Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2007-05-16 CVE-2007-2715 Remote Password Change vulnerability in Snaps Gallery Snaps Gallery 1.4.4
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
network
low complexity
snaps-gallery
critical
10.0
2007-05-16 CVE-2007-2714 Unspecified vulnerability in WordPress Akismet Plugin
Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors.
network
low complexity
matt-mullenweg
critical
10.0
2007-05-16 CVE-2007-2713 Authentication Bypass vulnerability in IFDate Administrative
ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
network
low complexity
ifusionservices
critical
10.0
2007-05-16 CVE-2007-2712 Unspecified vulnerability in MHSoftware Connect Daily
Unspecified vulnerability in MH Software Connect Daily before 3.3.3 has unknown impact and attack vectors.
network
low complexity
mh-software
critical
10.0
2007-05-16 CVE-2007-2711 Remote Buffer Overflow vulnerability in TinyIdentD
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.
network
low complexity
tinyirc
critical
10.0
2007-05-16 CVE-2007-2710 Remote Security vulnerability in NagiosQL
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter.
network
low complexity
nagiosql
7.5
2007-05-16 CVE-2007-2709 Remote File Include vulnerability in Nagiosql 2005 2.00
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.
network
low complexity
nagiosql
7.5
2007-05-16 CVE-2007-2708 Remote File Include vulnerability in Feindt Computerservice News-Script 2.0
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.
network
low complexity
feindt-computerservice
7.5
2007-05-16 CVE-2007-2707 Remote File Include vulnerability in Linksnet Newsfeed 1.0
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.
network
linksnet
6.8
2007-05-16 CVE-2007-2706 Remote File Include vulnerability in Geeklog Media Gallery Ftpmedia.PHP
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter.
network
low complexity
geeklog
7.5