Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2007-02-04 CVE-2007-0699 Code Injection vulnerability in Portail web PHP Portail web PHP 0.99
PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.
network
low complexity
portail-web-php CWE-94
7.5
2007-02-04 CVE-2006-6966 Remote Security vulnerability in Phpgraphy
phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a config.php file via the pictures[] parameter to index.php.
network
low complexity
phpgraphy
7.5
2007-02-03 CVE-2007-0695 SQL Injection vulnerability in Free LAN Intra Internet Portal Free LAN Intra Internet Portal 0.9.0.1029/0.9.0.730/1.0Rc1
Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
free-lan-intra-internet-portal CWE-89
7.5
2007-02-03 CVE-2007-0688 SQL Injection vulnerability in Hünkaray Duyuru Scripti Oku.ASP
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
hunkaray-duyuru
7.5
2007-02-03 CVE-2007-0686 Denial-Of-Service vulnerability in Intel 2200Bg Proset Wireless 9.0.3.9
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651.
network
intel
7.1
2007-02-03 CVE-2007-0684 Remote File Include vulnerability in Cerulean Portal System Cerulean Portal System 0.7B
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
network
low complexity
cerulean-portal-system
7.5
2007-02-03 CVE-2007-0683 Improper Input Validation vulnerability in Omegaboard Project Omegaboard 1.0
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
network
low complexity
omegaboard-project CWE-20
7.5
2007-02-03 CVE-2007-0682 Remote File Include vulnerability in JV2 Folder Gallery Template.PHP
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.
network
low complexity
jv2
7.5
2007-02-03 CVE-2007-0680 Remote File Include vulnerability in PHPbb Tweaked PHPbb Tweaked 1
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
network
low complexity
phpbb-tweaked
7.5
2007-02-03 CVE-2007-0679 Remote File Include vulnerability in Nicolas Grandjean PHPmyring 4.1.0B/4.1.1B/4.1.2B
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.
network
low complexity
nicolas-grandjean
7.5