Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dj7xpl vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-5612
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via the aide parameter.
Michel Pradel Gestart Beta 1
1 EDB exploit
7.8
CVSSv2
CVE-2007-3272
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote malicious users to read arbitrary files via a .. (dot dot) in the language parameter in a register action.
Minibb Minibb 2.0.5
1 EDB exploit
7.5
CVSSv2
CVE-2007-2145
The imagecomments function in classes.php in MiniGal b13 allows remote malicious users to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: some of these details are obtained from third party information.
Minigal Minigal B13
1 EDB exploit
7.5
CVSSv2
CVE-2007-2146
The imagecomments function in classes.php in MiniGal b13 allow remote malicious users to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fr...
Minigal Minigal B13
1 EDB exploit
7.5
CVSSv2
CVE-2007-2154
PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote malicious users to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.
Cabron Connector Cabron Connector
1 EDB exploit
7.5
CVSSv2
CVE-2007-2158
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote malicious users to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.
Kooijman-design Jgallery 1.3
1 EDB exploit
7.5
CVSSv2
CVE-2007-5050
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the q parameter.
Neuron News Neuron News 1.0
1 EDB exploit
6.4
CVSSv2
CVE-2007-3630
changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote malicious users to change passwords for arbitrary users via a modified password parameter.
Av Scripts Av Tutorial Script 1.0
1 EDB exploit
6.8
CVSSv2
CVE-2007-1908
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote malicious users to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.
Php121 Php121 Instant Messenger 2.2
1 EDB exploit
5
CVSSv2
CVE-2007-2050
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.
Ricargbook Ricargbook 1.2.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »