4.3
    Medium

    CVE-2011-5186

    Last Modified: 28 Oct 2012

    Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.

    Source:Robert Cooper
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5185

    Last Modified: 21 Dec 2011

    Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

    Source:M.Jock3R
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5184

    Last Modified: 12 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5) nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate. NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.

    Source:anonymous
    Published:20 Sept 2012
    7.5
    High

    CVE-2011-5183

    Last Modified: 25 Nov 2011

    Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.

    Source:muuratsalo
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5182

    Last Modified: 11 Mar 2015

    Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf.

    Source:Amir
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5181

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.

    Source:Amir
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5180

    Last Modified: 16 Mar 2015

    Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party.

    Source:Am!r
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5179

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

    Source:Amir
    Published:20 Sept 2012
    4.3
    Medium

    CVE-2011-5177

    Last Modified: 12 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort parameter to the search page.

    Source:d3v1l
    Published:20 Sept 2012
    6.8
    Medium

    CVE-2011-5173

    Last Modified: 30 Nov 2011

    Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.

    Source:Silent_Dream
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5172

    Last Modified: 1 Dec 2011

    Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file.

    Source:Nick Freeman
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5171

    Last Modified: 9 Dec 2011

    Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file.

    Source:modpr0be
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5170

    Last Modified: 3 Dec 2011

    Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.

    Source:Metasploit
    Published:15 Sept 2012
    7.5
    High

    CVE-2011-5169

    Last Modified: 27 Feb 2015

    SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.

    Source:Rem0ve
    Published:15 Sept 2012
    7.5
    High

    CVE-2011-5168

    Last Modified: 2 Oct 2011

    SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Aodrulez
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5167

    Last Modified: 22 Jun 2012

    Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.

    Source:rgod
    Published:15 Sept 2012
    7.5
    High

    CVE-2011-5166

    Last Modified: 18 Sept 2011

    Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.

    Source:loneferret
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5165

    Last Modified: 8 Dec 2016

    Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.

    Source:Richard leahy
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5164

    Last Modified: 9 Nov 2017

    Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.

    Source:Node
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2011-5162

    Last Modified: 30 Nov 2011

    Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.

    Source:Debasish Mandal
    Published:15 Sept 2012
    6.8
    Medium

    CVE-2011-5161

    Last Modified: 27 Oct 2016

    Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient directory under documents/.

    Source:Level
    Published:9 Sept 2012
    4.3
    Medium

    CVE-2011-5160

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.

    Source:Level
    Published:9 Sept 2012
    6.3
    Medium

    CVE-2011-5155

    Last Modified: 26 Dec 2014

    Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan horse ijl15.dll file in the current working directory, as demonstrated by a directory that contains a .hmxz, .hmxp, .hmskin, .hmx, .hm3, .hpj, .hlp, or .chm file. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:6 Sept 2012
    4.3
    Medium

    CVE-2011-5150

    Last Modified: 23 Dec 2011

    Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07 and possibly earlier allow remote attackers or authenticated users to inject arbitrary web script or HTML via the (1) ipaddress or (2) domain parameter to setup-network.php, different vectors than CVE-2011-5149. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Vulnerability-Lab
    Published:31 Aug 2012
    4.3
    Medium

    CVE-2011-5149

    Last Modified: 23 Dec 2011

    Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) testaddr or (2) testpass parameter to auth-settings.php; (3) hostname, (4) domainname, or (5) mailserver parameter to setup-relay.php; or (6) subnetmask or (7) defaultroute parameter to setup-network.php.

    Source:Vulnerability-Lab
    Published:31 Aug 2012
    6.8
    Medium

    CVE-2011-5148

    Last Modified: 28 Dec 2011

    Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.

    Source:gmda
    Published:31 Aug 2012
    5
    Medium

    CVE-2011-5147

    Last Modified: 17 Nov 2011

    Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier allows remote attackers to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a call to ajax_file_cut.php and then to ajax_save_name.php.

    Source:EgiX
    Published:31 Aug 2012
    7.5
    High

    CVE-2011-5140

    Last Modified: 29 Dec 2011

    Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to (a) tags.php, (b) list.php, (c) index.php, (d) main_index.php, (e) viewpost.php, (f) archive.php, (g) control/approve_comments.php, (h) control/approve_posts.php, and (i) control/viewcat.php; and the (2) month and (3) year parameters to archive.php.

