9.3
    Critical

    CVE-2011-4876

    Last Modified: 28 Nov 2011

    Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

    Source:Luigi Auriemma
    Published:3 Feb 2012
    9.3
    Critical

    CVE-2011-4875

    Last Modified: 28 Nov 2011

    Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.

    Source:Luigi Auriemma
    Published:3 Feb 2012
    5
    Medium

    CVE-2011-4871

    Last Modified: 10 Oct 2011

    Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port 58723.

    Source:Luigi Auriemma
    Published:18 Apr 2012
    10
    Critical

    CVE-2011-4862

    Last Modified: 14 Jan 2012

    Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.

    Source:Metasploit
    Published:25 Dec 2011
    5
    Medium

    CVE-2011-4858

    Last Modified: 9 Nov 2016

    Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Source:rgod
    Published:28 Dec 2011
    6.8
    Medium

    CVE-2011-4837

    Last Modified: 13 Oct 2012

    Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

    Source:Silent_Dream
    Published:15 Dec 2011
    4.3
    Medium

    CVE-2011-4836

    Last Modified: 19 Mar 2015

    Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI.

    Source:Silent Dream
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4835

    Last Modified: 13 Oct 2012

    Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via unspecified vectors.

    Source:Silent_Dream
    Published:15 Dec 2011
    4.6
    Medium

    CVE-2011-4834

    Last Modified: 19 Mar 2015

    The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.

    Source:anonymous
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4833

    Last Modified: 16 Mar 2015

    Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.

    Source:High-Tech Bridge SA
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4832

    Last Modified: 3 Nov 2011

    Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

    Source:Rami Salama
    Published:15 Dec 2011
    4
    Medium

    CVE-2011-4831

    Last Modified: 3 Nov 2011

    Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.

    Source:Sangyun YOO
    Published:15 Dec 2011
    3.5
    Low

    CVE-2011-4830

    Last Modified: 29 Oct 2011

    Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka Website Address), (4) paystring (aka Payment types accepted), (5) sell_price, (6) shipping_cost, and (7) quantity parameters to index.php.

    Source:Chris Russell
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4829

    Last Modified: 29 Oct 2011

    SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to index.php.

    Source:Chris Russell
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4828

    Last Modified: 14 Apr 2012

    Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.

    Source:Metasploit
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4825

    Last Modified: 5 Nov 2011

    Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

    Source:EgiX
    Published:15 Dec 2011
    7.5
    High

    CVE-2011-4823

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.

    Source:the_cyber_nuxbie
    Published:15 Dec 2011
    4.3
    Medium

    CVE-2011-4814

    Last Modified: 7 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.

    Source:High-Tech Bridge SA
    Published:14 Dec 2011
    5
    Medium

    CVE-2011-4813

    Last Modified: 3 May 2018

    Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invalid action and a ../ (dot dot slash) in the templatefile parameter.

    Source:red virus
    Published:14 Dec 2011
    4.3
    Medium

    CVE-2011-4812

    Last Modified: 2 Nov 2011

    Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web script or HTML via the str parameter.

    Source:CoBRa_21
    Published:14 Dec 2011
    7.5
    High

    CVE-2011-4811

    Last Modified: 2 Nov 2011

    SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter.

    Source:CoBRa_21
    Published:14 Dec 2011
    5
    Medium

    CVE-2011-4810

    Last Modified: 7 Nov 2011

    Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2) downloads.php, and (3) the report parameter to admin/reports.php.

    Source:ZxH-Labs
    Published:14 Dec 2011
    4.3
    Medium

    CVE-2011-4809

    Last Modified: 19 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8) movies[], (9) games[], (10) syp[], (11) ft[], and (12) fa[] parameters in a save task for a profile to index.php. NOTE: some of these details are obtained from third party information.

    Source:599eme Man
    Published:14 Dec 2011
    7.5
    High

    CVE-2011-4808

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php.

    Source:599eme Man
    Published:14 Dec 2011
    5
    Medium

    CVE-2011-4807

    Last Modified: 29 Oct 2011

    Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the var1 parameter.

    Source:BHG Security Center
    Published:14 Dec 2011
    4.3
    Medium

    CVE-2011-4806

    Last Modified: 29 Oct 2011

    Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) var1 and (2) keyword parameters.

    Source:BHG Security Center
    Published:14 Dec 2011
    5
    Medium

    CVE-2011-4804

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:the_cyber_nuxbie
    Published:14 Dec 2011
    7.5
    High

    CVE-2011-4803

    Last Modified: 27 Oct 2011

    SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:longrifle0x
    Published:14 Dec 2011
    6.5
    Medium

    CVE-2011-4802

    Last Modified: 13 Jul 2018

    Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php.

    Source:High-Tech Bridge SA
    Published:14 Dec 2011
    7.5
    High

    CVE-2011-4801

    Last Modified: 6 Nov 2017

    SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Jose Carlos de Arriba
    Published:14 Dec 2011
    9
    Critical

    CVE-2011-4800

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directories, via a "..:/" (dot dot colon forward slash) in the (1) list, (2) put, or (3) get commands.

