Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2007-03-02 CVE-2007-1168 Authentication Bypass vulnerability in Trend Micro Serverprotect 1.2520070216/1.3/2.5
Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).
network
low complexity
trend-micro
7.5
2007-03-02 CVE-2007-1166 SQL Injection vulnerability in Nabocorp Nabopoll 1.2
SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.
network
low complexity
nabocorp CWE-89
7.5
2007-03-02 CVE-2007-1165 Code Injection vulnerability in Dbscripts Dbguestbook 1.1
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.
network
low complexity
dbscripts CWE-94
7.5
2007-03-02 CVE-2007-1164 Code Injection vulnerability in Dbscripts Dbimagegallery 1.2.2
Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.
network
low complexity
dbscripts CWE-94
7.5
2007-03-02 CVE-2007-1163 SQL Injection vulnerability in Webspell 4.0/4.01.00/4.01.01
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
network
low complexity
webspell CWE-89
7.5
2007-03-02 CVE-2007-1162 Buffer Overflow vulnerability in BrowseDialog ActiveX Control CCRPBDS6.DLL
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.
network
low complexity
common-controls-replacement-project
7.8
2007-03-02 CVE-2007-1157 Cross-Site Request Forgery (CSRF) vulnerability in Jboss
Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.
network
high complexity
jboss CWE-352
7.6
2007-03-02 CVE-2007-1156 Unspecified vulnerability in MAN Machine Systems Jbrowser
JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.
network
low complexity
man-machine-systems
7.5
2007-03-02 CVE-2007-1153 Code Injection vulnerability in Cutephp Cutenews 1.3.6
Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors.
network
low complexity
cutephp CWE-94
7.5
2007-03-02 CVE-2007-1148 Code Injection vulnerability in Lovecms 1.4
PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.
network
low complexity
lovecms CWE-94
7.5