE-2007-6377](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6377) ### Description Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string. ### POC #### Reference - http://aluigi.altervista.org/adv/badblue-adv.txt - http://securityreason.com/securityalert/3448 - https://www.exploit-db.com/exploits/4784 #### Github - https://github.com/Nicoslo/Windows-exploitation-BadBlue-2.7-CVE-2007-6377 --- ### 2007/CVE 2007 6378 (2007/CVE-2007-6378.md) ### [CVE-2007-6378](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6378) ### Description Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter. ### POC #### Reference - http://aluigi.altervista.org/adv/badblue-adv.txt - http://securityreason.com/securityalert/3448 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6379 (2007/CVE-2007-6379.md) ### [CVE-2007-6379](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6379) ### Description BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message. ### POC #### Reference - http://aluigi.altervista.org/adv/badblue-adv.txt - http://securityreason.com/securityalert/3448 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6387 (2007/CVE-2007-6387.md) ### [CVE-2007-6387](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6387) ### Description Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4825 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6388 (2007/CVE-2007-6388.md) ### [CVE-2007-6388](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6388) ### Description Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3541 - http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html - http://www.vupen.com/english/advisories/2008/1697 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/Lateefaholagoke/Vulnerability-Scanning- - https://github.com/SecureAxom/strike - https://github.com/kasem545/vulnsearch - https://github.com/m4r4v/get-os-cve - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6391 (2007/CVE-2007-6391.md) ### [CVE-2007-6391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6391) ### Description SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4709 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6392 (2007/CVE-2007-6392.md) ### [CVE-2007-6392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6392) ### Description SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI. ### POC #### Reference - https://www.exploit-db.com/exploits/4708 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6393 (2007/CVE-2007-6393.md) ### [CVE-2007-6393](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6393) ### Description SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode. ### POC #### Reference - https://www.exploit-db.com/exploits/4707 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6394 (2007/CVE-2007-6394.md) ### [CVE-2007-6394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6394) ### Description SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action. ### POC #### Reference - https://www.exploit-db.com/exploits/4706 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6395 (2007/CVE-2007-6395.md) ### [CVE-2007-6395](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6395) ### Description Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/. ### POC #### Reference - https://www.exploit-db.com/exploits/4705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6396 (2007/CVE-2007-6396.md) ### [CVE-2007-6396](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6396) ### Description Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE: similar code injection might be possible in a user profile. ### POC #### Reference - https://www.exploit-db.com/exploits/4705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6397 (2007/CVE-2007-6397.md) ### [CVE-2007-6397](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6397) ### Description Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action or (b) the username parameter in a viewprofile action. ### POC #### Reference - https://www.exploit-db.com/exploits/4705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6398 (2007/CVE-2007-6398.md) ### [CVE-2007-6398](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6398) ### Description Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie. ### POC #### Reference - https://www.exploit-db.com/exploits/4705 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6399 (2007/CVE-2007-6399.md) ### [CVE-2007-6399](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6399) ### Description index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action. ### POC #### Reference - https://www.exploit-db.com/exploits/4705 #### Github - https://github.com/krlabs/apache-vulnerabilities --- ### 2007/CVE 2007 6400 (2007/CVE-2007-6400.md) ### [CVE-2007-6400](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6400) ### Description Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4704 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6401 (2007/CVE-2007-6401.md) ### [CVE-2007-6401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6401) ### Description Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402. ### POC #### Reference - http://securityreason.com/securityalert/3453 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6404 (2007/CVE-2007-6404.md) ### [CVE-2007-6404](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6404) ### Description Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. ### POC #### Reference - https://www.exploit-db.com/exploits/4700 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6405 (2007/CVE-2007-6405.md) ### [CVE-2007-6405](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6405) ### Description Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407. ### POC #### Reference - https://www.exploit-db.com/exploits/4700 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6411 (2007/CVE-2007-6411.md) ### [CVE-2007-6411](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6411) ### Description Multiple buffer overflows in the HandleEmotsConfig function in the GG Client in Gadu-Gadu 7.7 Build 3669 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (gg.exe process crash) via a long string in an emots.txt file. ### POC #### Reference - http://securityreason.com/securityalert/3455 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6414 (2007/CVE-2007-6414.md) ### [CVE-2007-6414](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6414) ### Description admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. NOTE: this can be leveraged for arbitrary code execution through a request to admin/videolinks_view.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4731 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6416 (2007/CVE-2007-6416.md) ### [CVE-2007-6416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6416) ### Description The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9840 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6420 (2007/CVE-2007-6420.md) ### [CVE-2007-6420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6420) ### Description Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/fkie-cad/nvd-json-data-feeds - https://github.com/krlabs/apache-vulnerabilities - https://github.com/lekctut/sdb-hw-13-01 - https://github.com/pedr0alencar/vlab-metasploitable2 - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6421 (2007/CVE-2007-6421.md) ### [CVE-2007-6421](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6421) ### Description Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/HackDreamer/Network-Vulnerability-Scanner - https://github.com/Prakanth20/Network-Scanner-with-Banner-Grabbing-and-CVE-Detection - https://github.com/SecureAxom/strike - https://github.com/krlabs/apache-vulnerabilities - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6422 (2007/CVE-2007-6422.md) ### [CVE-2007-6422](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6422) ### Description The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/krlabs/apache-vulnerabilities - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6423 (2007/CVE-2007-6423.md) ### [CVE-2007-6423](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6423) ### Description Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/ARPSyndicate/cvemon - https://github.com/SecureAxom/strike - https://github.com/xxehacker/strike --- ### 2007/CVE 2007 6424 (2007/CVE-2007-6424.md) ### [CVE-2007-6424](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6424) ### Description registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack. ### POC #### Reference - http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002528.html - http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002533.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6427 (2007/CVE-2007-6427.md) ### [CVE-2007-6427](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6427) ### Description The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6435 (2007/CVE-2007-6435.md) ### [CVE-2007-6435](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6435) ### Description Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail. ### POC #### Reference - http://securityreason.com/securityalert/3459 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6436 (2007/CVE-2007-6436.md) ### [CVE-2007-6436](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6436) ### Description Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted document, as actively exploited in December 2007 by the Tarodrop.F trojan. NOTE: some of these details are obtained from third party information. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6438 (2007/CVE-2007-6438.md) ### [CVE-2007-6438](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6438) ### Description Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors. NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6439 (2007/CVE-2007-6439.md) ### [CVE-2007-6439](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6439) ### Description Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissector, which can trigger resource consumption or a crash. NOTE: this identifier originally included Firebird/Interbase, but it is already covered by CVE-2007-6116. The DCP ETSI issue is already covered by CVE-2007-6119. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6441 (2007/CVE-2007-6441.md) ### [CVE-2007-6441](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6441) ### Description The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms." ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6450 (2007/CVE-2007-6450.md) ### [CVE-2007-6450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6450) ### Description The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6451 (2007/CVE-2007-6451.md) ### [CVE-2007-6451](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6451) ### Description Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=199958 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9685 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6453 (2007/CVE-2007-6453.md) ### [CVE-2007-6453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6453) ### Description Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter. ### POC #### Reference - http://securityreason.com/securityalert/3460 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6454 (2007/CVE-2007-6454.md) ### [CVE-2007-6454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6454) ### Description Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request. ### POC #### Reference - http://aluigi.altervista.org/adv/peercasthof-adv.txt - http://securityreason.com/securityalert/3461 #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 6455 (2007/CVE-2007-6455.md) ### [CVE-2007-6455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6455) ### Description Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter. ### POC #### Reference - http://securityreason.com/securityalert/3462 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6458 (2007/CVE-2007-6458.md) ### [CVE-2007-6458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6458) ### Description SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4733 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6459 (2007/CVE-2007-6459.md) ### [CVE-2007-6459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6459) ### Description Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460. ### POC #### Reference - https://www.exploit-db.com/exploits/4734 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6460 (2007/CVE-2007-6460.md) ### [CVE-2007-6460](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6460) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CVE-2007-6459. ### POC #### Reference - http://anonproxyserver.svn.sourceforge.net/viewvc/anonproxyserver/trunk/anon_proxy_server/ - http://anonproxyserver.svn.sourceforge.net/viewvc/anonproxyserver/trunk/anon_proxy_server/log.php?r1=284&r2=325 - http://anonproxyserver.svn.sourceforge.net/viewvc/anonproxyserver/trunk/anon_proxy_server/logerror.php?r1=245&r2=325 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6462 (2007/CVE-2007-6462.md) ### [CVE-2007-6462](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6462) ### Description SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4737 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6464 (2007/CVE-2007-6464.md) ### [CVE-2007-6464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6464) ### Description Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP code via a URL in the g_root_dir parameter to (1) admin_page_open.php and (2) client_page_open.php in global/templates/. ### POC #### Reference - https://www.exploit-db.com/exploits/4736 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6466 (2007/CVE-2007-6466.md) ### [CVE-2007-6466](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6466) ### Description Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action. NOTE: it was later reported that MOG - Web Shop (MOG-WebShop), a product based on the same code, is also affected. ### POC #### Reference - https://www.exploit-db.com/exploits/4739 - https://www.exploit-db.com/exploits/4740 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6468 (2007/CVE-2007-6468.md) ### [CVE-2007-6468](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6468) ### Description Buffer overflow in the HuffDecode function in hw_utils/hwrcon/huffman.c and hexenworld/Client/huffman.c in Hammer of Thyrion 1.4.2 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted huffman encoded packet. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=562016&group_id=124987 - http://uhexen2.cvs.sourceforge.net/uhexen2/hexenworld/Client/huffman.c?r1=1.24&r2=1.25 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6472 (2007/CVE-2007-6472.md) ### [CVE-2007-6472](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6472) ### Description Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information. ### POC #### Reference - https://www.exploit-db.com/exploits/4750 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6473 (2007/CVE-2007-6473.md) ### [CVE-2007-6473](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6473) ### Description Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command. ### POC #### Reference - https://www.exploit-db.com/exploits/4742 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6474 (2007/CVE-2007-6474.md) ### [CVE-2007-6474](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6474) ### Description Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6475 (2007/CVE-2007-6475.md) ### [CVE-2007-6475](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6475) ### Description Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_sel parameter to (1) updater.php and (2) thumber.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6476 (2007/CVE-2007-6476.md) ### [CVE-2007-6476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6476) ### Description GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function. ### POC #### Reference - https://www.exploit-db.com/exploits/4738 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6478 (2007/CVE-2007-6478.md) ### [CVE-2007-6478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6478) ### Description Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://securityreason.com/securityalert/3470 - https://www.exploit-db.com/exploits/5122 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6479 (2007/CVE-2007-6479.md) ### [CVE-2007-6479](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6479) ### Description Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/. ### POC #### Reference - https://www.exploit-db.com/exploits/4753 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6483 (2007/CVE-2007-6483.md) ### [CVE-2007-6483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6483) ### Description Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string. ### POC #### Reference No PoCs from references. #### Github - https://github.com/syph0n/Exploits --- ### 2007/CVE 2007 6485 (2007/CVE-2007-6485.md) ### [CVE-2007-6485](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6485) ### Description Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/. ### POC #### Reference - https://www.exploit-db.com/exploits/4735 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6488 (2007/CVE-2007-6488.md) ### [CVE-2007-6488](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6488) ### Description Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4712 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6489 (2007/CVE-2007-6489.md) ### [CVE-2007-6489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6489) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4712 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6490 (2007/CVE-2007-6490.md) ### [CVE-2007-6490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6490) ### Description Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4712 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6491 (2007/CVE-2007-6491.md) ### [CVE-2007-6491](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6491) ### Description Multiple SQL injection vulnerabilities in Kvaliitti WebDoc 3.0 CMS allow remote attackers to execute arbitrary SQL commands via (1) the cat_id parameter to categories.asp; and probably (2) the document_id parameter to categories.asp, and the (3) cat_id and (4) document_id parameters to subcategory.asp. ### POC #### Reference - http://securityreason.com/securityalert/3473 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6494 (2007/CVE-2007-6494.md) ### [CVE-2007-6494](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6494) ### Description Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6495 (2007/CVE-2007-6495.md) ### [CVE-2007-6495](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6495) ### Description inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action to accounts/AccountActions.asp. NOTE: this can be leveraged for remote code execution by changing the permissions of \Forum\db, which is configured for execution of ASP scripts with administrative privileges, and then uploading a script to \Forum\db. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6496 (2007/CVE-2007-6496.md) ### [CVE-2007-6496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6496) ### Description Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6497 (2007/CVE-2007-6497.md) ### [CVE-2007-6497](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6497) ### Description Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6498 (2007/CVE-2007-6498.md) ### [CVE-2007-6498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6498) ### Description Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter to OpenApi/GatewayVariables.asp, and possibly (5) unspecified vectors to IIS/iibind.asp. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6499 (2007/CVE-2007-6499.md) ### [CVE-2007-6499](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6499) ### Description Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "host id (IIS) value." ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6500 (2007/CVE-2007-6500.md) ### [CVE-2007-6500](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6500) ### Description Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6501 (2007/CVE-2007-6501.md) ### [CVE-2007-6501](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6501) ### Description Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6502 (2007/CVE-2007-6502.md) ### [CVE-2007-6502](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6502) ### Description Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects, which trigger a response with the setup directory pathname in the HTML source; and (3) might allow remote attackers to obtain sensitive information via a request for /admin/forum/, which reveals the path in an error message when a forum is not found. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6503 (2007/CVE-2007-6503.md) ### [CVE-2007-6503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6503) ### Description Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to hosting/AutoSignUpPlans.asp with the (a) save, (b) 30, and (c) d_30 parameters. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6504 (2007/CVE-2007-6504.md) ### [CVE-2007-6504](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6504) ### Description Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4730 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6506 (2007/CVE-2007-6506.md) ### [CVE-2007-6506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6506) ### Description The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method. ### POC #### Reference - http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818 - https://www.exploit-db.com/exploits/4757 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6508 (2007/CVE-2007-6508.md) ### [CVE-2007-6508](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6508) ### Description Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4758 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6509 (2007/CVE-2007-6509.md) ### [CVE-2007-6509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6509) ### Description Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119794961212714&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6510 (2007/CVE-2007-6510.md) ### [CVE-2007-6510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6510) ### Description Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown impact via a crafted file to the SkytPacker ripper. ### POC #### Reference - http://aluigi.altervista.org/adv/prowizbof-adv.txt - http://aluigi.org/poc/prowizbof.zip #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6511 (2007/CVE-2007-6511.md) ### [CVE-2007-6511](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6511) ### Description Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, or (3) StoneHttpAgent User-Agent header, which results in a Non-HTTP categorization. ### POC #### Reference - http://mrhinkydink.blogspot.com/2007/12/websense-policy-filtering-bypass.