CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-4959

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 9 Oct 2011
    4.3
    Medium

    CVE-2010-4960

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka Yellow Pages or mh_branchenbuch) extension before 0.9.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Oct 2011
    4.3
    Medium

    CVE-2010-4895

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4896

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/index.asp in Member Management System 4.0 allows remote attackers to inject arbitrary web script or HTML via the REF_URL parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4897

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4898

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4899

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 Oct 2011
    5.8
    Medium

    CVE-2010-4900

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4901

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4902

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4904

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4905

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4906

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4907

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4908

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4909

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4910

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4911

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4914

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4915

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4916

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4917

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4918

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4919

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4920

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4913

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2010-4893

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4894

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4903

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4912

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.

    Published: 8 Oct 2011
    7.5
    High

    CVE-2010-4921

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action.

    Published: 8 Oct 2011
    10
    Critical

    CVE-2011-0333

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."

    Published: 8 Oct 2011
    10
    Critical

    CVE-2011-0334

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2011-1696

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.

    Published: 8 Oct 2011
    5
    Medium

    CVE-2011-2219

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2011-2661

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2011-3598

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page title, related to classes/Misc.php; or the (2) return_url or (3) return_desc parameter to display.php.

    Published: 8 Oct 2011
    5
    Medium

    CVE-2011-2218

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.

    Published: 8 Oct 2011
    4.3
    Medium

    CVE-2011-2227

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.

    Published: 8 Oct 2011
    10
    Critical

    CVE-2011-2662

    Last Modified: 11 Apr 2025

    Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.

    Published: 8 Oct 2011
    10
    Critical

    CVE-2011-2663

    Last Modified: 11 Apr 2025

    Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message.

    Published: 8 Oct 2011
    9.3
    Critical

    CVE-2011-3868

    Last Modified: 11 Apr 2025

    Buffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remote attackers to execute arbitrary code via a crafted UDF filesystem in an ISO image.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4870

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

    Published: 7 Oct 2011
    10
    Critical

    CVE-2010-4871

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4872

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4873

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4874

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim parameter.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4877

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4878

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4879

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the input_file parameter.

    Published: 7 Oct 2011