Total
6537 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-6233 | 1 Ftp Admin | 1 Ftp Admin | 2024-11-21 | 4.9 MEDIUM | N/A |
Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL. | |||||
CVE-2007-6230 | 1 Rayzz | 1 Rayzz Script | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CFG[site][project_path] parameter. | |||||
CVE-2007-6215 | 1 Web-meetme | 1 Web-meetme | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (2) bookid parameter. | |||||
CVE-2007-6214 | 1 Learnloop | 1 Learnloop | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter. NOTE: exploitation requires that the product is configured, but has zero files in the database. | |||||
CVE-2007-6213 | 1 Webed | 1 Webed | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters. | |||||
CVE-2007-6212 | 1 Google | 1 Kml | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter. | |||||
CVE-2007-6188 | 1 Tumusika Evolution | 1 Tumusika Evolution | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php. | |||||
CVE-2007-6187 | 1 Noah | 1 Noah | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filepath parameter to (1) css_file.php, (2) js_file.php, or (3) xml_file.php in noah/modules/nosystem/templates/. | |||||
CVE-2007-6185 | 1 Eurologon | 1 Eurologon Cms | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a download action, as demonstrated by a certain PHP file containing database credentials. | |||||
CVE-2007-6184 | 1 Project Alumni | 1 Project Alumni | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter. | |||||
CVE-2007-6086 | 1 Vigilecms | 1 Vigilecms | 2024-11-21 | 9.3 HIGH | N/A |
Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter. | |||||
CVE-2007-6079 | 1 Bcoos | 1 Bcoos | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file. | |||||
CVE-2007-5960 | 1 Mozilla | 2 Firefox, Seamonkey | 2024-11-21 | 4.3 MEDIUM | N/A |
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent. | |||||
CVE-2007-5956 | 1 Ibm | 1 Informix Dynamic Server | 2024-11-21 | 7.2 HIGH | N/A |
Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable. | |||||
CVE-2007-5927 | 1 Openbase International Ltd | 1 Openbase | 2024-11-21 | 9.0 HIGH | N/A |
Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926. | |||||
CVE-2007-5920 | 1 Picoflat Cms | 1 Picoflat Cms | 2024-11-21 | 6.8 MEDIUM | N/A |
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative scripts. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-5915 | 1 Phphelpdesk | 1 Phphelpdesk | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter. | |||||
CVE-2007-5844 | 1 Guppy | 1 Guppy | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin parameter to index.php. NOTE: this can be leveraged for remote file inclusion by including inc/boxleft.inc and specifying a URL in the xposbox[L][] array parameter. | |||||
CVE-2007-5831 | 1 Ssl-explorer | 1 Ssl-explorer | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in fileSystem.do in SSL-Explorer before 0.2.14 allows remote attackers to access arbitrary files via directory traversal sequences in the path parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-5826 | 1 Edraw | 1 Flowchart Activex | 2024-11-21 | 9.3 HIGH | N/A |
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420. |