9.3
    Critical

    CVE-2011-4644

    Last Modified: 4 Dec 2016

    Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.

    Source:Gary O'Leary-Steele
    Published:3 Jan 2012
    4
    Medium

    CVE-2011-4643

    Last Modified: 4 Dec 2016

    Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.

    Source:Gary O'Leary-Steele
    Published:3 Jan 2012
    4.6
    Medium

    CVE-2011-4642

    Last Modified: 4 Dec 2016

    mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.

    Source:Gary O'Leary-Steele
    Published:3 Jan 2012
    4
    Medium

    CVE-2011-4640

    Last Modified: 23 Aug 2015

    Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname parameter in a view action.

    Source:Richard Conner
    Published:8 Oct 2012
    9.3
    Critical

    CVE-2011-4620

    Last Modified: 21 Dec 2011

    Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.

    Source:Andrés Gómez
    Published:31 Dec 2011
    4.3
    Medium

    CVE-2011-4618

    Last Modified: 11 Mar 2015

    Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Amir
    Published:24 Jan 2013
    6.8
    Medium

    CVE-2011-4614

    Last Modified: 4 Jan 2012

    PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP code via a URL in the BACK_PATH parameter.

    Source:MaXe
    Published:18 Feb 2012
    5.9
    Medium

    CVE-2011-4613

    Last Modified: 25 Jan 2018

    The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.

    Source:vladz
    Published:15 Dec 2011
    6.1
    Medium

    CVE-2011-4595

    Last Modified: 16 Mar 2015

    Pretty-Link WordPress plugin 1.5.2 has XSS

    Source:Am!r
    Published:10 Jan 2020
    4.3
    Medium

    CVE-2011-4572

    Last Modified: 4 Oct 2011

    Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate.

    Source:bd0rk
    Published:29 Nov 2011
    7.5
    High

    CVE-2011-4571

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php.

    Source:xDarkSton3x
    Published:29 Nov 2011
    7.5
    High

    CVE-2011-4570

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php.

    Source:kaMtiEz
    Published:29 Nov 2011
    7.5
    High

    CVE-2011-4569

    Last Modified: 13 Oct 2011

    SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.

    Source:Mario_Vs
    Published:29 Nov 2011
    4.3
    Medium

    CVE-2011-4567

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.

    Source:RPinto
    Published:29 Nov 2011
    4.3
    Medium

    CVE-2011-4564

    Last Modified: 1 Mar 2015

    Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter in a module action.

    Source:Stefan Schurtz
    Published:28 Nov 2011
    4.3
    Medium

    CVE-2011-4561

    Last Modified: 27 Feb 2015

    Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.

    Source:Stefan Schurtz
    Published:28 Nov 2011
    7.5
    High

    CVE-2011-4559

    Last Modified: 4 Oct 2017

    SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.

    Source:Aung Khant
    Published:28 Nov 2011
    7.2
    High

    CVE-2011-4558

    Last Modified: 22 Apr 2015

    Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

    Source:EgiX
    Published:27 Jan 2020
    4.3
    Medium

    CVE-2011-4551

    Last Modified: 23 Mar 2015

    Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

    Source:Stefan Schurtz
    Published:1 Oct 2012
    5
    Medium

    CVE-2011-4545

    Last Modified: 12 Mar 2015

    CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name parameter.

    Source:RGouveia
    Published:2 Dec 2011
    4.3
    Medium

    CVE-2011-4544

    Last Modified: 12 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) address or (2) relativ_base_dir parameter to modules/mondialrelay/googlemap.php; the (3) relativ_base_dir, (4) Pays, (5) Ville, (6) CP, (7) Poids, (8) Action, or (9) num parameter to prestashop/modules/mondialrelay/googlemap.php; (10) the num_mode parameter to modules/mondialrelay/kit_mondialrelay/RechercheDetailPointRelais_ajax.php; (11) the Expedition parameter to modules/mondialrelay/kit_mondialrelay/SuiviExpedition_ajax.php; or the (12) folder or (13) name parameter to admin/ajaxfilemanager/ajax_save_text.php.

    Source:Prestashop
    Published:1 Dec 2011
    7.5
    High

    CVE-2011-4542

    Last Modified: 12 Jul 2012

    Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.

    Source:Metasploit
    Published:30 Nov 2011
    4.3
    Medium

    CVE-2011-4541

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action.

    Source:HTrovao
    Published:29 Nov 2011
    4.3
    Medium

    CVE-2011-4540

    Last Modified: 16 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ldap.php or (2) search.php.

    Source:Dognædis
    Published:1 Dec 2011
    6.8
    Medium

    CVE-2011-4535

    Last Modified: 12 Sept 2011

    Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.