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6513 (2007/CVE-2007-6513.md) ### [CVE-2007-6513](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6513) ### Description HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method. ### POC #### Reference - http://www.heise-security.co.uk/news/100934 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6515 (2007/CVE-2007-6515.md) ### [CVE-2007-6515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6515) ### Description support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. ### POC #### Reference - http://securityreason.com/securityalert/3480 - http://www.exploit-db.com/exploits/15987 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6523 (2007/CVE-2007-6523.md) ### [CVE-2007-6523](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6523) ### Description Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) via a crafted bitmap (BMP) file that triggers a large number of calculations and checks. ### POC #### Reference - http://securityreason.com/securityalert/3482 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6524 (2007/CVE-2007-6524.md) ### [CVE-2007-6524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6524) ### Description Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420. ### POC #### Reference - https://bugzilla.mozilla.org/show_bug.cgi?id=408076 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6528 (2007/CVE-2007-6528.md) ### [CVE-2007-6528](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6528) ### Description Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter. ### POC #### Reference - http://securityreason.com/securityalert/3484 - https://www.exploit-db.com/exploits/4942 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6530 (2007/CVE-2007-6530.md) ### [CVE-2007-6530](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6530) ### Description Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function. ### POC #### Reference - http://marc.info/?l=full-disclosure&m=119863639428564&w=2 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6533 (2007/CVE-2007-6533.md) ### [CVE-2007-6533](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6533) ### Description Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message. ### POC #### Reference - http://aluigi.altervista.org/adv/zoomprayer-adv.txt - http://securityreason.com/securityalert/3486 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6534 (2007/CVE-2007-6534.md) ### [CVE-2007-6534](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6534) ### Description Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart. ### POC #### Reference - http://securityreason.com/securityalert/3490 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6537 (2007/CVE-2007-6537.md) ### [CVE-2007-6537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6537) ### Description Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbitrary code via a long filename in a gzipped archive, such as a (1) gz, (2) adz, (3) roz, or (4) hdz archive in a compressed floppy disk image. ### POC #### Reference - http://aluigi.altervista.org/adv/winuaebof-adv.txt - http://aluigi.org/poc/winuaebof.zip - http://securityreason.com/securityalert/3487 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6538 (2007/CVE-2007-6538.md) ### [CVE-2007-6538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6538) ### Description SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://securityreason.com/securityalert/3492 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6542 (2007/CVE-2007-6542.md) ### [CVE-2007-6542](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6542) ### Description PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4764 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6543 (2007/CVE-2007-6543.md) ### [CVE-2007-6543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6543) ### Description SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4791 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6544 (2007/CVE-2007-6544.md) ### [CVE-2007-6544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6544) ### Description Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/. ### POC #### Reference - https://www.exploit-db.com/exploits/4787 - https://www.exploit-db.com/exploits/4790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6545 (2007/CVE-2007-6545.md) ### [CVE-2007-6545](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6545) ### Description Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly related to the XoopsPageNav class; or (3) an avatar image to edituser.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6546 (2007/CVE-2007-6546.md) ### [CVE-2007-6546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6546) ### Description RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. ### POC #### Reference - https://www.exploit-db.com/exploits/4790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6547 (2007/CVE-2007-6547.md) ### [CVE-2007-6547](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6547) ### Description RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session. ### POC #### Reference - https://www.exploit-db.com/exploits/4790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6548 (2007/CVE-2007-6548.md) ### [CVE-2007-6548](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6548) ### Description Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) footer parameters to modules/system/admin.php in a meta-generator action, (3) the disclaimer parameter to modules/system/admin.php in a disclaimer action, (4) the disclaimer parameter to modules/mydownloads/admin/index.php in a mydownloadsConfigAdmin action, (5) the disclaimer parameter to modules/newbb_plus/admin/forum_config.php, (6) the disclaimer parameter to modules/mylinks/admin/index.php in a myLinksConfigAdmin action, or (7) the intro parameter to modules/sections/admin/index.php in a secconfig action, which inject PHP sequences into (a) sections/cache/intro.php, (b) mylinks/cache/disclaimer.php, (c) mydownloads/cache/disclaimer.php, (d) newbb_plus/cache/disclaimer.php, (e) system/cache/disclaimer.php, (f) system/cache/footer.php, (g) system/cache/header.php, or (h) system/cache/maintenance.php in modules/. ### POC #### Reference - https://www.exploit-db.com/exploits/4790 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6550 (2007/CVE-2007-6550.md) ### [CVE-2007-6550](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6550) ### Description form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4789 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6551 (2007/CVE-2007-6551.md) ### [CVE-2007-6551](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6551) ### Description SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4788 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6552 (2007/CVE-2007-6552.md) ### [CVE-2007-6552](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6552) ### Description Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request. ### POC #### Reference - https://www.exploit-db.com/exploits/4786 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6553 (2007/CVE-2007-6553.md) ### [CVE-2007-6553](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6553) ### Description Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) tcuser.class.php, (2) absencecount.inc.php, (3) avatar.inc.php, (4) csvhandler.class.php, (5) functions.tcpro.php, (6) header.html.inc.php, (7) joomlajack.tcpro.php, (8) menu.inc.php, (9) other.inc.php, (10) tcabsence.class.php, (11) tcabsencegroup.class.php, (12) tcallowance.class.php, (13) tcannouncement.class.php, (14) tcconfig.class.php, (15) tcdaynote.class.php, (16) tcgroup.class.php, (17) tcholiday.class.php, (18) tclogin.class.php, (19) tcmonth.class.php, (20) tctemplate.class.php, (21) tcusergroup.class.php, or (22) tcuseroption.class.php in includes/, possibly a related issue to CVE-2006-4845. ### POC #### Reference - https://www.exploit-db.com/exploits/4785 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6554 (2007/CVE-2007-6554.md) ### [CVE-2007-6554](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6554) ### Description Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) register.php, (3) login.php, or (4) statistics.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4785 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6555 (2007/CVE-2007-6555.md) ### [CVE-2007-6555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6555) ### Description PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4783 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6556 (2007/CVE-2007-6556.md) ### [CVE-2007-6556](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6556) ### Description Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to default.asp in a news page action or (2) the pageid parameter to default.asp. ### POC #### Reference - https://www.exploit-db.com/exploits/4777 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6557 (2007/CVE-2007-6557.md) ### [CVE-2007-6557](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6557) ### Description Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors. ### POC #### Reference - https://www.exploit-db.com/exploits/4778 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6558 (2007/CVE-2007-6558.md) ### [CVE-2007-6558](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6558) ### Description TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288. ### POC #### Reference - http://securityreason.com/securityalert/3500 - http://www.securityfocus.com/archive/1/485564/100/100/threaded #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6561 (2007/CVE-2007-6561.md) ### [CVE-2007-6561](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6561) ### Description Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF_load_image function that results in an overflow in the pdc_fsearch_fopen function, and possibly other vectors. ### POC #### Reference - http://securityreason.com/securityalert/3495 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6565 (2007/CVE-2007-6565.md) ### [CVE-2007-6565](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6565) ### Description Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component. ### POC #### Reference - https://www.exploit-db.com/exploits/4793 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6566 (2007/CVE-2007-6566.md) ### [CVE-2007-6566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6566) ### Description SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6567 (2007/CVE-2007-6567.md) ### [CVE-2007-6567](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6567) ### Description Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action. ### POC #### Reference - https://www.exploit-db.com/exploits/4794 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6568 (2007/CVE-2007-6568.md) ### [CVE-2007-6568](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6568) ### Description PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4795 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6573 (2007/CVE-2007-6573.md) ### [CVE-2007-6573](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6573) ### Description QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551. ### POC #### Reference - http://securityreason.com/securityalert/3494 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6575 (2007/CVE-2007-6575.md) ### [CVE-2007-6575](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6575) ### Description SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action. ### POC #### Reference - https://www.exploit-db.com/exploits/4776 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6576 (2007/CVE-2007-6576.md) ### [CVE-2007-6576](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6576) ### Description Multiple SQL injection vulnerabilities in Adult Script 1.6.