CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-4880

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to inject arbitrary web script or HTML via the (1) category_name, (2) category_description, (3) event_name, or (4) event_description parameter.

    Published: 7 Oct 2011
    6.8
    Medium

    CVE-2010-4881

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the authentication of unspecified victims for requests that use the (1) category_name, (2) category_description, (3) event_name, or (4) event_description parameter.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4882

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web script or HTML via the sitetitle parameter.

    Published: 7 Oct 2011
    2.6
    Low

    CVE-2010-4883

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4888

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Oct 2011
    10
    Critical

    CVE-2010-4889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4890

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4891

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4892

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the powermail extension before 1.5.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4876

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4886

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "official twitter tweet button for your page" (tweetbutton) extension before 1.0.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4887

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4885

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the XING Button (xing) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Oct 2011
    4.3
    Medium

    CVE-2010-4875

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.

    Published: 7 Oct 2011
    7.5
    High

    CVE-2010-4884

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.

    Published: 7 Oct 2011
    6.8
    Medium

    CVE-2011-2191

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.

    Published: 7 Oct 2011
    2.1
    Low

    CVE-2011-2190

    Last Modified: 11 Apr 2025

    The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.

    Published: 7 Oct 2011
    5.3
    Medium

    CVE-2011-3624

    Last Modified: 21 Nov 2024

    Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.

    Published: 7 Oct 2011
    10
    Critical

    CVE-2011-3332

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Iceni Argus 6.20 and earlier and Infix 5.04 allows remote attackers to execute arbitrary code via a crafted PDF document that uses flate compression.

    Published: 6 Oct 2011
    7.5
    High

    CVE-2011-3288

    Last Modified: 11 Apr 2025

    Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug IDs CSCtq89842 and CSCtq88547, a similar issue to CVE-2003-1564.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3296

    Last Modified: 11 Apr 2025

    Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when IPv6 is used, allows remote attackers to cause a denial of service (memory corruption and module crash or hang) via vectors that trigger syslog message 302015, aka Bug ID CSCti83875.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3297

    Last Modified: 11 Apr 2025

    Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many authentication requests for network access, aka Bug ID CSCtn15697.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3301

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 and 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2.6), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to cause a denial of service (device reload) via crafted SunRPC traffic, aka Bug IDs CSCtq06062 and CSCtq09986.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3303

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.6), 8.3 before 8.3(2.23), 8.4 before 8.4(2.7), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to cause a denial of service (device reload) via malformed ILS traffic, aka Bug IDs CSCtq57697 and CSCtq57802.

    Published: 6 Oct 2011
    7.9
    High

    CVE-2011-3298

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 before 8.3(2.18), 8.4 before 8.4(1.10), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to bypass authentication via a crafted TACACS+ reply, aka Bug IDs CSCto40365 and CSCto74274.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3299

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 and 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2.6), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to cause a denial of service (device reload) via crafted SunRPC traffic, aka Bug IDs CSCto92380 and CSCtq09972.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3300

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 and 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2.6), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to cause a denial of service (device reload) via crafted SunRPC traffic, aka Bug IDs CSCtq06065 and CSCtq09978.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3302

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 and 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2.6), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to cause a denial of service (device reload) via crafted SunRPC traffic, aka Bug IDs CSCto92398 and CSCtq09989.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3305

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read arbitrary files via crafted traffic to TCP port 443, aka Bug ID CSCtq10755.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3287

    Last Modified: 11 Apr 2025

    Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug ID CSCtq78106, a similar issue to CVE-2003-1564.

    Published: 6 Oct 2011
    7.8
    High

    CVE-2011-3304

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.2 before 7.2(5.3), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 before 8.4(2), and 8.5 before 8.5(1.1) allow remote attackers to cause a denial of service (device reload) via crafted MSN Instant Messenger traffic, aka Bug ID CSCtl67486.

    Published: 6 Oct 2011
    4
    Medium

    CVE-2011-4079

    Last Modified: 11 Apr 2025

    Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.

    Published: 6 Oct 2011
    7.5
    High

    CVE-2010-4853

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.

    Published: 5 Oct 2011
    6.8
    Medium

    CVE-2010-4854

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ajax/coupon.php in Zuitu 1.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a consume action.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4855

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4856

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

    Published: 5 Oct 2011
    5
    Medium

    CVE-2010-4858

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4859

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in WebAsyst Shop-Script allows remote attackers to execute arbitrary SQL commands via the blog_id parameter in a news action.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4860

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4861

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4862

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

    Published: 5 Oct 2011
    4.3
    Medium

    CVE-2010-4863

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4864

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4867

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4869

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4866

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4857

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2010-4865

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.

    Published: 5 Oct 2011
    4.3
    Medium

    CVE-2010-4868

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.

    Published: 5 Oct 2011
    2.1
    Low

    CVE-2011-3982

    Last Modified: 11 Apr 2025

    The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.

    Published: 5 Oct 2011