    Source:kingcope
    Published:14 Dec 2011
    10
    Critical

    CVE-2011-4789

    Last Modified: 27 Jan 2012

    Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is actually HP LoadRunner."

    Source:Metasploit
    Published:13 Jan 2012
    9.3
    Critical

    CVE-2011-4786

    Last Modified: 18 Jan 2012

    A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-2404 and CVE-2011-4787.

    Source:Metasploit
    Published:12 Jan 2012
    Low

    CVE-2011-4779

    Last Modified: 4 Dec 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4642. Reason: This candidate is a reservation duplicate of CVE-2011-4642. Notes: All CVE users should reference CVE-2011-4642 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Gary O'Leary-Steele
    Published:20 Dec 2011
    7.8
    High

    CVE-2011-4722

    Last Modified: 3 Dec 2011

    Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

    Source:SecPod Research
    Published:28 Dec 2014
    5
    Medium

    CVE-2011-4720

    Last Modified: 3 Dec 2011

    Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.

    Source:SecPod Research
    Published:28 Dec 2014
    5.5
    Medium

    CVE-2011-4717

    Last Modified: 11 Dec 2011

    Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (aka rmdir) command.

    Source:Stefan Schurtz
    Published:20 Dec 2011
    5
    Medium

    CVE-2011-4716

    Last Modified: 24 Jul 2011

    Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file parameter.

    Source:ShellVision
    Published:8 Dec 2011
    5
    Medium

    CVE-2011-4715

    Last Modified: 21 Dec 2011

    Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

    Source:Akin Tosunlar
    Published:8 Dec 2011
    5
    Medium

    CVE-2011-4714

    Last Modified: 16 Mar 2015

    Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \.. (backslash dot dot) in the URL.

    Source:Nick Freeman
    Published:8 Dec 2011
    5
    Medium

    CVE-2011-4713

    Last Modified: 13 Nov 2011

    Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.

    Source:Stefan Schurtz
    Published:8 Dec 2011
    5
    Medium

    CVE-2011-4712

    Last Modified: 16 Mar 2015

    Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.

    Source:demonalex
    Published:8 Dec 2011
    7.5
    High

    CVE-2011-4710

    Last Modified: 25 Nov 2011

    Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.

    Source:Piranha
    Published:8 Dec 2011
    4.3
    Medium

    CVE-2011-4709

    Last Modified: 9 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search parameters to index.php. NOTE: some of these details are obtained from third party information.

    Source:Gjoko Krstic
    Published:8 Dec 2011
    10
    Critical

    CVE-2011-4684

    Last Modified: 23 Mar 2015

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

    Source:anonymous
    Published:7 Dec 2011
    7.5
    High

    CVE-2011-4674

    Last Modified: 24 Jul 2012

    SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.

    Source:Marcio Almeida
    Published:2 Dec 2011
    7.5
    High

    CVE-2011-4673

    Last Modified: 25 Nov 2011

    SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:longrifle0x
    Published:2 Dec 2011
    7.5
    High

    CVE-2011-4672

    Last Modified: 25 Nov 2011

    Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncategory_list.php, (3) _rantevou_list.php, (4) syncategory_list.php, (5) synallasomenos_list.php, (6) ypelaton_list.php, and (7) yproion_list.php.

    Source:muuratsalo
    Published:2 Dec 2011
    7.5
    High

    CVE-2011-4671

    Last Modified: 24 Sept 2011

    SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).

    Source:Miroslav Stampar
    Published:2 Dec 2011
    4.3
    Medium

    CVE-2011-4670

    Last Modified: 4 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView action, (3) contact_id and (4) parent_id parameters in an EditView action, (5) day, (6) month, (7) subtab, (8) view, and (9) viewOption parameters in the index action, and (10) start parameter in the ListView action to the Calendar module; (11) return_action and (12) return_module parameters in the EditView action, and (13) query parameter in an index action to the Campaigns module; (14) return_url and (15) workflow_id parameters in an editworkflow action to the com_vtiger_workflow module; (16) display_view parameter in an index action to the Dashboard module; (17) closingdate_end, (18) closingdate_start, (19) date_closed, (20) owner, (21) leadsource, (22) sales_stage, and (23) type parameters in a ListView action to the Potentials module; (24) folderid parameter in a SaveandRun action to the Reports module; (25) returnaction and (26) groupId parameters in a createnewgroup action, (27) mode and (28) parent parameters in a createrole action, (29) src_module in a ModuleManager action, (30) mode and (31) profile_id parameters in a profilePrivileges action, and (32) roleid parameter in a RoleDetailView to the Settings module; and (33) action parameter to the Home module and (34) module parameter to phprint.php.

    Source:Aung Khant
    Published:2 Dec 2011