    Source:mr_me
    Published:3 Apr 2012
    5
    Medium

    CVE-2011-4532

    Last Modified: 28 Nov 2011

    Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.

    Source:Luigi Auriemma
    Published:8 Jan 2012
    5
    Medium

    CVE-2011-4531

    Last Modified: 28 Nov 2011

    Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command.

    Source:Luigi Auriemma
    Published:8 Jan 2012
    5
    Medium

    CVE-2011-4530

    Last Modified: 28 Nov 2011

    Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.

    Source:Luigi Auriemma
    Published:8 Jan 2012
    7.5
    High

    CVE-2011-4529

    Last Modified: 28 Nov 2011

    Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.

    Source:Luigi Auriemma
    Published:8 Jan 2012
    4.3
    Medium

    CVE-2011-4520

    Last Modified: 31 Oct 2011

    Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

    Source:Luigi Auriemma
    Published:23 May 2013
    4.3
    Medium

    CVE-2011-4519

    Last Modified: 31 Oct 2011

    Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

    Source:Luigi Auriemma
    Published:23 May 2013
    5
    Medium

    CVE-2011-4518

    Last Modified: 31 Oct 2011

    Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.

    Source:Luigi Auriemma
    Published:23 May 2013
    7.5
    High

    CVE-2011-4453

    Last Modified: 23 Nov 2011

    The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.

    Source:EgiX
    Published:22 Dec 2011
    6.8
    Medium

    CVE-2011-4452

    Last Modified: 18 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete operation, as demonstrated by an {{image}} action.

    Source:EgiX
    Published:5 Sept 2012
    4.3
    Medium

    CVE-2011-4451

    Last Modified: 18 Dec 2016

    libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter

    Source:EgiX
    Published:5 Sept 2012
    6.4
    Medium

    CVE-2011-4450

    Last Modified: 18 Dec 2016

    Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.

    Source:EgiX
    Published:5 Sept 2012
    6.8
    Medium

    CVE-2011-4449

    Last Modified: 18 Dec 2016

    actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.

    Source:EgiX
    Published:5 Sept 2012
    7.5
    High

    CVE-2011-4448

    Last Modified: 18 Dec 2016

    SQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL commands via the default_comment_display parameter in an update action.

    Source:EgiX
    Published:5 Sept 2012
    6.5
    Medium

    CVE-2011-4431

    Last Modified: 6 Mar 2015

    Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.

    Source:Christophe de la Fuente
    Published:10 Nov 2011
    1.2
    Low

    CVE-2011-4415

    Last Modified: 29 Mar 2017

    The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.

    Source:halfdog
    Published:2 Nov 2011
    5
    Medium

    CVE-2011-4404

    Last Modified: 21 Nov 2011

    The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

    Source:Alexey Sintsov
    Published:19 Nov 2011
    5.8
    Medium

    CVE-2011-4403

    Last Modified: 9 Apr 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.php.

    Source:DisK0nn3cT
    Published:24 Apr 2015
    7.5
    High

    CVE-2011-4367

    Last Modified: 9 Apr 2015

    Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.

    Source:Paul Nicolucci
    Published:19 Jun 2014
    5
    Medium

    CVE-2011-4362

    Last Modified: 14 May 2015

    Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.

    Source:pi3
    Published:24 Dec 2011
    7.5
    High

    CVE-2011-4342

    Last Modified: 28 Mar 2011

    PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.

    Source:Sense of Security
    Published:8 Oct 2012
    4.3
    Medium

    CVE-2011-4341

    Last Modified: 5 Mar 2015

    Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter parameter to (1) symphony/publish/comments or (2) symphony/publish/images. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks via error messages. NOTE: some of these details are obtained from third party information.

    Source:Mesut Timur
    Published:12 Feb 2012
    3.5
    Low

    CVE-2011-4340

    Last Modified: 5 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to inject arbitrary web script or HTML via (1) the profile parameter to extensions/profiledevkit/content/content.profile.php, as demonstrated via requests to (a) the default URI, (b) about/, or (c) drafts/; or (2) the filter parameter in symphony/lib/core/class.symphony.php, as demonstrated via requests to (d) symphony/publish/comments or (e) symphony/publish/images. NOTE: some of these details are obtained from third party information.

    Source:Mesut Timur
    Published:12 Feb 2012
    7.5
    High

    CVE-2011-4337

    Last Modified: 25 Nov 2011

    Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.

    Source:EgiX
    Published:29 Jan 2012
    6.1
    Medium

    CVE-2011-4336

    Last Modified: 3 Feb 2015

    Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

    Source:High-Tech Bridge SA
    Published:15 Jan 2020
    4.3
    Medium

    CVE-2011-4335

    Last Modified: 2 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.

    Source:Stefan Schurtz
    Published:28 Nov 2011