7.5
    High

    CVE-2010-3485

    Last Modified: 20 Sept 2010

    SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the userhandle cookie to LightNEasy.php, a different vector than CVE-2008-6593. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Solidmedia
    Published:22 Sept 2010
    7.5
    High

    CVE-2010-3484

    Last Modified: 20 Sept 2010

    SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to LightNEasy.php, a different vector than CVE-2008-6593.

    Source:Solidmedia
    Published:22 Sept 2010
    7.5
    High

    CVE-2010-3483

    Last Modified: 20 Sept 2010

    cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. NOTE: this vulnerability can be leveraged to conduct cross-site scripting attacks, as demonstrated using the (1) title, (2) content, and (3) menutitle parameters.

    Source:Stephan Sattler
    Published:22 Sept 2010
    6.5
    Medium

    CVE-2010-3482

    Last Modified: 20 Sept 2010

    Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. NOTE: this can be leveraged with CVE-2010-3483 to conduct attacks without authentication.

    Source:Stephan Sattler
    Published:22 Sept 2010
    6.8
    Medium

    CVE-2010-3481

    Last Modified: 15 Sept 2010

    Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.

    Source:Abysssec
    Published:22 Sept 2010
    6.8
    Medium

    CVE-2010-3480

    Last Modified: 15 Sept 2010

    Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:Abysssec
    Published:22 Sept 2010
    7.5
    High

    CVE-2010-3479

    Last Modified: 19 Sept 2010

    SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:BrOx-Dz
    Published:22 Sept 2010
    5
    Medium

    CVE-2010-3468

    Last Modified: 26 Sept 2010

    Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.

    Source:mr_me
    Published:29 Sept 2010
    6.8
    Medium

    CVE-2010-3467

    Last Modified: 25 Sept 2010

    SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.

    Source:_mRkZ_
    Published:17 Sept 2010
    4.3
    Medium

    CVE-2010-3462

    Last Modified: 13 Sept 2014

    Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the confirm parameter. NOTE: some of these details are obtained from third party information.

    Source:John Leitch
    Published:17 Sept 2010
    7.5
    High

    CVE-2010-3461

    Last Modified: 15 Sept 2010

    SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394.

    Source:vYc0d
    Published:17 Sept 2010
    5
    Medium

    CVE-2010-3460

    Last Modified: 11 Sept 2014

    Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.

    Source:Bogdan Calin
    Published:17 Sept 2010
    7.5
    High

    CVE-2010-3458

    Last Modified: 10 Sept 2010

    SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

    Source:JosS
    Published:17 Sept 2010
    4.3
    Medium

    CVE-2010-3457

    Last Modified: 10 Sept 2010

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-default-theme/ or (2) send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

    Source:JosS
    Published:17 Sept 2010
    5
    Medium

    CVE-2010-3456

    Last Modified: 10 Sept 2010

    Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Kazza
    Published:17 Sept 2010
    6.8
    Medium

    CVE-2010-3449

    Last Modified: 9 Dec 2010

    Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.

    Source:Anatolia Security
    Published:6 Dec 2010
    6.6
    Medium

    CVE-2010-3437

    Last Modified: 6 Nov 2010

    Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.

    Source:Jon Oberheide
    Published:28 Sept 2010
    7.5
    High

    CVE-2010-3428

    Last Modified: 13 Sept 2010

    SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.

    Source:ViciOuS
    Published:16 Sept 2010
    7.5
    High

    CVE-2010-3426

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:16 Sept 2010
    4.3
    Medium

    CVE-2010-3425

    Last Modified: 25 Oct 2010

    Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:sqlhacker
    Published:16 Sept 2010
    7.5
    High

    CVE-2010-3422

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Source:**RoAd_KiLlEr**
    Published:16 Sept 2010
    7.5
    High

    CVE-2010-3419

    Last Modified: 13 Sept 2010

    Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.

    Source:LoSt.HaCkEr
    Published:16 Sept 2010
    9.3
    Critical

    CVE-2010-3407

    Last Modified: 17 Nov 2016

    Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

    Source:A. Plaskett
    Published:16 Sept 2010
    7.5
    High

    CVE-2010-3404

    Last Modified: 12 Sept 2010

    Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.

    Source:Abysssec
    Published:16 Sept 2010
    7.2
    High

    CVE-2010-3396

    Last Modified: 2 Oct 2010

    Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004. NOTE: some of these details are obtained from third party information.

    Source:Lufeng Li
    Published:15 Sept 2010
    7.2
    High

    CVE-2010-3338

    Last Modified: 27 Oct 2016

    The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.

    Source:Metasploit
    Published:16 Dec 2010
    7.8
    High

    CVE-2010-3333

    Last Modified: 16 Mar 2012

    Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

    Source:b33f & g11tch
    Published:10 Nov 2010
    6.4
    Medium

    CVE-2010-3332

    Last Modified: 6 Oct 2010

    Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."

    Source:Giorgio Fedon
    Published:22 Sept 2010
    9.3
    Critical

    CVE-2010-3329

    Last Modified: 16 Oct 2017

    mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."

    Source:Core Security
    Published:13 Oct 2010
    4.3
    Medium

    CVE-2010-3325

    Last Modified: 9 Sept 2014

    Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."

    Source:Chris Evans
    Published:13 Oct 2010
    4.3
    Medium

    CVE-2010-3324

    Last Modified: 30 Aug 2014

    The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.

    Source:Mario Heiderich
    Published:17 Sept 2010
    4.3
    Medium

    CVE-2010-3314

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Source:Nahuel Grisolia
    Published:22 Sept 2010
    7.5
    High

    CVE-2010-3313

    Last Modified: 11 Apr 2025

    phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) aspell_path or (2) spellchecker_lang parameters.

    Source:Nahuel Grisolia
    Published:22 Sept 2010
    7.5
    High

    CVE-2010-3307

    Last Modified: 9 Oct 2010

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.

    Source:Dr.$audi
    Published:5 Oct 2010
    5
    Medium

    CVE-2010-3306

    Last Modified: 7 Sept 2010

    Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.

    Source:Rew
    Published:24 Sept 2010
    7.2
    High

    CVE-2010-3301

    Last Modified: 28 Nov 2016

    The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.

    Source:ben hawkes
    Published:15 Sept 2010
    9.3
    Critical

    CVE-2010-3275

    Last Modified: 15 Nov 2016

    libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability."

    Source:Metasploit
    Published:28 Mar 2011
    4.3
    Medium

    CVE-2010-3274

    Last Modified: 23 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.

    Source:Core Security
    Published:17 Feb 2011
    4.3
    Medium

    CVE-2010-3272

    Last Modified: 23 Nov 2014

    accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.

    Source:Core Security
    Published:17 Feb 2011
    6.8
    Medium

    CVE-2010-3271

    Last Modified: 15 Jun 2011

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.

    Source:Core Security
    Published:18 Jul 2011
    6.5
    Medium

    CVE-2010-3267

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.

    Source:Core Security
    Published:2 Dec 2010
    3.5
    Low

    CVE-2010-3266

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.

    Source:Core Security
    Published:2 Dec 2010
    9.3
    Critical

    CVE-2010-3227

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."

    Source:fl0 fl0w
    Published:26 Oct 2010
    6.8
    Medium

    CVE-2010-3213

    Last Modified: 12 Jul 2010

    Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.

    Source:Rosario Valotta
    Published:7 Sept 2010
    7.5
    High

    CVE-2010-3212

    Last Modified: 1 Sept 2010

    SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.

    Source:Sweet
    Published:3 Sept 2010
    7.5
    High

    CVE-2010-3211

    Last Modified: 19 Dec 2016

    Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid parameter or (2) the catid parameter in a lists action.

    Source:Chip d3 bi0s
    Published:3 Sept 2010
    7.5
    High

    CVE-2010-3210

    Last Modified: 29 Aug 2010

    Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) checkout2-CYM.php, (2) checkout2-EN.php, (3) checkout2-FR.php, (4) cat-FR.php, (5) cat-EN.php, (6) cat-CYM.php, (7) checkout1-CYM.php, (8) checkout1-EN.php, (9) checkout1-FR.php, (10) prod-CYM.php, (11) prod-EN.php, and (12) prod-FR.php in inc/.

    Source:JosS
    Published:3 Sept 2010
    7.5
    High

    CVE-2010-3209

    Last Modified: 30 Aug 2010

    Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code via a URL in the includeFile parameter to (1) Config/Container.php and (2) HTML/QuickForm.php in fog/lib/pear/, the (3) driverpath parameter to fog/lib/pear/DB/NestedSet.php, and the (4) path parameter to fog/lib/pear/DB/NestedSet/Output.php.

    Source:FoX HaCkEr
    Published:3 Sept 2010
    6.8
    Medium

    CVE-2010-3207

    Last Modified: 4 Sept 2010

    SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the album_id parameter. NOTE: some of these details are obtained from third party information.

    Source:Valentin
    Published:3 Sept 2010
    7.5
    High

    CVE-2010-3206

    Last Modified: 6 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to modules/guestbook/blocks/control.block.php, (2) main_module parameter to index.php, and (3) getFile parameter to includes/general.functions.php.

    Source:LoSt.HaCkEr
    Published:3 Sept 2010