Total
5025 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-4420 | 1 Edraw | 1 Office Viewer Component | 2017-09-28 | 9.3 HIGH | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169. | |||||
CVE-2007-4583 | 1 Acti | 1 Network Video Recorder | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method. | |||||
CVE-2007-4585 | 1 2532gigs | 1 2532gigs | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. | |||||
CVE-2007-4641 | 1 Pakupaku | 1 Pakupaku Cms | 2017-09-28 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file. | |||||
CVE-2007-4726 | 1 Weboddity | 1 Weboddity | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |||||
CVE-2007-4805 | 1 Fuzzylime | 1 Fuzzylime | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter. | |||||
CVE-2007-5465 | 1 Mydoop | 1 Doop Cms | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in doop CMS 1.3.7 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter to an unspecified component. | |||||
CVE-2007-4820 | 1 Sisfo Kampus | 1 Sisfo Kampus | 2017-09-28 | 7.5 HIGH | N/A |
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter. | |||||
CVE-2007-4890 | 1 Microsoft | 1 Visual Studio | 2017-09-28 | 5.8 MEDIUM | N/A |
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method. | |||||
CVE-2007-4895 | 1 Sisfo Kampus | 1 Sisfo Kampus | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. | |||||
CVE-2007-4902 | 1 Ultra Shareware | 1 Ultra Crypto Component | 2017-09-28 | 6.4 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method. | |||||
CVE-2007-4908 | 1 Auracms | 1 Auracms | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter. | |||||
CVE-2007-5620 | 1 Zehnet | 1 Zz Flashchat | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. | |||||
CVE-2007-4957 | 1 Chupix | 1 Chupix Cms | 2017-09-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter. | |||||
CVE-2007-4982 | 1 Mw6 Technologies | 1 Qrcode Activex | 2017-09-28 | 10.0 HIGH | N/A |
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-4983 | 1 Cowon America | 1 Jetaudio | 2017-09-28 | 10.0 HIGH | N/A |
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call. | |||||
CVE-2007-5017 | 1 Yahoo | 1 Messenger | 2017-09-28 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method. | |||||
CVE-2007-5055 | 1 Izicontents | 1 Izicontents | 2017-09-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php. | |||||
CVE-2007-5103 | 1 Wordsmith | 1 Wordsmith | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _path parameter. | |||||
CVE-2007-5674 | 1 Instaguide | 1 Weather | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter. |