CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2011-3616

    Last Modified: 11 Apr 2025

    The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.

    Published: 4 Nov 2011
    9.3
    Critical

    CVE-2011-3991

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in FFFTP 1.98a and earlier allows local users to execute arbitrary code via unspecified functions.

    Published: 4 Nov 2011
    4.3
    Medium

    CVE-2011-3986

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Pligg before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Nov 2011
    4.9
    Medium

    CVE-2011-3987

    Last Modified: 11 Apr 2025

    dtsoftbus01.sys in DAEMON Tools Lite before 4.41.3, Pro Standard before 4.41.0315, and Pro Advanced before 4.41.0315 allows local users to cause a denial of service (system crash) via an invalid DeviceIoControl request to \\.\dtsoftbusctl.

    Published: 3 Nov 2011
    5.5
    Medium

    CVE-2011-3993

    Last Modified: 11 Apr 2025

    SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors.

    Published: 3 Nov 2011
    5
    Medium

    CVE-2011-3996

    Last Modified: 11 Apr 2025

    The LiveData Service in CSWorks before 2.0.4115.1 allows remote attackers to cause a denial of service (service crash) via crafted TCP packets.

    Published: 3 Nov 2011
    10
    Critical

    CVE-2011-3992

    Last Modified: 11 Apr 2025

    Buffer overflow in the SSH server functionality on the D-Link DES-3800 with firmware before 4.50B052, DWL-2100AP with firmware before 2.50RC548, and DWL-3200AP with firmware before 2.55RC549 allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

    Published: 3 Nov 2011
    6.8
    Medium

    CVE-2011-3994

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data.

    Published: 3 Nov 2011
    4.3
    Medium

    CVE-2011-4277

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page.

    Published: 3 Nov 2011
    5
    Medium

    CVE-2011-4078

    Last Modified: 11 Apr 2025

    include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

    Published: 3 Nov 2011
    5
    Medium

    CVE-2011-3995

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Twilight Frontier Touhou Hisouten 1.06 and earlier allows remote attackers to cause a denial of service (daemon crash) via unknown network traffic.

    Published: 3 Nov 2011
    4.3
    Medium

    CVE-2011-4274

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-2676.

    Published: 3 Nov 2011
    9.3
    Critical

    CVE-2011-4005

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546W, and SRP547W with firmware before 1.2.1 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands, aka Bug ID CSCtr45124.

    Published: 3 Nov 2011
    4.3
    Medium

    CVE-2011-4273

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or (4) group parameter to goform/AddUser, related to adduser.asp.

    Published: 3 Nov 2011
    5.5
    Medium

    CVE-2011-2676

    Last Modified: 11 Apr 2025

    The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors.

    Published: 3 Nov 2011
    9.8
    Critical

    CVE-2011-4121

    Last Modified: 21 Nov 2024

    The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.

    Published: 3 Nov 2011
    4.3
    Medium

    CVE-2010-4971

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-4997

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-4998

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5004

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5005

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in members/profileCommentsResponse.php in Rayzz Photoz allows remote attackers to inject arbitrary web script or HTML via the profileCommentTextArea parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5006

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5007

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5008

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5011

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arbitrary SQL commands via the session parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5012

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5013

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5014

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5015

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5016

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5017

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5019

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5020

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5021

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5022

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5023

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.

    Published: 2 Nov 2011
    6
    Medium

    CVE-2010-5024

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5025

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    6.8
    Medium

    CVE-2010-5026

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5028

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5029

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5030

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter in a web action.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5031

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in fileNice 1.1 allows remote attackers to inject arbitrary web script or HTML via the sstring parameter (aka the Search Box). NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5032

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5033

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5034

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5037

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5038

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5039

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5041

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.

    Published: 2 Nov 2011