7.5
    High

    CVE-2010-4810

    Last Modified: 13 Nov 2017

    Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.

    Source:LoSt.HaCkEr
    Published:8 Jul 2011
    7.5
    High

    CVE-2010-4809

    Last Modified: 14 Nov 2010

    SQL injection vulnerability in index.php in DBSite 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:God_Of_Pain
    Published:8 Jul 2011
    7.5
    High

    CVE-2010-4808

    Last Modified: 13 Nov 2010

    SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:v3n0m
    Published:8 Jul 2011
    4.3
    Medium

    CVE-2010-4804

    Last Modified: 21 Dec 2016

    The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.

    Source:Thomas Cannon
    Published:9 Jun 2011
    6
    Medium

    CVE-2010-4801

    Last Modified: 11 Oct 2010

    Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.

    Source:John Leitch
    Published:27 Apr 2011
    7.5
    High

    CVE-2010-4800

    Last Modified: 11 Oct 2010

    SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Source:John Leitch
    Published:27 Apr 2011
    6.8
    Medium

    CVE-2010-4799

    Last Modified: 9 Oct 2010

    Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to pwn.php. NOTE: some of these details are obtained from third party information.

    Source:KnocKout
    Published:27 Apr 2011
    6.8
    Medium

    CVE-2010-4798

    Last Modified: 11 Oct 2010

    Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.

    Source:ZonTa
    Published:27 Apr 2011
    7.5
    High

    CVE-2010-4797

    Last Modified: 8 Oct 2010

    Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Source:KnocKout
    Published:27 Apr 2011
    7.5
    High

    CVE-2010-4795

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.

    Source:Salvatore Fresta
    Published:27 Apr 2011
    4.3
    Medium

    CVE-2010-4794

    Last Modified: 19 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a jscalendar action to index.php. NOTE: some of these details are obtained from third party information.

    Source:Salvatore Fresta
    Published:27 Apr 2011
    7.5
    High

    CVE-2010-4793

    Last Modified: 10 Oct 2010

    SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:KnocKout
    Published:27 Apr 2011
    4.3
    Medium

    CVE-2010-4792

    Last Modified: 30 Sept 2014

    Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter.

    Source:Anatolia Security
    Published:27 Apr 2011
    7.5
    High

    CVE-2010-4791

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.

    Source:Easy Laster
    Published:27 Apr 2011
    6.8
    Medium

    CVE-2010-4784

    Last Modified: 20 Oct 2014

    Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:Aliaksandr Hartsuyeu
    Published:7 Apr 2011
    2.6
    Low

    CVE-2010-4783

    Last Modified: 20 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner parameters.

    Source:Aliaksandr Hartsuyeu
    Published:7 Apr 2011
    7.5
    High

    CVE-2010-4782

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807.

    Source:ajann
    Published:7 Apr 2011
    5
    Medium

    CVE-2010-4781

    Last Modified: 1 Dec 2010

    index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.

    Source:High-Tech Bridge SA
    Published:7 Apr 2011
    7.5
    High

    CVE-2010-4780

    Last Modified: 1 Dec 2010

    SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:7 Apr 2011
    4.3
    Medium

    CVE-2010-4777

    Last Modified: 8 Dec 2014

    The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent attackers to cause a denial of service (assertion failure and application exit) via crafted input that is not properly handled when using certain regular expressions, as demonstrated by causing SpamAssassin and OCSInventory to crash.

    Source:Vladimir Perepelitsa
    Published:16 Jul 2010
    7.5
    High

    CVE-2010-4776

    Last Modified: 13 Nov 2010

    SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.

    Source:Cru3l.b0y
    Published:23 Mar 2011
    7.5
    High

    CVE-2010-4774

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.

    Source:Don Tukulesto
    Published:23 Mar 2011
    4.3
    Medium

    CVE-2010-4772

    Last Modified: 20 Nov 2010

    Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.

    Source:LordTittiS
    Published:23 Mar 2011
    7.5
    High

    CVE-2010-4771

    Last Modified: 20 Nov 2010

    SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:LordTittiS
    Published:23 Mar 2011
    7.5
    High

    CVE-2010-4770

    Last Modified: 19 Nov 2010

    SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.

    Source:JaMbA
    Published:23 Mar 2011
    7.5
    High

    CVE-2010-4769

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the task parameter to index.php.

