Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2007-02-21 CVE-2007-1034 SQL Injection vulnerability in PHP-Nuke Emporium Module
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
network
low complexity
php-nuke CWE-89
7.5
2007-02-21 CVE-2007-1033 Security Bypass vulnerability in Drupal Secure Site Module 4.7/5.0
Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.
network
low complexity
drupal
7.5
2007-02-21 CVE-2007-1030 Denial Of Service vulnerability in Niels Provos Libevent 1.2/1.2A
Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.
network
low complexity
niels-provos
7.8
2007-02-21 CVE-2007-1029 Remote Stack Buffer Overflow vulnerability in EasyMail Objects Connect Method
Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.
network
high complexity
quicksoft
7.6
2007-02-21 CVE-2007-1026 SQL Injection vulnerability in Scriptdungeon Xlatunes
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode.
network
low complexity
scriptdungeon CWE-89
7.5
2007-02-21 CVE-2007-1025 Remote File Include vulnerability in VS-Link-Partner Functions.Inc.PHP
PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.
network
low complexity
virtualsystem
7.5
2007-02-21 CVE-2007-1023 SQL Injection vulnerability in Snitz Communications Snitz Forums 2000 3.1
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
snitz-communications
7.5
2007-02-21 CVE-2007-1022 SQL Injection vulnerability in Turuncu Portal Turuncu Portal 1.0
SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
turuncu-portal
7.5
2007-02-21 CVE-2007-1016 SQL-Injection vulnerability in Aktueldownload Haber Script
SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters.
network
low complexity
aktueldownload
7.5
2007-02-21 CVE-2007-1011 Remote File Include vulnerability in VS-Gastebuch Gb_Pfad
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.
network
low complexity
vs-gastebuch
7.5