7.5
    High

    CVE-2011-5071

    Last Modified: 4 Feb 2015

    Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.

    Source:Yuri Goltsev
    Published:29 Jan 2012
    5
    Medium

    CVE-2011-5057

    Last Modified: 19 Mar 2015

    Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."

    Source:Hisato Killing
    Published:21 Dec 2011
    5.8
    Medium

    CVE-2011-5053

    Last Modified: 30 Dec 2011

    The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.

    Source:cheffner
    Published:6 Jan 2012
    6.8
    Medium

    CVE-2011-5052

    Last Modified: 30 Dec 2011

    Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long response to a download request.

    Source:Fady Mohammed Osman
    Published:4 Jan 2012
    6
    Medium

    CVE-2011-5050

    Last Modified: 23 Mar 2015

    SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information.

    Source:Benjamin Kunz Mejri
    Published:4 Jan 2012
    4.3
    Medium

    CVE-2011-5049

    Last Modified: 24 Dec 2011

    MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.

    Source:Level
    Published:4 Jan 2012
    9.3
    Critical

    CVE-2011-5046

    Last Modified: 25 Dec 2011

    The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."

    Source:webDEViL
    Published:30 Dec 2011
    4.3
    Medium

    CVE-2011-5045

    Last Modified: 23 Mar 2015

    Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.

    Source:G13
    Published:30 Dec 2011
    7.2
    High

    CVE-2011-5044

    Last Modified: 5 Dec 2011

    SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program.

    Source:LiquidWorm
    Published:30 Dec 2011
    4.3
    Medium

    CVE-2011-5043

    Last Modified: 19 Dec 2011

    TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.

    Source:JaMbA
    Published:30 Dec 2011
    4.3
    Medium

    CVE-2011-5041

    Last Modified: 20 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action and (2) post_id parameter in an edit-post action to index.php.

    Source:Avram Marius
    Published:30 Dec 2011
    4.3
    Medium

    CVE-2011-5040

    Last Modified: 21 Dec 2011

    Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php.

    Source:LiquidWorm
    Published:30 Dec 2011
    7.5
    High

    CVE-2011-5039

    Last Modified: 21 Dec 2011

    Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.

    Source:LiquidWorm
    Published:30 Dec 2011
    5
    Medium

    CVE-2011-5035

    Last Modified: 9 Nov 2016

    Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.

    Source:rgod
    Published:28 Dec 2011
    5.3
    Medium

    CVE-2011-5034

    Last Modified: 9 Nov 2016

    Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

    Source:rgod
    Published:29 Dec 2011
    4.4
    Medium

    CVE-2011-5033

    Last Modified: 7 Mar 2019

    Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.

    Source:FoX HaCkEr
    Published:29 Dec 2011
    7.5
    High

    CVE-2011-5031

    Last Modified: 16 Dec 2011

    Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) dfuserid and (2) dfpassword parameters. NOTE: some of these details are obtained from third party information.

    Source:D1rt3 Dud3
    Published:29 Dec 2011
    4
    Medium

    CVE-2011-5028

    Last Modified: 5 Sept 2012

    Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel before 7.0.1.0, allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Andrea Fabrizi
    Published:29 Dec 2011
    4.3
    Medium

    CVE-2011-5026

    Last Modified: 29 Dec 2011

    Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:G13
    Published:29 Dec 2011
    4.3
    Medium

    CVE-2011-5025

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

    Source:Michael Brooks
    Published:29 Dec 2011
    4.3
    Medium

    CVE-2011-5023

    Last Modified: 26 Mar 2015

    Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.

    Source:SiteWatch
    Published:29 Dec 2011
    7.5
    High

    CVE-2011-5022

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.

    Source:SiteWatch
    Published:29 Dec 2011
    4.3
    Medium

    CVE-2011-5019

    Last Modified: 25 Mar 2015

    Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

    Source:Jonathan Claudius
    Published:5 Jan 2012
    10
    Critical

    CVE-2011-5012

    Last Modified: 16 Nov 2011

    Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.

    Source:Francis Provencher
    Published:25 Dec 2011
    10
    Critical

    CVE-2011-5010

    Last Modified: 30 Nov 2011

    apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.

