CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-1015

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SAV Filter Alphabetic (sav_filter_abc) extension before 1.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1016

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SAV Filter Selectors (sav_filter_selectors) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1017

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SAV Filter Months (sav_filter_months) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1018

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1019

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    4.3
    Medium

    CVE-2010-1020

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Mar 2010
    4.3
    Medium

    CVE-2010-1021

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Typo3 Quixplorer (t3quixplorer) extension before 1.7.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1022

    Last Modified: 11 Apr 2025

    The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.

    Published: 19 Mar 2010
    4.3
    Medium

    CVE-2010-1023

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the UserTask Center, Recent (taskcenter_recent) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1024

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    4.3
    Medium

    CVE-2010-1025

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1026

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.5
    High

    CVE-2010-1027

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Meet Travelmates (travelmate) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2010
    7.9
    High

    CVE-2010-4263

    Last Modified: 11 Apr 2025

    The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via a VLAN tagged frame.

    Published: 19 Mar 2010
    Unknown

    CVE-2010-0735

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-0969. Reason: This candidate is a duplicate of CVE-2010-0969. Notes: All CVE users should reference CVE-2010-0969 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4720

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4721

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information.

    Published: 18 Mar 2010
    6.8
    Medium

    CVE-2009-4722

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the CheckLogin function in includes/functions.php in Limny 1.01, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4723

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 18 Mar 2010
    5
    Medium

    CVE-2009-4726

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4727

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4730

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4731

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4734

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login.php in Allomani Movies Library (Movies & Clips) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4735

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login.php in Allomani Audio & Video Library (Songs & Clips version) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Published: 18 Mar 2010
    5.1
    Medium

    CVE-2009-4725

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4728

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Mar 2010
    6.8
    Medium

    CVE-2009-4733

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4724

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2009-4719

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Discloser 0.0.4 rc2 allows remote attackers to execute arbitrary SQL commands via the more parameter.

    Published: 18 Mar 2010
    4.3
    Medium

    CVE-2009-4729

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php.

    Published: 18 Mar 2010
    6.8
    Medium

    CVE-2009-4732

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in tt/index.php in TT Web Site Manager 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tt_name parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Mar 2010
    10
    Critical

    CVE-2010-0104

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 18 Mar 2010
    8
    High

    CVE-2010-0737

    Last Modified: 21 Nov 2024

    A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

    Published: 18 Mar 2010
    7.5
    High

    CVE-2010-0980

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0976

    Last Modified: 11 Apr 2025

    Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts. NOTE: the final installation screen states "Important: you must now delete all files beginning with 'install' from the root directory."

    Published: 16 Mar 2010
    5
    Medium

    CVE-2010-0977

    Last Modified: 11 Apr 2025

    PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.

    Published: 16 Mar 2010
    5
    Medium

    CVE-2010-0978

    Last Modified: 11 Apr 2025

    KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.

    Published: 16 Mar 2010
    4.3
    Medium

    CVE-2010-0979

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0981

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.

    Published: 16 Mar 2010
    4.3
    Medium

    CVE-2010-0982

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 16 Mar 2010
    6.8
    Medium

    CVE-2010-0983

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156.

    Published: 16 Mar 2010
    5
    Medium

    CVE-2010-0984

    Last Modified: 11 Apr 2025

    Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0985

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 16 Mar 2010
    4.7
    Medium

    CVE-2007-6733

    Last Modified: 11 Apr 2025

    The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on an NFS filesystem and then changing this file's permissions, a related issue to CVE-2010-0727.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0793

    Last Modified: 11 Apr 2025

    Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.

    Published: 16 Mar 2010
    4.3
    Medium

    CVE-2010-0963

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID. NOTE: some of these details are obtained from third party information.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0964

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in start.php in Eros Webkatalog allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

    Published: 16 Mar 2010
    5
    Medium

    CVE-2010-0965

    Last Modified: 11 Apr 2025

    Jevci Siparis Formu Scripti stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for siparis.mdb.

    Published: 16 Mar 2010
    6.8
    Medium

    CVE-2010-0966

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

    Published: 16 Mar 2010