    Source:snup
    Published:31 Aug 2012
    7.5
    High

    CVE-2011-5139

    Last Modified: 20 Oct 2011

    SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:dr_zig
    Published:31 Aug 2012
    6
    Medium

    CVE-2011-5135

    Last Modified: 9 Dec 2011

    Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and earlier allow remote authenticated users with admin or teacher privileges to execute arbitrary SQL commands via the (1) coursereportuiconfig[name] or (2) coursereportuiconfig[description] parameters to index.php.

    Source:mr_me
    Published:30 Aug 2012
    6.8
    Medium

    CVE-2011-5130

    Last Modified: 6 Dec 2016

    dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.

    Source:mr_me
    Published:30 Aug 2012
    5
    Medium

    CVE-2011-5129

    Last Modified: 7 Dec 2016

    Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long response string.

    Source:Jane Doe
    Published:30 Aug 2012
    10
    Critical

    CVE-2011-5127

    Last Modified: 22 Sept 2011

    Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary code, via an unspecified HTTP request.

    Source:nitr0us
    Published:26 Aug 2012
    10
    Critical

    CVE-2011-5124

    Last Modified: 10 Jul 2011

    Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp).

    Source:Metasploit
    Published:26 Aug 2012
    7.5
    High

    CVE-2011-5116

    Last Modified: 2 Nov 2011

    SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute arbitrary SQL commands via the loggedInUser cookie.

    Source:LiquidWorm
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5113

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in frontend/models/techfoliodetail.php in Techfolio (com_techfolio) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Chris Russell
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5112

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in Alameda (com_alameda) component before 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the storeid parameter to index.php.

    Source:kaMtiEz
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5111

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in Kajian Website CMS Balitbang 3.x allow remote attackers to execute arbitrary SQL commands via the hal parameter to (1) the data module in alumni.php; or the (2) lih_buku, (3) artikel, (4) album, or (5) berita module in index.php.

    Source:X-Cisadane
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5110

    Last Modified: 25 Nov 2011

    Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

    Source:muuratsalo
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5109

    Last Modified: 25 Nov 2011

    Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4) customer_list.php, and (5) task_statistics_list.php in the worldcalendar directory.

    Source:muuratsalo
    Published:23 Aug 2012
    4.3
    Medium

    CVE-2011-5108

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in config.php in AdaptCMS 2.0.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:X-Cisadane
    Published:23 Aug 2012
    4.3
    Medium

    CVE-2011-5107

    Last Modified: 11 Mar 2015

    Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:Am!r
    Published:23 Aug 2012
    4.3
    Medium

    CVE-2011-5106

    Last Modified: 10 Mar 2015

    Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Am!r
    Published:23 Aug 2012
    4.3
    Medium

    CVE-2011-5105

    Last Modified: 10 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.

    Source:James webb
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5103

    Last Modified: 25 Nov 2011

    SQL injection vulnerability in Alurian Prismotube PHP Video Script allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:longrifle0x
    Published:23 Aug 2012
    7.5
    High

    CVE-2011-5099

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:E1nzte1N
    Published:14 Aug 2012
    5
    Medium

    CVE-2011-5075

    Last Modified: 25 Nov 2011

    translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request using the save action, which reveals the installation path.

    Source:EgiX
    Published:29 Jan 2012
    6.8
    Medium

    CVE-2011-5074

    Last Modified: 1 Feb 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.

    Source:High-Tech Bridge SA
    Published:29 Jan 2012
    4.3
    Medium

    CVE-2011-5073

    Last Modified: 1 Feb 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to contact_support.php; (2) contractid parameter to contract_add_service.php; (3) user parameter to edit_backup_users.php; (4) id parameter to edit_escalation_path.php; the Referer to (5) forgotpwd.php, (6) an approvalpage action to billable_incidents.php, or (7) transactions.php; (8) action parameter to inbox.php; (9) search_string parameter in a findcontact action to incident_add.php; table1 parameter to (10) report_customers.php, (11) report_incidents_by_engineer.php, (12) report_incidents_by_site.php, or (13) report_marketing.php; or the (14) startdate or (15) enddate parameter to report_incidents_by_vendor.php.

    Source:High-Tech Bridge SA
    Published:29 Jan 2012
    7.5
    High

    CVE-2011-5072

    Last Modified: 1 Feb 2012

    Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to portal/kb.php; (2) contractid parameter to contract_add_service.php; (3) id parameter to edit_escalation_path.php; (4) unlock, (5) lock, or (6) selected parameter to holding_queue.php; inc parameter in a report action to (7) report_customers.php or (8) report_incidents_by_site.php; (9) start parameter to search.php; or (10) sites parameter to transactions.php.

    Source:High-Tech Bridge SA
    Published:29 Jan 2012