4.3
    Medium

    CVE-2010-2846

    Last Modified: 15 Dec 2016

    Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.

    Source:Salvatore Fresta
    Published:23 Jul 2010
    7.5
    High

    CVE-2010-2845

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category action to index.php.

    Source:RoAd_KiLlEr
    Published:23 Jul 2010
    4.3
    Medium

    CVE-2010-2844

    Last Modified: 4 Aug 2014

    Cross-site scripting (XSS) vulnerability in news_show.php in Newanz NewsOffice 2.0.18 allows remote attackers to inject arbitrary web script or HTML via the n-cat parameter.

    Source:John Leitch
    Published:23 Jul 2010
    6.8
    Medium

    CVE-2010-2809

    Last Modified: 27 Aug 2014

    The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

    Source:Chuzz
    Published:19 Aug 2010
    6.5
    Medium

    CVE-2010-2785

    Last Modified: 21 Aug 2014

    The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated users to execute arbitrary CTCP commands via vectors involving \r and \40 sequences, a different vulnerability than CVE-2010-2451 and CVE-2010-2452.

    Source:unic0rn
    Published:2 Aug 2010
    Unknown

    CVE-2010-2782

    https://www.exploit-db.com/exploits/14367

    9
    Critical

    CVE-2010-2777

    Last Modified: 5 Aug 2010

    Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.

    Source:Francis Provencher
    Published:28 Jan 2011
    9.3
    Critical

    CVE-2010-2752

    Last Modified: 25 Sept 2010

    Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

    Source:Abysssec
    Published:20 Jul 2010
    7.6
    High

    CVE-2010-2746

    Last Modified: 10 Jan 2011

    Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."

    Source:Nephi Johnson
    Published:13 Oct 2010
    9.3
    Critical

    CVE-2010-2745

    Last Modified: 13 Oct 2017

    Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka "Windows Media Player Memory Corruption Vulnerability."

    Source:Skylined
    Published:13 Oct 2010
    7.2
    High

    CVE-2010-2744

    Last Modified: 2 Jan 2011

    The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."

    Source:Tarjei Mandt
    Published:13 Oct 2010
    7.2
    High

    CVE-2010-2743

    Last Modified: 13 Jan 2011

    The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.

    Source:Ruben Santamarta
    Published:20 Jan 2011
    7.2
    High

    CVE-2010-2739

    Last Modified: 15 Nov 2017

    Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.

    Source:Arkon
    Published:7 Sept 2010
    9.3
    Critical

    CVE-2010-2738

    Last Modified: 30 Sept 2010

    The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."

    Source:Abysssec
    Published:15 Sept 2010
    6.8
    Medium

    CVE-2010-2731

    Last Modified: 3 Jul 2010

    Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory Authentication Bypass Vulnerability."

    Source:Soroush Dalili
    Published:15 Sept 2010
    9.3
    Critical

    CVE-2010-2729

    Last Modified: 7 Mar 2011

    The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."

    Source:Metasploit
    Published:15 Sept 2010
    7.5
    High

    CVE-2010-2721

    Last Modified: 6 Jul 2010

    SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary SQL commands via the artist_id parameter in an addalbum action.

    Source:Sid3^effects
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2720

    Last Modified: 4 Jul 2010

    SQL injection vulnerability in list.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Source:CoBRa_21
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2719

    Last Modified: 4 Jul 2010

    SQL injection vulnerability in show.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Shafiq-Ur-Rehman
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2716

    Last Modified: 6 Jul 2010

    Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.

    Source:S.W.T
    Published:13 Jul 2010
    4.3
    Medium

    CVE-2010-2715

    Last Modified: 4 Jul 2010

    Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Source:L0rd CrusAd3r
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2714

    Last Modified: 4 Jul 2010

    SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL commands via the album parameter.

    Source:L0rd CrusAd3r
    Published:13 Jul 2010
    9.3
    Critical

    CVE-2010-2709

    Last Modified: 23 Mar 2011

    Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.

    Source:Metasploit
    Published:5 Aug 2010
    10
    Critical

    CVE-2010-2703

    Last Modified: 6 Sept 2010

    Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

    Source:Abysssec
    Published:27 Jul 2010
    9.3
    Critical

    CVE-2010-2701

    Last Modified: 8 Jul 2010

    Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.

    Source:blake
    Published:12 Jul 2010
    4.3
    Medium

    CVE-2010-2700

    Last Modified: 10 Jul 2010

    Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:L0rd CrusAd3r
    Published:12 Jul 2010
    7.5
    High

    CVE-2010-2699

    Last Modified: 10 Jul 2010

    SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:L0rd CrusAd3r
    Published:12 Jul 2010
    3.5
    Low

    CVE-2010-2698

    Last Modified: 7 Jul 2010

    Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Sid3^effects
    Published:12 Jul 2010
    3.5
    Low

    CVE-2010-2697

    Last Modified: 7 Jul 2010

    Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:12 Jul 2010
    7.5
    High

    CVE-2010-2696

    Last Modified: 7 Jul 2010

    SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter.

    Source:Sid3^effects
    Published:12 Jul 2010
    7.5
    High

    CVE-2010-2694

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.

    Source:v3n0m
    Published:12 Jul 2010
    7.2
    High

    CVE-2010-2693

    Last Modified: 19 Aug 2010

    FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.

    Source:kingcope
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2691

    Last Modified: 25 Jun 2010

    Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid parameter to products/products.php, and (3) designid parameter to designview.php.

    Source:Sangteamtham
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2690

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php.

    Source:v3n0m
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2689

    Last Modified: 29 Jun 2010

    SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL commands via the cf_id parameter.

    Source:Dr.0rYX & Cr3W-DZ
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2688

    Last Modified: 22 Jun 2010

    SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:Sangteamtham
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2687

    Last Modified: 23 Jun 2010

    SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter.

    Source:CoBRa_21
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2685

    Last Modified: 28 Jun 2010

    siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct request.

    Source:Tr0y-x
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2684

    Last Modified: 28 Jun 2010

    SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Tr0y-x
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2683

    Last Modified: 29 Jun 2010

    SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter.

    Source:v3n0m
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2682

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:MISTERFRIBO
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2681

    Last Modified: 20 Dec 2016

    PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to index.php.

    Source:Li0n-PaL
    Published:9 Jul 2010
    6.8
    Medium

    CVE-2010-2680

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.

    Source:Sid3^effects
    Published:9 Jul 2010
    7.5
    High

    CVE-2010-2679

    Last Modified: 19 Jun 2014

    SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Source:Pouya Daneshmand
    Published:8 Jul 2010
    5.1
    Medium

    CVE-2010-2677

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. NOTE: some of these details are obtained from third party information.

    Source:ITSecTeam
    Published:8 Jul 2010
    5
    Medium

    CVE-2010-2676

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.

    Source:ITSecTeam
    Published:8 Jul 2010
    4.3
    Medium

    CVE-2010-2675

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an articolo action.

    Source:d3v1l
    Published:8 Jul 2010
    7.5
    High

    CVE-2010-2674

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action.

    Source:d3v1l
    Published:8 Jul 2010
    7.5
    High

    CVE-2010-2673

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Valentin
    Published:8 Jul 2010
    7.5
    High

    CVE-2010-2670

    Last Modified: 5 Jul 2010

    SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Sid3^effects
    Published:8 Jul 2010