CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-5045

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5010

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5035

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5036

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Published: 2 Nov 2011
    6.8
    Medium

    CVE-2010-5040

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5042

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    6
    Medium

    CVE-2010-5044

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5000

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-5009

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5018

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2010-5027

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Nov 2011
    6
    Medium

    CVE-2010-5043

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.

    Published: 2 Nov 2011
    10
    Critical

    CVE-2011-1918

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

    Published: 2 Nov 2011
    10
    Critical

    CVE-2011-3167

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2011-4074

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2011-4075

    Last Modified: 11 Apr 2025

    The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.

    Published: 2 Nov 2011
    10
    Critical

    CVE-2011-1919

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic to (1) PRProficyMgr.exe in Proficy Server Manager, (2) PRGateway.exe in Proficy Server Gateway, (3) PRRDS.exe in Proficy Remote Data Service, or (4) PRLicenseMgr.exe in Proficy Server License Manager.

    Published: 2 Nov 2011
    10
    Critical

    CVE-2011-3166

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209.

    Published: 2 Nov 2011
    4.3
    Medium

    CVE-2011-3320

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 2 Nov 2011
    10
    Critical

    CVE-2011-3165

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208.

    Published: 2 Nov 2011
    1.2
    Low

    CVE-2011-4415

    Last Modified: 11 Apr 2025

    The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.

    Published: 2 Nov 2011
    4.4
    Medium

    CVE-2011-3607

    Last Modified: 11 Apr 2025

    Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.

    Published: 2 Nov 2011
    7.5
    High

    CVE-2010-4970

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4972

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4974

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4975

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to index.php.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2010-4976

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4977

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2010-4978

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4979

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4980

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4981

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4984

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4986

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4987

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4988

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers to execute arbitrary PHP code via a URL in the TMPL[path] parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4989

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4990

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4993

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4994

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4996

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4999

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-5001

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2010-5002

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-5003

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4969

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2010-4973

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4983

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2010-4985

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4992

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.

    Published: 1 Nov 2011