CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2010-1920

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1923

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1924

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1925

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1927

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) bible.class.php, (2) dossier.class.php, (3) service.class.php, (4) collectivite.class.php, (5) droit.class.php, (6) tache.class.php, (7) emetteur.class.php, (8) utilisateur.class.php, (9) courrier.recherche.tab.class.php, and (10) profil.class.php in obj/. NOTE: some of these details are obtained from third party information.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1928

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1935

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1936

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1926

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069. NOTE: some of these details are obtained from third party information.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1934

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) categorie.class.php, (2) profil.class.php, (3) collectivite.class.php, (4) ressource.class.php, (5) droit.class.php, (6) utilisateur.class.php, and (7) planning.class.php in obj/.

    Published: 12 May 2010
    6.8
    Medium

    CVE-2010-1921

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) annuaire.class.php, (2) droit.class.php, (3) collectivite.class.php, (4) profil.class.php, (5) direction.class.php, (6) service.class.php, (7) directiongenerale.class.php, and (8) utilisateur.class.php in obj/.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1922

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php, and (4) layoutParser.php in lib/layout/.

    Published: 12 May 2010
    4.3
    Medium

    CVE-2010-1482

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.

    Published: 12 May 2010
    4.9
    Medium

    CVE-2010-1457

    Last Modified: 11 Apr 2025

    Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message.

    Published: 12 May 2010
    7.2
    High

    CVE-2010-1620

    Last Modified: 11 Apr 2025

    Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.

    Published: 12 May 2010
    9.3
    Critical

    CVE-2010-0815

    Last Modified: 11 Apr 2025

    VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."

    Published: 12 May 2010
    9.3
    Critical

    CVE-2010-0816

    Last Modified: 11 Apr 2025

    Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."

    Published: 12 May 2010
    5
    Medium

    CVE-2010-1635

    Last Modified: 11 Apr 2025

    The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.

    Published: 12 May 2010
    5
    Medium

    CVE-2010-1642

    Last Modified: 11 Apr 2025

    The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1918

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.

    Published: 12 May 2010
    5
    Medium

    CVE-2010-1624

    Last Modified: 11 Apr 2025

    The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.

    Published: 12 May 2010
    7.5
    High

    CVE-2010-1916

    Last Modified: 11 Apr 2025

    The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.

    Published: 12 May 2010
    5
    Medium

    CVE-2010-2093

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction occurs.

    Published: 12 May 2010
    3.5
    Low

    CVE-2010-1481

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.

    Published: 11 May 2010
    4.3
    Medium

    CVE-2010-1905

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.

    Published: 11 May 2010
    7.2
    High

    CVE-2010-1906

    Last Modified: 11 Apr 2025

    tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

    Published: 11 May 2010
    4.3
    Medium

    CVE-2010-1907

    Last Modified: 11 Apr 2025

    The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.

    Published: 11 May 2010
    5.1
    Medium

    CVE-2010-1910

    Last Modified: 11 Apr 2025

    The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1911

    Last Modified: 11 Apr 2025

    The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1912

    Last Modified: 11 Apr 2025

    The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on ActiveX execution via "instantiation/free attacks."

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1913

    Last Modified: 11 Apr 2025

    The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.

    Published: 11 May 2010
    7.6
    High

    CVE-2010-1909

    Last Modified: 11 Apr 2025

    Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving "CreateProcess params." NOTE: some of these details are obtained from third party information.

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1908

    Last Modified: 11 Apr 2025

    The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1) HTTPDownloadFile or (2) HTTPGetFile.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1876

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1874

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1877

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1878

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1873

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 11 May 2010
    7.5
    High

    CVE-2010-1875

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 11 May 2010
    4.3
    Medium

    CVE-2010-1872

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1628

    Last Modified: 11 Apr 2025

    Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.

    Published: 11 May 2010
    9.3
    Critical

    CVE-2010-1869

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.

    Published: 11 May 2010
    5
    Medium

    CVE-2010-1917

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (PHP crash) via a crafted first argument to the fnmatch function, as demonstrated using a long string.

    Published: 11 May 2010
    7.5
    High

    CVE-2009-4855

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid parameter is generally used in third-party TYPO3 extensions - not in TYPO3 Core.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4857

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4858

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4859

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Online Work Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) default.asp and (2) report.asp, and the (3) go parameter to login.asp.

    Published: 10 May 2010
    7.5
    High

    CVE-2009-4860

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idTableProduit parameter.

    Published: 10 May 2010
    9.3
    Critical

    CVE-2009-4863

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file.

    Published: 10 May 2010
    6.8
    Medium

    CVE-2009-4865

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.

    Published: 10 May 2010