4.3
    Medium

    CVE-2010-4895

    Last Modified: 5 Sept 2010

    Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information.

    Source:AmnPardaz
    Published:8 Oct 2011
    7.5
    High

    CVE-2010-4894

    Last Modified: 5 Sept 2010

    SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.

    Source:AmnPardaz
    Published:8 Oct 2011
    4.3
    Medium

    CVE-2010-4893

    Last Modified: 9 Sept 2010

    Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.

    Source:Abysssec
    Published:8 Oct 2011
    7.5
    High

    CVE-2010-4884

    Last Modified: 11 Oct 2010

    PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.

    Source:bd0rk
    Published:7 Oct 2011
    2.6
    Low

    CVE-2010-4883

    Last Modified: 26 Sept 2014

    Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.

    Source:John Leitch
    Published:7 Oct 2011
    4.3
    Medium

    CVE-2010-4882

    Last Modified: 5 Sept 2014

    Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web script or HTML via the sitetitle parameter.

    Source:High-Tech Bridge SA
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4879

    Last Modified: 1 Sept 2010

    PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the input_file parameter.

    Source:Andre_Corleone
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4878

    Last Modified: 11 Oct 2010

    PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the script_pfad parameter.

    Source:bd0rk
    Published:7 Oct 2011
    4.3
    Medium

    CVE-2010-4877

    Last Modified: 8 Sept 2014

    Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Source:anT!-Tr0J4n
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4876

    Last Modified: 2 Sept 2010

    SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.

    Source:Ptrace Security
    Published:7 Oct 2011
    4.3
    Medium

    CVE-2010-4875

    Last Modified: 15 Oct 2014

    Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter.

    Source:John Leitch
    Published:7 Oct 2011
    4.3
    Medium

    CVE-2010-4874

    Last Modified: 28 Oct 2010

    Multiple cross-site scripting (XSS) vulnerabilities in users.php in NinkoBB 1.3 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) msn, or (4) aim parameter.

    Source:High-Tech Bridge SA
    Published:7 Oct 2011
    4.3
    Medium

    CVE-2010-4873

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:John Leitch
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4872

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the specific parameter.

    Source:Daikin
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4870

    Last Modified: 27 Dec 2010

    SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

    Source:High-Tech Bridge SA
    Published:7 Oct 2011
    7.5
    High

    CVE-2010-4869

    Last Modified: 30 Mar 2017

    SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.

    Source:ZonTa
    Published:5 Oct 2011
    4.3
    Medium

    CVE-2010-4868

    Last Modified: 6 Oct 2014

    Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.

    Source:MustLive
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4867

    Last Modified: 6 Oct 2014

    Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.

    Source:MustLive
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4866

    Last Modified: 3 Oct 2010

    SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands via the forumID parameter.

    Source:Shamus
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4865

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.

    Source:Salvatore Fresta
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4864

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.

    Source:FL0RiX
    Published:5 Oct 2011
    4.3
    Medium

    CVE-2010-4863

    Last Modified: 11 Nov 2016

    Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.

    Source:High-Tech Bridge SA
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4862

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

    Source:Easy Laster
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4861

    Last Modified: 31 Oct 2010

    SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:silent vapor
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4860

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:h4ck3r
    Published:5 Oct 2011
    5
    Medium

    CVE-2010-4858

    Last Modified: 4 Oct 2010

    Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter.

    Source:blake
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4857

    Last Modified: 5 Oct 2010

    SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

    Source:Shamus
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4856

    Last Modified: 8 Oct 2010

    SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

    Source:ZoRLu
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4855

    Last Modified: 7 Oct 2010

    SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.

    Source:KnocKout
    Published:5 Oct 2011
    7.5
    High

    CVE-2010-4853

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.

    Source:FL0RiX
    Published:5 Oct 2011
    4.3
    Medium

    CVE-2010-4852

    Last Modified: 1 Dec 2010

    Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.

    Source:High-Tech Bridge SA
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4851

    Last Modified: 1 Dec 2010

    Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php.

    Source:High-Tech Bridge SA
    Published:27 Sept 2011
    4.3
    Medium

    CVE-2010-4850

    Last Modified: 29 Nov 2010

    Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.

    Source:High-Tech Bridge SA
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4849

    Last Modified: 1 Dec 2010

    SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

    Source:Dr.0rYX & Cr3W-DZ
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4847

    Last Modified: 17 Dec 2010

    SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Source:Easy Laster
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4846

    Last Modified: 18 Dec 2010

    SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Source:DeadLy DeMon
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4845

    Last Modified: 18 Dec 2010

    Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

    Source:DeadLy DeMon
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4844

    Last Modified: 17 Dec 2010

    SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Source:Easy Laster
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4843

    Last Modified: 20 Dec 2010

    SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

    Source:R4dc0re
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4842

    Last Modified: 18 Dec 2010

    SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.

    Source:DeadLy DeMon
    Published:27 Sept 2011
    7.5
    High

    CVE-2010-4839

    Last Modified: 13 Nov 2010

    SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

    Source:k3m4n9i
    Published:13 Sept 2011
    6
    Medium

    CVE-2010-4838

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.

    Source:Valentin
    Published:13 Sept 2011
    4.3
    Medium

    CVE-2010-4837

    Last Modified: 19 Dec 2016

    Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.

    Source:Valentin
    Published:13 Sept 2011
    4.3
    Medium

    CVE-2010-4836

    Last Modified: 17 Oct 2014

    Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter.

    Source:MustLive
    Published:13 Sept 2011
    4
    Medium

    CVE-2010-4835

    Last Modified: 19 Dec 2010

    Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.

    Source:Valentin
    Published:13 Sept 2011
    6.5
    Medium

    CVE-2010-4834

    Last Modified: 19 Dec 2010

    Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.

    Source:Valentin
    Published:13 Sept 2011
    7.5
    High

    CVE-2010-4830

    Last Modified: 4 Dec 2010

    SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows remote attackers to execute arbitrary SQL commands via the z_Residency parameter.

    Source:R4dc0re
    Published:24 Aug 2011
    7.5
    High

    CVE-2010-4829

    Last Modified: 4 Dec 2010

    SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:R4dc0re
    Published:24 Aug 2011
    4.3
    Medium

    CVE-2010-4821

    Last Modified: 27 Sept 2016

    Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Source:Yam Mesicka
    Published:22 Oct 2012
    7.5
    High

    CVE-2010-4814

    Last Modified: 14 Nov 2010

    SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:v3n0m
    Published:8 Jul 2011