Total
6537 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-5110 | 1 Eb Design Pty Ltd | 1 Ebcrypt | 2024-11-21 | 7.5 HIGH | N/A |
Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-5103 | 1 Wordsmith | 1 Wordsmith | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _path parameter. | |||||
CVE-2007-5092 | 1 Multimedia | 1 Dance Music Module For Phpnuke | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php. | |||||
CVE-2007-5069 | 1 Massimo Chioni | 1 Mobile Entertainment Module | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter. | |||||
CVE-2007-5055 | 1 Izicontents | 1 Izicontents | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php. | |||||
CVE-2007-5050 | 1 Neuron News | 1 Neuron News | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter. | |||||
CVE-2007-5017 | 1 Yahoo | 1 Messenger | 2024-11-21 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method. | |||||
CVE-2007-5005 | 2 Broadcom, Ca | 3 Brightstor Arcserve Backup Laptops Desktops, Desktop Management Suite, Protection Suites | 2024-11-21 | 10.0 HIGH | N/A |
Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the rxrReceiveFileFromServer command. | |||||
CVE-2007-4983 | 1 Cowon America | 1 Jetaudio | 2024-11-21 | 10.0 HIGH | N/A |
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call. | |||||
CVE-2007-4982 | 1 Mw6 Technologies | 1 Qrcode Activex | 2024-11-21 | 10.0 HIGH | N/A |
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-4976 | 1 Coppermine | 1 Coppermine Photo Gallery | 2024-11-21 | 6.5 MEDIUM | N/A |
Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter. | |||||
CVE-2007-4962 | 1 Winimage | 1 Winimage | 2024-11-21 | 9.3 HIGH | N/A |
Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |||||
CVE-2007-4957 | 1 Chupix | 1 Chupix Cms | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter. | |||||
CVE-2007-4908 | 1 Auracms | 1 Auracms | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter. | |||||
CVE-2007-4902 | 1 Ultra Shareware | 1 Ultra Crypto Component | 2024-11-21 | 6.4 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method. | |||||
CVE-2007-4895 | 1 Sisfo Kampus | 1 Sisfo Kampus | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. | |||||
CVE-2007-4890 | 1 Microsoft | 1 Visual Studio | 2024-11-21 | 5.8 MEDIUM | N/A |
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method. | |||||
CVE-2007-4843 | 1 X-diesel | 1 Unreal Commander | 2024-11-21 | 5.8 MEDIUM | N/A |
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |||||
CVE-2007-4842 | 1 Enriva Development | 1 Magellan Explorer | 2024-11-21 | 9.3 HIGH | N/A |
Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |||||
CVE-2007-4829 | 2 Archive\, Canonical | 2 \, Ubuntu Linux | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences. |