    Source:Mask_magicianz
    Published:23 Mar 2011
    6.8
    Medium

    CVE-2010-4752

    Last Modified: 20 Sept 2010

    SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Solidmedia
    Published:1 Mar 2011
    6
    Medium

    CVE-2010-4751

    Last Modified: 20 Sept 2010

    SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the id parameter in an edituser action, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485.

    Source:Solidmedia
    Published:1 Mar 2011
    6.8
    Medium

    CVE-2010-4750

    Last Modified: 15 Dec 2010

    Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.

    Source:High-Tech Bridge SA
    Published:1 Mar 2011
    4.3
    Medium

    CVE-2010-4749

    Last Modified: 15 Dec 2010

    Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.

    Source:High-Tech Bridge SA
    Published:1 Mar 2011
    4.3
    Medium

    CVE-2010-4747

    Last Modified: 27 Oct 2014

    Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.

    Source:John Leitch
    Published:1 Mar 2011
    10
    Critical

    CVE-2010-4742

    Last Modified: 1 Apr 2017

    Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.

    Source:Metasploit
    Published:18 Feb 2011
    9.3
    Critical

    CVE-2010-4741

    Last Modified: 1 Apr 2017

    Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a session on TCP port 54321.

    Source:Metasploit
    Published:18 Feb 2011
    9.3
    Critical

    CVE-2010-4740

    Last Modified: 16 Sept 2010

    Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote attackers to execute arbitrary code via a crafted .csv file, related to a status log message.

    Source:Jeremy Brown
    Published:16 Feb 2011
    7.5
    High

    CVE-2010-4738

    Last Modified: 17 Nov 2016

    Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.

    Source:R4dc0re
    Published:16 Feb 2011
    7.5
    High

    CVE-2010-4737

    Last Modified: 5 Dec 2010

    SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter.

    Source:R4dc0re
    Published:16 Feb 2011
    7.5
    High

    CVE-2010-4736

    Last Modified: 5 Dec 2010

    SQL injection vulnerability in ECO.asp in GateSoft DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary SQL commands via the ECO_ID parameter. NOTE: some of these details are obtained from third party information.

    Source:R4dc0re
    Published:16 Feb 2011
    7.5
    High

    CVE-2010-4735

    Last Modified: 5 Dec 2010

    SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote attackers to execute arbitrary SQL commands via the d parameter.

    Source:R4dc0re
    Published:16 Feb 2011
    2.6
    Low

    CVE-2010-4734

    Last Modified: 28 Nov 2010

    Multiple cross-site scripting (XSS) vulnerabilities in the comment feature in Skeletonz CMS 1.0, when the Blog plugin is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Email parameters. NOTE: some of these details are obtained from third party information.

    Source:Jbyte
    Published:16 Feb 2011
    7.5
    High

    CVE-2010-4721

    Last Modified: 17 Dec 2010

    SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Easy Laster
    Published:1 Feb 2011
    7.5
    High

    CVE-2010-4719

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Source:Sid3^effects
    Published:1 Feb 2011
    6.5
    Medium

    CVE-2010-4717

    Last Modified: 9 Nov 2010

    Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long (1) LIST or (2) LSUB command.

    Source:Francis Provencher
    Published:31 Jan 2011
    5
    Medium

    CVE-2010-4715

    Last Modified: 15 Oct 2014

    Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Source:Francis Provencher
    Published:31 Jan 2011
    10
    Critical

    CVE-2010-4711

    Last Modified: 9 Nov 2010

    Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a large parameter in a LIST command.

    Source:Francis Provencher
    Published:31 Jan 2011
    7.6
    High

    CVE-2010-4709

    Last Modified: 25 Jan 2011

    Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.

    Source:Jeremy Brown
    Published:28 Jan 2011
    7.6
    High

    CVE-2010-4701

    Last Modified: 28 Dec 2010

    Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.

    Source:rgod
    Published:20 Jan 2011
    4.3
    Medium

    CVE-2010-4693

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.

    Source:waraxe
    Published:11 Jan 2011
    7.8
    High

    CVE-2010-4669

    Last Modified: 11 Apr 2025

    The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.

    Published:7 Jan 2011
    4.3
    Medium

    CVE-2010-4647

    Last Modified: 16 Nov 2017

    Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

    Source:Aung Khant
    Published:16 Nov 2010
    5
    Medium

    CVE-2010-4645

    Last Modified: 5 Nov 2014

    strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

    Source:Rick Regan
    Published:30 Dec 2010