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) videolink_count.php or (2) links.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4775 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6577 (2007/CVE-2007-6577.md) ### [CVE-2007-6577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6577) ### Description Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action. ### POC #### Reference - https://www.exploit-db.com/exploits/4772 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6578 (2007/CVE-2007-6578.md) ### [CVE-2007-6578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6578) ### Description SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4774 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6579 (2007/CVE-2007-6579.md) ### [CVE-2007-6579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6579) ### Description Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vlan_id parameter to (1) vlanview.php, (2) vlanedit.php, and (3) vlandel.php; the (4) assetclassgroup_id parameter to assetclassgroupview.php; the (5) subnet_id parameter to nodelist.php; and unspecified other vectors. NOTE: it was later reported that the vlanview.php and vlandel.php vectors are also in 0.4. ### POC #### Reference - https://www.exploit-db.com/exploits/4771 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6580 (2007/CVE-2007-6580.md) ### [CVE-2007-6580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6580) ### Description Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4770 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6581 (2007/CVE-2007-6581.md) ### [CVE-2007-6581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6581) ### Description Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/. ### POC #### Reference - https://www.exploit-db.com/exploits/4767 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6582 (2007/CVE-2007-6582.md) ### [CVE-2007-6582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6582) ### Description Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action. ### POC #### Reference - https://www.exploit-db.com/exploits/4766 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6583 (2007/CVE-2007-6583.md) ### [CVE-2007-6583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6583) ### Description SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4765 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6584 (2007/CVE-2007-6584.md) ### [CVE-2007-6584](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6584) ### Description Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1. ### POC #### Reference - https://www.exploit-db.com/exploits/4765 - https://www.exploit-db.com/exploits/5434 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6585 (2007/CVE-2007-6585.md) ### [CVE-2007-6585](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6585) ### Description PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4763 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6586 (2007/CVE-2007-6586.md) ### [CVE-2007-6586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6586) ### Description SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4762 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6587 (2007/CVE-2007-6587.md) ### [CVE-2007-6587](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6587) ### Description SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. ### POC #### Reference - http://packetstormsecurity.com/files/112947/Plogger-Photo-Gallery-SQL-Injection.html - http://packetstormsecurity.org/files/112947/Plogger-Photo-Gallery-SQL-Injection.html - https://labs.mwrinfosecurity.com/advisories/2007/12/17/plogger-sql-injection/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6589 (2007/CVE-2007-6589.md) ### [CVE-2007-6589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6589) ### Description The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947. ### POC #### Reference - http://blog.beford.org/?p=8 - http://www.mozilla.org/security/announce/2007/mfsa2007-37.html - http://www.vupen.com/english/advisories/2008/0083 - https://bugzilla.mozilla.org/show_bug.cgi?id=403331 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6593 (2007/CVE-2007-6593.md) ### [CVE-2007-6593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6593) ### Description Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909. ### POC #### Reference - http://securityreason.com/securityalert/3499 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6601 (2007/CVE-2007-6601.md) ### [CVE-2007-6601](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6601) ### Description The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Live-Hack-CVE/CVE-2007-6601 - https://github.com/brunoh6/postgresql-cve-exploitation --- ### 2007/CVE 2007 6602 (2007/CVE-2007-6602.md) ### [CVE-2007-6602](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6602) ### Description SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script. ### POC #### Reference - https://www.exploit-db.com/exploits/4805 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6603 (2007/CVE-2007-6603.md) ### [CVE-2007-6603](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6603) ### Description Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4804 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6604 (2007/CVE-2007-6604.md) ### [CVE-2007-6604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6604) ### Description Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or by executing embedded PHP code in images under uploads/avatar/. ### POC #### Reference - https://www.exploit-db.com/exploits/4802 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6605 (2007/CVE-2007-6605.md) ### [CVE-2007-6605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6605) ### Description Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four arguments to the Start method. ### POC #### Reference - https://www.exploit-db.com/exploits/4801 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6606 (2007/CVE-2007-6606.md) ### [CVE-2007-6606](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6606) ### Description OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. ### POC #### Reference - http://securityreason.com/securityalert/3502 - http://sourceforge.net/project/shownotes.php?release_id=451780&group_id=50071 - http://sourceforge.net/project/shownotes.php?release_id=488061&group_id=50071 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6607 (2007/CVE-2007-6607.md) ### [CVE-2007-6607](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6607) ### Description OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various error messages. ### POC #### Reference - http://securityreason.com/securityalert/3502 - http://sourceforge.net/project/shownotes.php?release_id=451780&group_id=50071 - http://sourceforge.net/project/shownotes.php?release_id=488061&group_id=50071 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6608 (2007/CVE-2007-6608.md) ### [CVE-2007-6608](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6608) ### Description Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIRST parameters to admin/staff_del_confirm.php, (3) the name parameter to admin/theme_del_confirm.php, or (4) the themeName parameter to admin/theme_preview.php. ### POC #### Reference - http://securityreason.com/securityalert/3502 - http://sourceforge.net/project/shownotes.php?release_id=451780&group_id=50071 - http://sourceforge.net/project/shownotes.php?release_id=488061&group_id=50071 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6612 (2007/CVE-2007-6612.md) ### [CVE-2007-6612](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6612) ### Description Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP request containing double-encoded sequences (".%252e"). ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1697 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6614 (2007/CVE-2007-6614.md) ### [CVE-2007-6614](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6614) ### Description PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter, a related issue to CVE-2007-6542. ### POC #### Reference - https://www.exploit-db.com/exploits/4782 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6615 (2007/CVE-2007-6615.md) ### [CVE-2007-6615](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6615) ### Description Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the selected_provider parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4782 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6620 (2007/CVE-2007-6620.md) ### [CVE-2007-6620](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6620) ### Description Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4799 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6621 (2007/CVE-2007-6621.md) ### [CVE-2007-6621](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6621) ### Description Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the picture parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4799 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6622 (2007/CVE-2007-6622.md) ### [CVE-2007-6622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6622) ### Description SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. ### POC #### Reference - https://www.exploit-db.com/exploits/4798 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6623 (2007/CVE-2007-6623.md) ### [CVE-2007-6623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6623) ### Description Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary directories via a full pathname