CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2010-2456

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. NOTE: this was originally reported as remote file inclusion, but this may be inaccurate.

    Published: 25 Jun 2010
    5
    Medium

    CVE-2010-2465

    Last Modified: 11 Apr 2025

    The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2457

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2458

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.

    Published: 25 Jun 2010
    7.5
    High

    CVE-2010-2459

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.

    Published: 25 Jun 2010
    7.5
    High

    CVE-2010-2460

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.

    Published: 25 Jun 2010
    7.5
    High

    CVE-2010-2461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.

    Published: 25 Jun 2010
    7.5
    High

    CVE-2010-2462

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2463

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2464

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.

    Published: 25 Jun 2010
    5
    Medium

    CVE-2010-2466

    Last Modified: 11 Apr 2025

    The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.

    Published: 25 Jun 2010
    5
    Medium

    CVE-2010-2467

    Last Modified: 11 Apr 2025

    The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.

    Published: 25 Jun 2010
    10
    Critical

    CVE-2010-2468

    Last Modified: 11 Apr 2025

    The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.

    Published: 25 Jun 2010
    5
    Medium

    CVE-2010-2469

    Last Modified: 11 Apr 2025

    The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device.

    Published: 25 Jun 2010
    5
    Medium

    CVE-2009-4904

    Last Modified: 11 Apr 2025

    article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

    Published: 25 Jun 2010
    6.8
    Medium

    CVE-2009-4906

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2009-4903

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in oBlog allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jun 2010
    6.8
    Medium

    CVE-2009-4909

    Last Modified: 11 Apr 2025

    admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.

    Published: 25 Jun 2010
    6.8
    Medium

    CVE-2009-4905

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses.

    Published: 25 Jun 2010
    6.8
    Medium

    CVE-2009-4907

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2009-4908

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (5) article_id or (6) title parameter to admin/write.php, the (7) category_id or (8) category_name parameter to admin/groups.php, the (9) blogroll_id or (10) title parameter to admin/blogroll.php, or the (11) blog_name or (12) tag_line parameter to admin/settings.php.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2454

    Last Modified: 11 Apr 2025

    Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2455

    Last Modified: 11 Apr 2025

    Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.

    Published: 25 Jun 2010
    9.3
    Critical

    CVE-2010-2434

    Last Modified: 11 Apr 2025

    Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-2444

    Last Modified: 11 Apr 2025

    parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

    Published: 25 Jun 2010
    9.8
    Critical

    CVE-2010-1205

    Last Modified: 11 Apr 2025

    Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

    Published: 25 Jun 2010
    6.5
    Medium

    CVE-2010-2249

    Last Modified: 11 Apr 2025

    Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

    Published: 25 Jun 2010
    4.3
    Medium

    CVE-2010-0778

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jun 2010
    4.3
    Medium

    CVE-2010-0779

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jun 2010
    9.3
    Critical

    CVE-2010-2440

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. NOTE: some of these details are obtained from third party information.

    Published: 24 Jun 2010
    5
    Medium

    CVE-2010-2435

    Last Modified: 11 Apr 2025

    Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.

    Published: 24 Jun 2010
    7.5
    High

    CVE-2010-2436

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

    Published: 24 Jun 2010
    4.3
    Medium

    CVE-2010-2437

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.

    Published: 24 Jun 2010
    7.5
    High

    CVE-2010-2438

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.

    Published: 24 Jun 2010
    9.3
    Critical

    CVE-2010-2439

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

    Published: 24 Jun 2010
    4.3
    Medium

    CVE-2010-2442

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."

    Published: 24 Jun 2010
    4.3
    Medium

    CVE-2010-2477

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.

    Published: 24 Jun 2010
    4.3
    Medium

    CVE-2010-2433

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-1625

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-1448

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/LXR/Common.pm in LXR Cross Referencer before 0.9.8 allows remote attackers to inject arbitrary web script or HTML via vectors related to a string in the search page's TITLE element, a different vulnerability than CVE-2009-4497 and CVE-2010-1625.

    Published: 23 Jun 2010
    6.5
    Medium

    CVE-2010-2425

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.

    Published: 23 Jun 2010
    4
    Medium

    CVE-2010-2426

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via "..//" sequences in the xcrc command.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-2428

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-2429

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-2244

    Last Modified: 11 Apr 2025

    The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-2481

    Last Modified: 11 Apr 2025

    The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.

    Published: 23 Jun 2010
    4.3
    Medium

    CVE-2010-2480

    Last Modified: 11 Apr 2025

    Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

    Published: 23 Jun 2010
    5
    Medium

    CVE-2010-1751

    Last Modified: 11 Apr 2025

    Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to obtain location information via unspecified vectors.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-1755

    Last Modified: 11 Apr 2025

    Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.

    Published: 22 Jun 2010
    5.8
    Medium

    CVE-2010-1756

    Last Modified: 11 Apr 2025

    The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick users into communicating over an unintended network.

    Published: 22 Jun 2010