Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2007-05-16 CVE-2007-2440 Information Disclosure vulnerability in Caucho Resin
Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a ..
network
low complexity
caucho-technology
5.0
2007-05-16 CVE-2007-2439 Denial-Of-Service vulnerability in Resin
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.
network
low complexity
caucho-technology
critical
9.4
2007-05-16 CVE-2007-2715 Remote Password Change vulnerability in Snaps Gallery Snaps Gallery 1.4.4
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
network
low complexity
snaps-gallery
critical
10.0
2007-05-16 CVE-2007-2714 Unspecified vulnerability in WordPress Akismet Plugin
Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors.
network
low complexity
matt-mullenweg
critical
10.0
2007-05-16 CVE-2007-2713 Authentication Bypass vulnerability in IFDate Administrative
ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
network
low complexity
ifusionservices
critical
10.0
2007-05-16 CVE-2007-2712 Unspecified vulnerability in MHSoftware Connect Daily
Unspecified vulnerability in MH Software Connect Daily before 3.3.3 has unknown impact and attack vectors.
network
low complexity
mh-software
critical
10.0
2007-05-16 CVE-2007-2711 Remote Buffer Overflow vulnerability in TinyIdentD
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.
network
low complexity
tinyirc
critical
10.0
2007-05-16 CVE-2007-2710 Remote Security vulnerability in NagiosQL
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter.
network
low complexity
nagiosql
7.5
2007-05-16 CVE-2007-2709 Remote File Include vulnerability in Nagiosql 2005 2.00
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.
network
low complexity
nagiosql
7.5
2007-05-16 CVE-2007-2708 Remote File Include vulnerability in Feindt Computerservice News-Script 2.0
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.
network
low complexity
feindt-computerservice
7.5