Total
5025 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-5110 | 1 Eb Design Pty Ltd | 1 Ebcrypt | 2017-09-28 | 7.5 HIGH | N/A |
Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and earlier in EB Design ebCrypt allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-5219 | 1 Cyberlink | 1 Powerdvd | 2017-09-28 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method. | |||||
CVE-2007-5299 | 1 Skadate | 1 Skadate Online Dating Software | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. (dot dot) in the view_mode parameter to (1) featured_list.php and (2) online_list.php in member/. | |||||
CVE-2007-5446 | 1 Perfection Bytes | 1 Pbemail | 2017-09-28 | 6.4 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method. | |||||
CVE-2007-5731 | 1 Apache | 1 Jakarta Slide | 2017-09-28 | 3.5 LOW | N/A |
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461. | |||||
CVE-2007-5812 | 1 Modulebuilder | 1 Modulebuilder | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2007-5826 | 1 Edraw | 1 Flowchart Activex | 2017-09-28 | 9.3 HIGH | N/A |
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420. | |||||
CVE-2007-5782 | 1 Fireconfig | 1 Fireconfig | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2007-5811 | 1 Phpmyconferences | 1 Phpmyconferences | 2017-09-28 | 5.0 MEDIUM | N/A |
** DISPUTED ** Directory traversal vulnerability in PageTraiteDownload.php in phpMyConferences 8.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter. NOTE: this issue is disputed for 8.0.2 by a reliable third party, who notes that the PHP code is syntactically incorrect and cannot be executed. | |||||
CVE-2007-5813 | 1 Ispworker | 1 Ispworker | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters. | |||||
CVE-2007-5820 | 1 Ax Developer Cms | 1 Ax Developer Cms | 2017-09-28 | 9.3 HIGH | N/A |
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter. | |||||
CVE-2007-5821 | 1 Dm Guestbook | 1 Dm Guestbook | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lng parameter to (a) guestbook.php, (b) admin/admin.guestbook.php, or (c) auto/glob_new.php; or (2) the lngdefault parameter to auto/ch_lng.php. | |||||
CVE-2007-5844 | 1 Guppy | 1 Guppy | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin parameter to index.php. NOTE: this can be leveraged for remote file inclusion by including inc/boxleft.inc and specifying a URL in the xposbox[L][] array parameter. | |||||
CVE-2007-6079 | 1 Bcoos | 1 Bcoos | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file. | |||||
CVE-2007-6184 | 1 Project Alumni | 1 Project Alumni | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter. | |||||
CVE-2007-6213 | 1 Webed | 1 Webed | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters. | |||||
CVE-2007-6187 | 1 Noah | 1 Noah | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filepath parameter to (1) css_file.php, (2) js_file.php, or (3) xml_file.php in noah/modules/nosystem/templates/. | |||||
CVE-2007-6188 | 1 Tumusika Evolution | 1 Tumusika Evolution | 2017-09-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php. | |||||
CVE-2007-6212 | 1 Google | 1 Kml | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter. | |||||
CVE-2007-6214 | 1 Learnloop | 1 Learnloop | 2017-09-28 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter. NOTE: exploitation requires that the product is configured, but has zero files in the database. |