LiveActive security incident?Get immediate response
CVE archive

2007 CVE Archive

Browse CVE records published in 2007 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6458 matching CVEs · Page 6 of 130.

Unknown · CVSS Not scored

CVE-2007-6617: Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows rem...

Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.

Published Jan 3, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6644: Joomla!

Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.

Published Jan 4, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6628: LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and d...

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

Published Jan 4, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6633: Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remot...

Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to inject arbitrary web script or HTML via (1) the cat_name parameter to faq.php; and unspecified parameters to the (2) add categories, (3) edit categories, (4) delete categories, (5) add faq, (6) edit faq, and (7) delete faq Admin scripts.

Published Jan 4, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6645: Unspecified vulnerability in Joomla!

Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered user privilege escalation vulnerability."

Published Jan 4, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6629: Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of serv...

Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a User-Agent header line that contains a carriage-return character, which is considered a line delimiter when the header is split into individual lines, but not when log_user_agent in RTSP_utils.c parses the content of the User-Agent line.

Published Jan 4, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6498: Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authe...

Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter to OpenApi/GatewayVariables.asp, and possibly (5) unspecified vectors to IIS/iibind.asp.

Published Dec 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6584: Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execut...

Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.

Published Dec 28, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6603: Hot or Not Clone has insufficient access control for producing and reading database backups, which allows r...

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

Published Dec 31, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6591: KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domai...

KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

Published Dec 28, 2007 · Updated Aug 7, 2024