in the dir parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4798 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6624 (2007/CVE-2007-6624.md) ### [CVE-2007-6624](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6624) ### Description Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4796 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6626 (2007/CVE-2007-6626.md) ### [CVE-2007-6626](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6626) ### Description Multiple buffer overflows in the RTSP_valid_response_msg function in RTSP_state_machine.c in LScube Feng 0.1.15 and earlier allow remote attackers to execute arbitrary code via (1) a long first line of a response, as demonstrated by a long VER line; or (2) a long second line of a response, as demonstrated by a message that follows a RETURN line. ### POC #### Reference - http://aluigi.altervista.org/adv/fengulo-adv.txt - http://aluigi.org/poc/fengulo.zip - http://securityreason.com/securityalert/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6627 (2007/CVE-2007-6627.md) ### [CVE-2007-6627](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6627) ### Description Integer overflow in the RTSP_remove_msg function in RTSP_lowlevel.c in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an RTP packet with a size value of 0xffff. ### POC #### Reference - http://aluigi.altervista.org/adv/fengulo-adv.txt - http://aluigi.org/poc/fengulo.zip - http://securityreason.com/securityalert/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6628 (2007/CVE-2007-6628.md) ### [CVE-2007-6628](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6628) ### Description LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header. ### POC #### Reference - http://aluigi.altervista.org/adv/fengulo-adv.txt - http://aluigi.org/poc/fengulo.zip - http://securityreason.com/securityalert/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6629 (2007/CVE-2007-6629.md) ### [CVE-2007-6629](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6629) ### Description Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a User-Agent header line that contains a carriage-return character, which is considered a line delimiter when the header is split into individual lines, but not when log_user_agent in RTSP_utils.c parses the content of the User-Agent line. ### POC #### Reference - http://aluigi.altervista.org/adv/fengulo-adv.txt - http://aluigi.org/poc/fengulo.zip - http://securityreason.com/securityalert/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6630 (2007/CVE-2007-6630.md) ### [CVE-2007-6630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6630) ### Description The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a malformed URI containing a "/:" sequence, as demonstrated by a "DESCRIBE /: RTSP/1.0" request. ### POC #### Reference - http://aluigi.altervista.org/adv/fengulo-adv.txt - http://aluigi.org/poc/fengulo.zip - http://securityreason.com/securityalert/3507 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6631 (2007/CVE-2007-6631.md) ### [CVE-2007-6631](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6631) ### Description Multiple buffer overflows in LScube libnemesi 0.6.4-rc1 and earlier allow remote attackers to execute arbitrary code via (1) a reply that begins with a long version string, which triggers an overflow in handle_rtsp_pkt in rtsp_handlers.c; long headers that trigger overflows in (2) send_pause_request, (3) send_play_request, (4) send_setup_request, or (5) send_teardown_request in rtsp_send.c, as demonstrated by the Content-Base header; or a long Transport header, which triggers an overflow in (6) get_transport_str_sctp, (7) get_transport_str_tcp, or (8) get_transport_str_udp in rtsp_transport.c. ### POC #### Reference - http://aluigi.altervista.org/adv/libnemesibof-adv.txt - http://aluigi.org/poc/libnemesibof.zip - http://securityreason.com/securityalert/3513 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6632 (2007/CVE-2007-6632.md) ### [CVE-2007-6632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6632) ### Description showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4800 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6637 (2007/CVE-2007-6637.md) ### [CVE-2007-6637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6637) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1. ### POC #### Reference - http://www.vupen.com/english/advisories/2008/1697 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9828 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6638 (2007/CVE-2007-6638.md) ### [CVE-2007-6638](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6638) ### Description March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz. ### POC #### Reference - https://www.exploit-db.com/exploits/4797 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo --- ### 2007/CVE 2007 6639 (2007/CVE-2007-6639.md) ### [CVE-2007-6639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6639) ### Description SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewdir action. ### POC #### Reference - https://www.exploit-db.com/exploits/4821 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6642 (2007/CVE-2007-6642.md) ### [CVE-2007-6642](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6642) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an extension containing arbitrary PHP code, and (3) modify the configuration as administrators via unspecified vectors. ### POC #### Reference - http://securityreason.com/securityalert/3505 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6647 (2007/CVE-2007-6647.md) ### [CVE-2007-6647](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6647) ### Description SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4817 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6648 (2007/CVE-2007-6648.md) ### [CVE-2007-6648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6648) ### Description Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4816 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6649 (2007/CVE-2007-6649.md) ### [CVE-2007-6649](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6649) ### Description PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4815 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6650 (2007/CVE-2007-6650.md) ### [CVE-2007-6650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6650) ### Description Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file. ### POC #### Reference - http://www.bugreport.ir/?/24 - https://www.exploit-db.com/exploits/4814 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6651 (2007/CVE-2007-6651.md) ### [CVE-2007-6651](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6651) ### Description Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter. ### POC #### Reference - http://www.bugreport.ir/?/24 - https://www.exploit-db.com/exploits/4814 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6652 (2007/CVE-2007-6652.md) ### [CVE-2007-6652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6652) ### Description cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer). ### POC #### Reference - https://www.exploit-db.com/exploits/4813 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6653 (2007/CVE-2007-6653.md) ### [CVE-2007-6653](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6653) ### Description Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4812 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6654 (2007/CVE-2007-6654.md) ### [CVE-2007-6654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6654) ### Description Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660. ### POC #### Reference - https://www.exploit-db.com/exploits/4819 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6655 (2007/CVE-2007-6655.md) ### [CVE-2007-6655](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6655) ### Description PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4811 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6656 (2007/CVE-2007-6656.md) ### [CVE-2007-6656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6656) ### Description SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4810 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6657 (2007/CVE-2007-6657.md) ### [CVE-2007-6657](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6657) ### Description PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mfh_root_path parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4808 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6658 (2007/CVE-2007-6658.md) ### [CVE-2007-6658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6658) ### Description SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page. ### POC #### Reference - https://www.exploit-db.com/exploits/4809 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6663 (2007/CVE-2007-6663.md) ### [CVE-2007-6663](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6663) ### Description SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to index.php. ### POC #### Reference - https://www.exploit-db.com/exploits/4827 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6664 (2007/CVE-2007-6664.md) ### [CVE-2007-6664](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6664) ### Description SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4826 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6665 (2007/CVE-2007-6665.md) ### [CVE-2007-6665](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6665) ### Description SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4824 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6666 (2007/CVE-2007-6666.md) ### [CVE-2007-6666](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6666) ### Description SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4823 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6667 (2007/CVE-2007-6667.md) ### [CVE-2007-6667](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6667) ### Description SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413. ### POC #### Reference - https://www.exploit-db.com/exploits/4822 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6668 (2007/CVE-2007-6668.md) ### [CVE-2007-6668](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6668) ### Description admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file. ### POC #### Reference - https://www.exploit-db.com/exploits/4741 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6672 (2007/CVE-2007-6672.md) ### [CVE-2007-6672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6672) ### Description Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI. ### POC #### Reference - http://www.igniterealtime.org/community/message/163752 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6673 (2007/CVE-2007-6673.md) ### [CVE-2007-6673](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6673) ### Description Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action. ### POC #### Reference - http://www.packetstormsecurity.org/0712-exploits/makale-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6674 (2007/CVE-2007-6674.md) ### [CVE-2007-6674](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6674) ### Description Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter. ### POC #### Reference - http://www.packetstormsecurity.org/0801-exploits/rapidshare-xss.