6.9
    Medium

    CVE-2010-5241

    Last Modified: 27 Aug 2010

    Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:xsploited security
    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5240

    Last Modified: 7 Sept 2010

    Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a directory that contains a .cdr, .cpt, .cmx, or .csl file. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5239

    Last Modified: 26 Aug 2010

    Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that contains a .mds file. NOTE: some of these details are obtained from third party information.

    Source:Mohamed Clay
    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5236

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working directory, as demonstrated by a directory that contains a .roxio, .c2d, or .gi file. NOTE: some of these details are obtained from third party information.

    Source:storm
    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5230

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in MicroStation 7.1 allow local users to gain privileges via a Trojan horse (1) mptools.dll, (2) baseman.dll, (3) wintab32.dll, or (4) wintab.dll file in the current working directory, as demonstrated by a directory that contains a .hln or .rdl file. NOTE: some of these details are obtained from third party information.

    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5227

    Last Modified: 24 Aug 2010

    Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .htm, .mht, .mhtml, .xht, .xhtm, or .xhtl file. NOTE: some of these details are obtained from third party information.

    Source:Nicolas Krassas
    Published:7 Sept 2012
    6.9
    Medium

    CVE-2010-5195

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9.dll file in the current working directory, as demonstrated by a directory that contains a .dmsd or .dmsm file. NOTE: some of these details are obtained from third party information.

    Source:storm
    Published:6 Sept 2012
    9.3
    Critical

    CVE-2010-5194

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0, Gold 5.5, Gold 6.0, and earlier allows remote attackers to execute arbitrary code via a long strPDFFile parameter.

    Source:bz1p
    Published:31 Aug 2012
    9.3
    Critical

    CVE-2010-5193

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0 and Gold 6.0 allows remote attackers to execute arbitrary code via a long strDelimit parameter.

    Source:Dr_IDE
    Published:31 Aug 2012
    6.8
    Medium

    CVE-2010-5099

    Last Modified: 29 Dec 2010

    The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files, as demonstrated using path traversal sequences with %00 null bytes and CVE-2010-3714 to read the TYPO3 encryption key from localconf.php.

    Source:ikki
    Published:30 May 2012
    7.5
    High

    CVE-2010-5096

    Last Modified: 3 Nov 2014

    Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.

    Source:Aung Khant
    Published:13 Aug 2012
    7.5
    High

    CVE-2010-5083

    Last Modified: 3 May 2018

    SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

    Source:ITSecTeam
    Published:14 Feb 2012
    9.3
    Critical

    CVE-2010-5081

    Last Modified: 22 Dec 2017

    Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.

    Source:Metasploit
    Published:25 Dec 2011
    2.1
    Low

    CVE-2010-5075

    Last Modified: 3 Aug 2010

    Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.

    Source:x90c
    Published:28 Dec 2014
    7.5
    High

    CVE-2010-5063

    Last Modified: 18 Feb 2014

    SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.

    Source:Darren McDonald
    Published:8 Oct 2012
    7.5
    High

    CVE-2010-5062

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:Easy Laster
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5060

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:n3w7u
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5059

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.

    Source:Dr.0rYX & Cr3W-DZ
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5058

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Andrés Gómez
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5057

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

    Source:Andrés Gómez
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5056

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.

    Source:kaMtiEz
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5055

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:NeX HaCkEr
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5053

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.

    Source:AntiSecurity
    Published:23 Nov 2011
    4.3
    Medium

    CVE-2010-5052

    Last Modified: 12 Jul 2014

    Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter.

    Source:High-Tech Bridge SA
    Published:23 Nov 2011
    4.3
    Medium

    CVE-2010-5051

    Last Modified: 12 Jul 2014

    Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web script or HTML via the content parameter in an edit action to admin/index.php.

    Source:High-Tech Bridge SA
    Published:23 Nov 2011
    4.3
    Medium

    CVE-2010-5048

    Last Modified: 19 Dec 2016

    Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.

    Source:High-Tech Bridge SA
    Published:23 Nov 2011
    7.5
    High

    CVE-2010-5047

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:R3d-D3V!L
    Published:23 Nov 2011
    4.3
    Medium

    CVE-2010-5046

    Last Modified: 30 Jun 2014

    Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter.

    Source:High-Tech Bridge SA
    Published:23 Nov 2011
    4.3
    Medium

    CVE-2010-5045

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011
    6
    Medium

    CVE-2010-5044

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. NOTE: some of these details are obtained from third party information.

    Source:d0lc3
    Published:2 Nov 2011
    6
    Medium

    CVE-2010-5043

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.

    Source:d0lc3
    Published:2 Nov 2011
    4.3
    Medium

    CVE-2010-5042

    Last Modified: 19 Dec 2016

    Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the cid[] parameter in an editItem action to administrator/index.php. NOTE: some of these details are obtained from third party information.

    Source:d0lc3
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5041

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.

    Source:AntiSecurity
    Published:2 Nov 2011
    6.8
    Medium

    CVE-2010-5040

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5039

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.

    Source:Mr.ThieF
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5037

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

    Source:Pokeng
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5036

    Last Modified: 9 Jul 2010

    SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Source:Sid3^effects
    Published:2 Nov 2011
    4.3
    Medium

    CVE-2010-5035

    Last Modified: 9 Jul 2010

    Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5034

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.

    Source:Sid3^effects
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5033

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.

    Source:Shamus
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5032

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.

    Source:Valentin Hoebel
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5029

    Last Modified: 29 Jun 2010

    SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.

    Source:High-Tech Bridge SA
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5028

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

    Source:v3n0m
    Published:2 Nov 2011
    4.3
    Medium

    CVE-2010-5027

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: some of these details are obtained from third party information.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011
    6.8
    Medium

    CVE-2010-5026

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011
    4.3
    Medium

    CVE-2010-5025

    Last Modified: 17 Jul 2014

    Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:2 Nov 2011
    6
    Medium

    CVE-2010-5024

    Last Modified: 17 Jul 2014

    SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5023

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5022

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011
    7.5
    High

    CVE-2010-5021

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.

    Source:L0rd CrusAd3r
    Published:2 Nov 2011