CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-2721

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary SQL commands via the artist_id parameter in an addalbum action.

    Published: 13 Jul 2010
    4.3
    Medium

    CVE-2010-2722

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to inject arbitrary web script or HTML via the artist_id parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Jul 2010
    4.3
    Medium

    CVE-2010-2715

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Published: 13 Jul 2010
    4.3
    Medium

    CVE-2010-2718

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and unspecified vectors to (3) newtelephone.php and (4) newappointment.php.

    Published: 13 Jul 2010
    2.1
    Low

    CVE-2010-2724

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.

    Published: 13 Jul 2010
    7.5
    High

    CVE-2010-2714

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL commands via the album parameter.

    Published: 13 Jul 2010
    4.3
    Medium

    CVE-2010-2723

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Jul 2010
    7.8
    High

    CVE-2010-2492

    Last Modified: 11 Apr 2025

    Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.

    Published: 13 Jul 2010
    7.5
    High

    CVE-2010-2694

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.

    Published: 12 Jul 2010
    6.5
    Medium

    CVE-2010-2695

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.

    Published: 12 Jul 2010
    7.5
    High

    CVE-2010-2696

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter.

    Published: 12 Jul 2010
    3.5
    Low

    CVE-2010-2697

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Jul 2010
    3.5
    Low

    CVE-2010-2698

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Jul 2010
    9.3
    Critical

    CVE-2010-2701

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.

    Published: 12 Jul 2010
    3.5
    Low

    CVE-2010-2448

    Last Modified: 11 Apr 2025

    znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

    Published: 12 Jul 2010
    4.3
    Medium

    CVE-2010-2700

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 12 Jul 2010
    7.5
    High

    CVE-2010-2699

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 12 Jul 2010
    9.3
    Critical

    CVE-2010-2702

    Last Modified: 11 Apr 2025

    Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL field in a WELCOME response to a download request.

    Published: 12 Jul 2010
    6.9
    Medium

    CVE-2010-0832

    Last Modified: 11 Apr 2025

    pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.

    Published: 12 Jul 2010
    4.4
    Medium

    CVE-2010-2237

    Last Modified: 11 Apr 2025

    Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.

    Published: 12 Jul 2010
    4.4
    Medium

    CVE-2010-2238

    Last Modified: 11 Apr 2025

    Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.

    Published: 12 Jul 2010
    2.1
    Low

    CVE-2010-2242

    Last Modified: 11 Apr 2025

    Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.

    Published: 12 Jul 2010
    4.4
    Medium

    CVE-2010-2239

    Last Modified: 11 Apr 2025

    Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.

    Published: 12 Jul 2010
    5.5
    Medium

    CVE-2010-5329

    Last Modified: 20 Apr 2025

    The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 relies on the count value of a v4l2_ext_controls data structure to determine a kmalloc size, which might allow local users to cause a denial of service (memory consumption) via a large value.

    Published: 12 Jul 2010
    10
    Critical

    CVE-2010-2901

    Last Modified: 11 Apr 2025

    The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 10 Jul 2010
    7.5
    High

    CVE-2010-2685

    Last Modified: 11 Apr 2025

    siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct request.

    Published: 9 Jul 2010
    6.8
    Medium

    CVE-2010-2680

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2682

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2687

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2688

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2689

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL commands via the cf_id parameter.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2690

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2691

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid parameter to products/products.php, and (3) designid parameter to designview.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2684

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Jul 2010
    7.2
    High

    CVE-2010-2489

    Last Modified: 11 Apr 2025

    Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2681

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to index.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2683

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2010-2686

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in clientes.asp in the TopManage OLK module 1.91.30 for SAP allow remote attackers to execute arbitrary SQL commands via the (1) PriceFrom, (2) PriceTo, and (3) InvFrom parameters, as reachable from olk/c_p/searchCart.asp, and other unspecified vectors when performing an advanced search. NOTE: some of these details are obtained from third party information.

    Published: 9 Jul 2010
    4.3
    Medium

    CVE-2010-2692

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in 2daybiz Custom T-Shirt Design Script allows remote attackers to inject arbitrary web script or HTML via a review comment.

    Published: 9 Jul 2010
    6.8
    Medium

    CVE-2009-4925

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

    Published: 9 Jul 2010
    4.3
    Medium

    CVE-2009-4926

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2009-4927

    Last Modified: 11 Apr 2025

    WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2009-4928

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2009-4929

    Last Modified: 11 Apr 2025

    admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.

    Published: 9 Jul 2010
    6.8
    Medium

    CVE-2009-4932

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2009-4933

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.

    Published: 9 Jul 2010
    4.3
    Medium

    CVE-2009-4934

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Published: 9 Jul 2010
    7.5
    High

    CVE-2009-4935

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter.

    Published: 9 Jul 2010
    6.8
    Medium

    CVE-2009-4931

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.

    Published: 9 Jul 2010
    4.3
    Medium

    CVE-2009-4930

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the twbkwbis.P_SecurityQuestion (aka Change Security Question) page in SunGard Banner Student System 7.4 allows remote attackers to inject arbitrary web script or HTML via the New Question field.

    Published: 9 Jul 2010