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6675 (2007/CVE-2007-6675.md) ### [CVE-2007-6675](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6675) ### Description The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows remote attackers to read the comments in restricted modules. ### POC #### Reference - http://sourceforge.net/tracker/index.php?func=detail&aid=1808484&group_id=41586&atid=430840 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6676 (2007/CVE-2007-6676.md) ### [CVE-2007-6676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6676) ### Description The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to uber_uploader_file.js, a different issue than CVE-2007-0123. NOTE: the vendor disputes the severity of the issue, noting that it is the administrator's responsibility to "add file extensions that you may or may not want uploaded." ### POC #### Reference - http://securityreason.com/securityalert/3519 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6677 (2007/CVE-2007-6677.md) ### [CVE-2007-6677](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6677) ### Description Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form. ### POC #### Reference No PoCs from references. #### Github - https://github.com/20142995/nuclei-templates --- ### 2007/CVE 2007 6681 (2007/CVE-2007-6681.md) ### [CVE-2007-6681](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6681) ### Description Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file. ### POC #### Reference - http://aluigi.altervista.org/adv/vlcboffs-adv.txt - http://securityreason.com/securityalert/3550 - https://www.exploit-db.com/exploits/5667 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6682 (2007/CVE-2007-6682.md) ### [CVE-2007-6682](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6682) ### Description Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter. ### POC #### Reference - http://aluigi.altervista.org/adv/vlcboffs-adv.txt - http://securityreason.com/securityalert/3550 - https://www.exploit-db.com/exploits/5519 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6685 (2007/CVE-2007-6685.md) ### [CVE-2007-6685](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6685) ### Description Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6686 (2007/CVE-2007-6686.md) ### [CVE-2007-6686](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6686) ### Description The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6687 (2007/CVE-2007-6687.md) ### [CVE-2007-6687](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6687) ### Description Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP PROPPATCH in the WebDAV module. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6688 (2007/CVE-2007-6688.md) ### [CVE-2007-6688](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6688) ### Description Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the storage folder." ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6689 (2007/CVE-2007-6689.md) ### [CVE-2007-6689](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6689) ### Description Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6690 (2007/CVE-2007-6690.md) ### [CVE-2007-6690](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6690) ### Description The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6691 (2007/CVE-2007-6691.md) ### [CVE-2007-6691](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6691) ### Description Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the WebDAV module, (3) a comment view in the Comment module, (4) unspecified "item information disclosure attacks" in the Core module Gallery application, (5) the slideshow in the Slideshow module, and (6) multiple Print modules. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6692 (2007/CVE-2007-6692.md) ### [CVE-2007-6692](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6692) ### Description Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules. ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6693 (2007/CVE-2007-6693.md) ### [CVE-2007-6693](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6693) ### Description Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request." ### POC #### Reference - http://bugs.gentoo.org/show_bug.cgi?id=203217 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6697 (2007/CVE-2007-6697.md) ### [CVE-2007-6697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6697) ### Description Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484. NOTE: some of these details are obtained from third party information. ### POC #### Reference - http://marc.info/?l=bugtraq&m=120110205511630&w=2 - http://vexillium.org/?sec-sdlgif #### Github - https://github.com/ARPSyndicate/cve-scores - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 6699 (2007/CVE-2007-6699.md) ### [CVE-2007-6699](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6699) ### Description Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values. ### POC #### Reference - http://seclists.org/fulldisclosure/2007/Dec/0561.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6702 (2007/CVE-2007-6702.md) ### [CVE-2007-6702](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6702) ### Description goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603. ### POC #### Reference - https://www.exploit-db.com/exploits/4744 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6707 (2007/CVE-2007-6707.md) ### [CVE-2007-6707](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6707) ### Description Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-3574. ### POC #### Reference - http://www.gnucitizen.org/blog/persistent-xss-and-csrf-on-wireless-g-adsl-gateway-with-speedbooster-wag54gs/ #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6708 (2007/CVE-2007-6708.md) ### [CVE-2007-6708](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6708) ### Description Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi. ### POC #### Reference - http://www.gnucitizen.org/blog/persistent-xss-and-csrf-on-wireless-g-adsl-gateway-with-speedbooster-wag54gs/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6709 (2007/CVE-2007-6709.md) ### [CVE-2007-6709](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6709) ### Description The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, which makes it easier for remote attackers to obtain access. ### POC #### Reference - http://www.gnucitizen.org/blog/persistent-xss-and-csrf-on-wireless-g-adsl-gateway-with-speedbooster-wag54gs/ #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6712 (2007/CVE-2007-6712.md) ### [CVE-2007-6712](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6712) ### Description Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users to cause a denial of service (infinite loop) via a timer with a large expiry value, which causes the timer to always be expired. ### POC #### Reference - http://www.ubuntu.com/usn/usn-625-1 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9210 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6720 (2007/CVE-2007-6720.md) ### [CVE-2007-6720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6720) ### Description libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer, and possibly other products, relies on the channel count of the last loaded song, rather than the currently playing song, for certain playback calculations, which allows user-assisted attackers to cause a denial of service (application crash) by loading multiple songs (aka MOD files) with different numbers of channels. ### POC #### Reference - http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6723 (2007/CVE-2007-6723.md) ### [CVE-2007-6723](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6723) ### Description TorK before 0.22, when running on Windows and Mac OS X, installs Privoxy with a configuration file (config.txt or config) that contains insecure (1) enable-remote-toggle and (2) enable-edit-actions settings, which allows remote attackers to bypass intended access restrictions and modify configuration. ### POC #### Reference - http://sourceforge.net/project/shownotes.php?release_id=551544&group_id=159836 #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6725 (2007/CVE-2007-6725.md) ### [CVE-2007-6725](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725) ### Description The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function. ### POC #### Reference - http://www.openwall.com/lists/oss-security/2009/04/01/10 - http://www.redhat.com/support/errata/RHSA-2009-0420.html - https://bugzilla.redhat.com/show_bug.cgi?id=493442 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9507 #### Github - https://github.com/0xCyberY/CVE-T4PDF - https://github.com/ARPSyndicate/cvemon --- ### 2007/CVE 2007 6731 (2007/CVE-2007-6731.md) ### [CVE-2007-6731](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6731) ### Description Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow. ### POC #### Reference - http://aluigi.altervista.org/adv/xmpbof-adv.txt #### Github - https://github.com/mudongliang/LinuxFlaw - https://github.com/oneoy/cve- --- ### 2007/CVE 2007 6732 (2007/CVE-2007-6732.md) ### [CVE-2007-6732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6732) ### Description Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays. ### POC #### Reference - http://aluigi.altervista.org/adv/xmpbof-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6736 (2007/CVE-2007-6736.md) ### [CVE-2007-6736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6736) ### Description Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR command. