LiveActive security incident?Get immediate response
CVE archive

March 2007

Browse CVE records published in March 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 549 matching CVEs · Page 4 of 11.

Unknown · CVSS Not scored

CVE-2007-1623: Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled...

Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to welcome_admin.php; and possibly unspecified other parameters and files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Mar 23, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1432: Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct...

Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.

Published Mar 13, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1498: Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the...

Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.

Published Mar 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1462: The luci server component in conga preserves the password between page loads for the Add System/Cluster tas...

The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.

Published Mar 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1605: w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with a...

w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies. NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1598: Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arb...

Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by filecopa.tar by Immunity. NOTE: some of these details are obtained from third party information. NOTE: As of 20070322, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1582: The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers t...

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.

Published Mar 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1592: net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a...

net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1601: Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers...

Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1596: Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 compon...

Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1567: Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause...

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

Published Mar 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1581: The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code...

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

Published Mar 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1446: Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote atta...

Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.

Published Mar 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1597: Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access contr...

Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1583: The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_glo...

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

Published Mar 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1604: Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload a...

Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.

Published Mar 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1585: The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03...

The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to obtain sensitive information (passwords and configuration data) via a packet to UDP port 916. NOTE: some of these details are obtained from third party information.

Published Mar 21, 2007 · Updated Aug 7, 2024