    Source:Metasploit
    Published:25 Dec 2011
    5
    Medium

    CVE-2011-5009

    Last Modified: 16 Mar 2015

    The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

    Source:Luigi Auriemma
    Published:25 Dec 2011
    10
    Critical

    CVE-2011-5007

    Last Modified: 16 Nov 2017

    Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

    Source:Celil Ünüver
    Published:25 Dec 2011
    9.3
    Critical

    CVE-2011-5006

    Last Modified: 26 Nov 2011

    Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file.

    Source:hellok
    Published:25 Dec 2011
    7.5
    High

    CVE-2011-5005

    Last Modified: 17 Nov 2011

    Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

    Source:PCA
    Published:25 Dec 2011
    10
    Critical

    CVE-2011-5003

    Last Modified: 4 Dec 2011

    Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.

    Source:Nick Freeman
    Published:25 Dec 2011
    10
    Critical

    CVE-2011-5002

    Last Modified: 1 Dec 2011

    Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.

    Source:Nick Freeman
    Published:25 Dec 2011
    10
    Critical

    CVE-2011-5001

    Last Modified: 23 Feb 2012

    Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

    Source:Metasploit
    Published:25 Dec 2011
    4.3
    Medium

    CVE-2011-4958

    Last Modified: 24 Sept 2018

    Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.

    Source:Stefan Schurtz
    Published:8 Apr 2014
    7.5
    High

    CVE-2011-4929

    Last Modified: 23 Mar 2017

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

    Source:Metasploit
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2011-4926

    Last Modified: 11 Mar 2015

    Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Am!r
    Published:29 Aug 2012
    7.5
    High

    CVE-2011-4919

    Last Modified: 21 Nov 2024

    mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

    Published:19 Nov 2019
    4.3
    Medium

    CVE-2011-4918

    Last Modified: 16 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to inject arbitrary web script or HTML via the (1) task parameter to elxis/index.php, and (2) PATH_INFO to elxis/administrator/index.php.

    Source:Ewerson Guimaraes
    Published:29 Aug 2012
    4.3
    Medium

    CVE-2011-4909

    Last Modified: 28 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.

    Source:Juan Galiana Lara
    Published:7 Oct 2012
    9.8
    Critical

    CVE-2011-4908

    Last Modified: 21 Nov 2024

    TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

    Source:spinbad
    Published:12 Feb 2020
    9.8
    Critical

    CVE-2011-4906

    Last Modified: 3 Nov 2016

    Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

    Source:daath
    Published:12 Feb 2020
    7.5
    High

    CVE-2011-4899

    Last Modified: 4 May 2017

    wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments

    Source:Trustwave's SpiderLabs
    Published:30 Jan 2012
    5
    Medium

    CVE-2011-4898

    Last Modified: 4 May 2017

    wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

    Source:Trustwave's SpiderLabs
    Published:30 Jan 2012
    5
    Medium

    CVE-2011-4885

    Last Modified: 1 Dec 2016

    PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Source:infodox
    Published:28 Dec 2011
    5
    Medium

    CVE-2011-4883

    Last Modified: 10 Oct 2011

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers to cause a denial of service (resource consumption) via a crafted request.

    Source:Luigi Auriemma
    Published:13 Apr 2012
    5
    Medium

    CVE-2011-4882

    Last Modified: 10 Oct 2011

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unspecified command in an HTTP request.

    Source:Luigi Auriemma
    Published:13 Apr 2012
    5
    Medium

    CVE-2011-4881

    Last Modified: 10 Oct 2011

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted HTTP request.

    Source:Luigi Auriemma
    Published:13 Apr 2012
    5
    Medium

    CVE-2011-4880

    Last Modified: 10 Oct 2011

    Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary files via a crafted HTTP request.

    Source:Luigi Auriemma
    Published:13 Apr 2012
    8.5
    High

    CVE-2011-4879

    Last Modified: 28 Nov 2011

    miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not properly handle URIs beginning with a 0xfa character, which allows remote attackers to read data from arbitrary memory locations or cause a denial of service (application crash) via a crafted POST request.

    Source:Luigi Auriemma
    Published:3 Feb 2012
    7.8
    High

    CVE-2011-4878

    Last Modified: 28 Nov 2011

    Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.

    Source:Luigi Auriemma
    Published:3 Feb 2012
    7.1
    High

    CVE-2011-4877

    Last Modified: 28 Nov 2011

    HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP.

    Source:Luigi Auriemma
    Published:3 Feb 2012