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6737 (2007/CVE-2007-6737.md) ### [CVE-2007-6737](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6737) ### Description FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6738 (2007/CVE-2007-6738.md) ### [CVE-2007-6738](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6738) ### Description pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6739 (2007/CVE-2007-6739.md) ### [CVE-2007-6739](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6739) ### Description FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6740 (2007/CVE-2007-6740.md) ### [CVE-2007-6740](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6740) ### Description The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6741 (2007/CVE-2007-6741.md) ### [CVE-2007-6741](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6741) ### Description The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as demonstrated by an FTP bounce attack against a NAT server, a related issue to CVE-1999-0017. ### POC #### Reference - http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6744 (2007/CVE-2007-6744.md) ### [CVE-2007-6744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6744) ### Description Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe. ### POC #### Reference - http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Installation-InstallShield-InstallShield2008Premier-Public-ProductInfo-IS2008PremProReleaseNotes2pdf&sliceId=pdfPage_42 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2007/CVE 2007 6750 (2007/CVE-2007-6750.md) ### [CVE-2007-6750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750) ### Description The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15. ### POC #### Reference No PoCs from references. #### Github - https://github.com/3vil-Tux/Pentesting-Resources - https://github.com/AMOSFinds/network-security-assessment - https://github.com/ARPSyndicate/cvemon - https://github.com/AidanBurkeCyb/Network-Vulnerability-Assessment-with-Nmap - https://github.com/Aledangelo/THM_Kiba_Writeup - https://github.com/AleksandrMihajlov/SDB-13-01 - https://github.com/AlienTec1908/Magifi_HackMyVM_Hard - https://github.com/AntonioPC94/Ice - https://github.com/Blackvectra/ethical-hacking-lab - https://github.com/Brindamour76/THM---PickleRick - https://github.com/CH-Anonymous/devtown-basicpentesting1 - https://github.com/DButter/whitehat_public - https://github.com/Dmitri131313/ReconScan - https://github.com/Dokukin1/Metasploitable - https://github.com/Dom-Techblue/Relatorio_pentest - https://github.com/Drew-Alleman/PeztioQ2 - https://github.com/Esther7171/Ice - https://github.com/Eutectico/Steel-Mountain - https://github.com/Evisu77/Vulnerability-assessment - https://github.com/Farah-mohamed-salama/MetasplitTable2 - https://github.com/Furious992/HW13-01 - https://github.com/GiJ03/ReconScan - https://github.com/Iknowmyname/Nmap-Scans-M2 - https://github.com/Jeanpseven/slowl0ris - https://github.com/Maribel0370/Nebula-io - https://github.com/MrFrozenPepe/Pentest-Cheetsheet - https://github.com/Nanaopoku25/Nmap-Scanning - https://github.com/NeoOniX/5ATTACK - https://github.com/NikulinMS/13-01-hw - https://github.com/Nomaan3002/-Day03-cyber-task - https://github.com/Phaneesh-Katti/VAPT - https://github.com/PierreChrd/py-projet-tut - https://github.com/PradhapGH/Vulner-Reports - https://github.com/PradhapRam/Vulner-Reports - https://github.com/RoliSoft/ReconScan - https://github.com/SebSundin/THM-Nmap - https://github.com/SecureAxom/strike - https://github.com/SexyBeast233/SecBooks - https://github.com/SinghNanak/apache-dos - https://github.com/SirSeoPro/12-01 - https://github.com/Tchoumis/Analyse_SI - https://github.com/Zhivarev/13-01-hw - https://github.com/adamziaja/vulnerability-check - https://github.com/binglansky/Slowloris-DOS-Attack - https://github.com/bioly230/THM_Skynet - https://github.com/giusepperuggiero96/Network-Security-2021 - https://github.com/h0ussni/pwnloris - https://github.com/hibahmad30/NmapAnalysis - https://github.com/hktalent/bug-bounty - https://github.com/issdp/test - https://github.com/jaiderospina/NMAP - https://github.com/jkiala2/Projet_etude_M1 - https://github.com/jordanf17/PenTest-Report - https://github.com/kasem545/vulnsearch - https://github.com/le37/slowloris - https://github.com/lekctut/sdb-hw-13-01 - https://github.com/malavathpradeepkumar/task_01 - https://github.com/marcocastro100/Intrusion_Detection_System-Python - https://github.com/matoweb/Enumeration-Script - https://github.com/mrt2h/DZ - https://github.com/murilofurlan/trabalho-seguranca-redes - https://github.com/neo-13th/HW13.1 - https://github.com/noahwilliamshaffer/Target-IP-159.45.104.135 - https://github.com/nsdhanoa/apache-dos - https://github.com/oscaar90/nmap-scan - https://github.com/pedr0alencar/vlab-metasploitable2 - https://github.com/salmontts/network-security-lab - https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems - https://github.com/vshaliii/Basic-Pentesting-1-Vulnhub-Walkthrough - https://github.com/vshaliii/Basic-Pentesting-2-Vulnhub-Walkthrough - https://github.com/vshaliii/Cengbox1-Vulnhub-walkthrough - https://github.com/vshaliii/DC-3-Vulnhub-Walkthrough - https://github.com/vshaliii/FristiLeaks-Vulnhub-Walkthrough - https://github.com/vshaliii/Investigator_1-vulnhub-writeup - https://github.com/xxehacker/strike - https://github.com/yassserhabib/internal-network-pentest - https://github.com/zzzWTF/db-13-01 --- ### 2007/CVE 2007 6752 (2007/CVE-2007-6752.md) ### [CVE-2007-6752](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6752) ### Description Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off. ### POC #### Reference - http://groups.drupal.org/node/216314 - http://packetstormsecurity.org/files/110404/drupal712-xsrf.txt #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6753 (2007/CVE-2007-6753.md) ### [CVE-2007-6753](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6753) ### Description Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari. ### POC #### Reference - http://blog.acrossecurity.com/2010/10/breaking-setdlldirectory-protection.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6755 (2007/CVE-2007-6755.md) ### [CVE-2007-6755](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6755) ### Description The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE. ### POC #### Reference - http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/ - https://www.schneier.com/blog/archives/2007/11/the_strange_sto.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/GrigGM/05-virt-04-docker-hw - https://github.com/Live-Hack-CVE/CVE-2007-6755 - https://github.com/PajakAlexandre/wik-dps-tp02 - https://github.com/cdupuis/image-api - https://github.com/fokypoky/places-list - https://github.com/garethr/findcve - https://github.com/garethr/snykout - https://github.com/gatecheckdev/gatecheck - https://github.com/jasona7/ChatCVE - https://github.com/joelckwong/anchore - https://github.com/valancej/anchore-five-minutes --- ### 2007/CVE 2007 6757 (2007/CVE-2007-6757.md) ### [CVE-2007-6757](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6757) ### Description GE Healthcare Centricity DMS 4.2, 4.1, and 4.0 has a password of Muse!Admin for the Museadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. ### POC #### Reference - http://apps.gehealthcare.com/servlet/ClientServlet/2019295-133D.pdf?REQ=RAA&DIRECTION=2019295-133D&FILENAME=2019295-133D.pdf&FILEREV=D&DOCREV_ORG=D - http://apps.gehealthcare.com/servlet/ClientServlet/2019295-133G.pdf?REQ=RAA&DIRECTION=2019295-133&FILENAME=2019295-133G.pdf&FILEREV=G&DOCREV_ORG=G - http://apps.gehealthcare.com/servlet/ClientServlet/DMS+Sys+Mgmt+Manual.pdf?REQ=RAA&DIRECTION=DOC1258180&FILENAME=DMS%2BSys%2BMgmt%2BManual.pdf&FILEREV=3&DOCREV_ORG=3 - http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/ #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6758 (2007/CVE-2007-6758.md) ### [CVE-2007-6758](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6758) ### Description Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0. ### POC #### Reference - http://attrition.org/pipermail/vim/2007-April/001545.html #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6759 (2007/CVE-2007-6759.md) ### [CVE-2007-6759](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6759) ### Description Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie. ### POC #### Reference - http://blog.tmcnet.com/blog/tom-keating/computer-hardware/dataprobe-ibootbar-review.asp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6760 (2007/CVE-2007-6760.md) ### [CVE-2007-6760](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6760) ### Description Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie. ### POC #### Reference - http://blog.tmcnet.com/blog/tom-keating/computer-hardware/dataprobe-ibootbar-review.asp #### Github No PoCs found on GitHub currently. --- ### 2007/CVE 2007 6761 (2007/CVE-2007-6761.md) ### [CVE-2007-6761](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6761) ### Description drivers/media/video/videobuf-vmalloc.c in the Linux kernel before 2.6.24 does not initialize videobuf_mapping data structures, which allows local users to trigger an incorrect count value and videobuf leak via unspecified vectors, a different vulnerability than CVE-2010-5321. ### POC #### Reference - https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0b29669c065f60501e7289e1950fa2a618962358 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0001 (2008/CVE-2008-0001.md) ### [CVE-2008-0001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0001) ### Description VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9709 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0002 (2008/CVE-2008-0002.md) ### [CVE-2008-0002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0002) ### Description Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2009-0016.html #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0005 (2008/CVE-2008-0005.md) ### [CVE-2008-0005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0005) ### Description mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/DButter/whitehat_public - https://github.com/Dokukin1/Metasploitable - https://github.com/Furious992/HW13-01 - https://github.com/Iknowmyname/Nmap-Scans-M2 - https://github.com/Live-Hack-CVE/CVE-2008-0005 - https://github.com/NikulinMS/13-01-hw - https://github.com/Zhivarev/13-01-hw - https://github.com/kasem545/vulnsearch - https://github.com/krlabs/apache-vulnerabilities - https://github.com/mrt2h/DZ - https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems - https://github.com/zzzWTF/db-13-01 --- ### 2008/CVE 2008 0007 (2008/CVE-2008-0007.md) ### [CVE-2008-0007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0007) ### Description Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9412 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0009 (2008/CVE-2008-0009.md) ### [CVE-2008-0009](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0009) ### Description The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/R0B1NL1N/linux-kernel-exploitation - https://github.com/Technoashofficial/kernel-exploitation-linux - https://github.com/kdn111/linux-kernel-exploitation - https://github.com/khanhdn111/linux-kernel-exploitation - https://github.com/khanhdz-06/linux-kernel-exploitation - https://github.com/khanhdz191/linux-kernel-exploitation - https://github.com/khanhhdz/linux-kernel-exploitation - https://github.com/khanhhdz06/linux-kernel-exploitation - https://github.com/khanhnd123/linux-kernel-exploitation - https://github.com/khnhdz/linux-kernel-exploitation - https://github.com/knd06/linux-kernel-exploitation - https://github.com/ndk06/linux-kernel-exploitation - https://github.com/ndk191/linux-kernel-exploitation - https://github.com/skbasava/Linux-Kernel-exploit - https://github.com/ssr-111/linux-kernel-exploitation - https://github.com/wkhnh06/linux-kernel-exploitation - https://github.com/xairy/linux-kernel-exploitation --- ### 2008/CVE 2008 0010 (2008/CVE-2008-0010.md) ### [CVE-2008-0010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0010) ### Description The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations. ### POC #### Reference - https://www.exploit-db.com/exploits/5093 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/R0B1NL1N/linux-kernel-exploitation - https://github.com/Technoashofficial/kernel-exploitation-linux - https://github.com/kdn111/linux-kernel-exploitation - https://github.com/khanhdn111/linux-kernel-exploitation - https://github.com/khanhdz-06/linux-kernel-exploitation - https://github.com/khanhdz191/linux-kernel-exploitation - https://github.com/khanhhdz/linux-kernel-exploitation - https://github.com/khanhhdz06/linux-kernel-exploitation - https://github.com/khanhnd123/linux-kernel-exploitation - https://github.com/khnhdz/linux-kernel-exploitation - https://github.com/knd06/linux-kernel-exploitation - https://github.com/ndk06/linux-kernel-exploitation - https://github.com/ndk191/linux-kernel-exploitation - https://github.com/skbasava/Linux-Kernel-exploit - https://github.com/ssr-111/linux-kernel-exploitation - https://github.com/wkhnh06/linux-kernel-exploitation - https://github.com/xairy/linux-kernel-exploitation --- ### 2008/CVE 2008 0011 (2008/CVE-2008-0011.md) ### [CVE-2008-0011](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0011) ### Description Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-033 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0015 (2008/CVE-2008-0015.md) ### [CVE-2008-0015](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0015) ### Description Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability." ### POC #### Reference - http://isc.sans.org/diary.html?storyid=6733 - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037 #### Github - https://github.com/ahmedobied/python-exploits --- ### 2008/CVE 2008 0016 (2008/CVE-2008-0016.md) ### [CVE-2008-0016](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0016) ### Description Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link. ### POC #### Reference - http://www.ubuntu.com/usn/usn-645-1 - http://www.ubuntu.com/usn/usn-645-2 - http://www.vupen.com/english/advisories/2009/0977 - https://bugzilla.mozilla.org/show_bug.cgi?id=443288 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0017 (2008/CVE-2008-0017.md) ### [CVE-2008-0017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0017) ### Description The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow. ### POC #### Reference - http://www.redhat.com/support/errata/RHSA-2008-0977.html - http://www.vupen.com/english/advisories/2009/0977 - https://bugzilla.mozilla.org/show_bug.cgi?id=443299 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0020 (2008/CVE-2008-0020.md) ### [CVE-2008-0020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0020) ### Description Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0027 (2008/CVE-2008-0027.md) ### [CVE-2008-0027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0027) ### Description Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request. ### POC #### Reference - http://securityreason.com/securityalert/3551 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0028 (2008/CVE-2008-0028.md) ### [CVE-2008-0028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0028) ### Description Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20080123-asa.shtml #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0029 (2008/CVE-2008-0029.md) ### [CVE-2008-0029](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0029) ### Description Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges. ### POC #### Reference - http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0033 (2008/CVE-2008-0033.md) ### [CVE-2008-0033](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0033) ### Description Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0053 (2008/CVE-2008-0053.md) ### [CVE-2008-0053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0053) ### Description Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file. ### POC #### Reference - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10356 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0062 (2008/CVE-2008-0062.md) ### [CVE-2008-0062](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0062) ### Description KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free. ### POC #### Reference - http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt - http://www.vmware.com/security/advisories/VMSA-2008-0009.html - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9496 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0063 (2008/CVE-2008-0063.md) ### [CVE-2008-0063](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0063) ### Description The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." ### POC #### Reference - http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt - http://www.vmware.com/security/advisories/VMSA-2008-0009.html #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0066 (2008/CVE-2008-0066.md) ### [CVE-2008-0066](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0066) ### Description Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0067 (2008/CVE-2008-0067.md) ### [CVE-2008-0067](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0067) ### Description Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program. ### POC #### Reference - http://securityreason.com/securityalert/4885 - http://securityreason.com/securityalert/8307 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0068 (2008/CVE-2008-0068.md) ### [CVE-2008-0068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0068) ### Description Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter. ### POC #### Reference - http://aluigi.altervista.org/adv/closedviewx-adv.txt #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0069 (2008/CVE-2008-0069.md) ### [CVE-2008-0069](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0069) ### Description Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461. ### POC #### Reference - https://www.exploit-db.com/exploits/5346 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0071 (2008/CVE-2008-0071.md) ### [CVE-2008-0071](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0071) ### Description The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header. ### POC #### Reference - http://securityreason.com/securityalert/3943 - https://www.exploit-db.com/exploits/5918 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0074 (2008/CVE-2008-0074.md) ### [CVE-2008-0074](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0074) ### Description Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-005 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0075 (2008/CVE-2008-0075.md) ### [CVE-2008-0075](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0075) ### Description Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-006 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0076 (2008/CVE-2008-0076.md) ### [CVE-2008-0076](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0076) ### Description Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0077 (2008/CVE-2008-0077.md) ### [CVE-2008-0077](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0077) ### Description Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0078 (2008/CVE-2008-0078.md) ### [CVE-2008-0078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0078) ### Description Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability." ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-010 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0080 (2008/CVE-2008-0080.md) ### [CVE-2008-0080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0080) ### Description Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-007 #### Github - https://github.com/ARPSyndicate/cve-scores --- ### 2008/CVE 2008 0081 (2008/CVE-2008-0081.md) ### [CVE-2008-0081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0081) ### Description Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0082 (2008/CVE-2008-0082.md) ### [CVE-2008-0082](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0082) ### Description An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-050 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0083 (2008/CVE-2008-0083.md) ### [CVE-2008-0083](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0083) ### Description The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-022 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0084 (2008/CVE-2008-0084.md) ### [CVE-2008-0084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0084) ### Description Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-004 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0085 (2008/CVE-2008-0085.md) ### [CVE-2008-0085](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0085) ### Description SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2011-0003.html - http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0086 (2008/CVE-2008-0086.md) ### [CVE-2008-0086](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0086) ### Description Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression. ### POC #### Reference - http://www.vmware.com/security/advisories/VMSA-2011-0003.html - http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0087 (2008/CVE-2008-0087.md) ### [CVE-2008-0087](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0087) ### Description The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses. ### POC #### Reference - http://www.trusteer.com/docs/windowsresolver.html - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-020 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0088 (2008/CVE-2008-0088.md) ### [CVE-2008-0088](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0088) ### Description Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request. ### POC #### Reference - https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-003 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0089 (2008/CVE-2008-0089.md) ### [CVE-2008-0089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0089) ### Description SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4830 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0090 (2008/CVE-2008-0090.md) ### [CVE-2008-0090](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0090) ### Description A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method. ### POC #### Reference - https://www.exploit-db.com/exploits/4829 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0091 (2008/CVE-2008-0091.md) ### [CVE-2008-0091](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0091) ### Description Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter. ### POC #### Reference - https://www.exploit-db.com/exploits/4828 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0092 (2008/CVE-2008-0092.md) ### [CVE-2008-0092](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0092) ### Description Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. ### POC #### Reference - http://securityreason.com/securityalert/3511 #### Github No PoCs found on GitHub currently. --- ### 2008/CVE 2008 0094 (2008/CVE-2008-0094.md) ### [CVE-2008-0094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0094) ### Description Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php. ### POC #### Reference - http://securityreason.com/securityalert/3522 #### Github No PoCs found on GitHub currently. ---