4.3
    Medium

    CVE-2010-2669

    Last Modified: 3 Aug 2014

    Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:John Leitch
    Published:8 Jul 2010
    5
    Medium

    CVE-2010-2656

    Last Modified: 6 Jul 2010

    The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.

    Source:Alexey Sintsov
    Published:7 Jul 2010
    4
    Medium

    CVE-2010-2655

    Last Modified: 6 Jul 2010

    Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.

    Source:Alexey Sintsov
    Published:7 Jul 2010
    4.3
    Medium

    CVE-2010-2654

    Last Modified: 6 Jul 2010

    Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT parameter to private/ipmi_bladestatus.php.

    Source:Alexey Sintsov
    Published:7 Jul 2010
    7.8
    High

    CVE-2010-2632

    Last Modified: 7 Oct 2017

    Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

    Source:Maksymilian Arciemowicz
    Published:19 Jan 2011
    4.3
    Medium

    CVE-2010-2631

    Last Modified: 10 Aug 2014

    LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.

    Source:Tom Lane
    Published:22 Jun 2010
    4.3
    Medium

    CVE-2010-2630

    Last Modified: 10 Aug 2014

    The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.

    Source:Tom Lane
    Published:11 Jan 2010
    6.8
    Medium

    CVE-2010-2627

    Last Modified: 8 Jul 2010

    Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.

    Source:Luigi Auriemma
    Published:2 Jul 2010
    7.5
    High

    CVE-2010-2626

    Last Modified: 31 Jul 2014

    index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.

    Source:Marshall Whittaker
    Published:2 Jul 2010
    7.5
    High

    CVE-2010-2624

    Last Modified: 3 Jul 2010

    Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.

    Source:Salvatore Fresta
    Published:2 Jul 2010
    7.5
    High

    CVE-2010-2623

    Last Modified: 30 Jun 2010

    SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.

    Source:JaMbA
    Published:2 Jul 2010
    7.5
    High

    CVE-2010-2622

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:Sid3^effects
    Published:2 Jul 2010
    5
    Medium

    CVE-2010-2621

    Last Modified: 8 Jul 2010

    The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.

    Source:Luigi Auriemma
    Published:29 Jun 2010
    9.3
    Critical

    CVE-2010-2620

    Last Modified: 7 Aug 2013

    Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.

    Source:Wireghoul
    Published:2 Jul 2010
    6.8
    Medium

    CVE-2010-2618

    Last Modified: 9 Jul 2010

    PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. NOTE: it was later reported that 2.0.1 is also affected.

    Source:v3n0m
    Published:1 Jul 2010
    4.3
    Medium

    CVE-2010-2617

    Last Modified: 30 Jul 2014

    Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.

    Source:L0rd CrusAd3r
    Published:1 Jul 2010
    7.5
    High

    CVE-2010-2616

    Last Modified: 30 Jul 2014

    SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.

    Source:L0rd CrusAd3r
    Published:1 Jul 2010
    4.3
    Medium

    CVE-2010-2615

    Last Modified: 15 Jul 2010

    Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) page_menu and (2) description parameters in an edit_page action.

    Source:10n1z3d
    Published:1 Jul 2010
    4.3
    Medium

    CVE-2010-2613

    Last Modified: 15 Dec 2016

    Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to index.php.

    Source:Sid3^effects
    Published:1 Jul 2010
    7.5
    High

    CVE-2010-2611

    Last Modified: 27 Jun 2010

    SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Source:Sid3^effects
    Published:1 Jul 2010
    7.5
    High

    CVE-2010-2610

    Last Modified: 24 Jun 2010

    Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.

    Source:Sangteamtham
    Published:1 Jul 2010
    7.5
    High

    CVE-2010-2609

    Last Modified: 22 Jun 2010

    SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Source:L0rd CrusAd3r
    Published:1 Jul 2010
    9.3
    Critical

    CVE-2010-2590

    Last Modified: 18 Dec 2012

    Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.

    Source:Metasploit
    Published:22 Dec 2010
    7.8
    High

    CVE-2010-2568

    Last Modified: 18 Jul 2010

    Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

    Source:Ivanlef0u
    Published:22 Jul 2010
    9.3
    Critical

    CVE-2010-2561

    Last Modified: 10 Aug 2010

    Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability."

    Source:Skylined
    Published:11 Aug 2010
    7.8
    High

    CVE-2010-2554

    Last Modified: 12 Nov 2016

    The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."

    Source:Cesar Cerrudo
    Published:11 Aug 2010
    9.3
    Critical

    CVE-2010-2553

    Last Modified: 26 Sept 2010

    The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression Vulnerability."

    Source:Abysssec
    Published:11 Aug 2010
    10
    Critical

    CVE-2010-2550

    Last Modified: 10 Aug 2010

    The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."

    Source:laurent gaffie
    Published:11 Aug 2010
    7.2
    High

    CVE-2010-2549

    Last Modified: 12 Nov 2010

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."

    Source:MSRC
    Published:2 Jul 2010
    4.3
    Medium

    CVE-2010-2544

    Last Modified: 1 Sept 2014

    Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

    Source:Marc Schoenefeld
    Published:9 Jul 2010
    4.3
    Medium

    CVE-2010-2543

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-4032.2.b.

    Source:Moritz Naumann
    Published:21 Nov 2009
    7.5
    High

    CVE-2010-2513

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.

    Source:ALTBTA
    Published:28 Jun 2010
    7.5
    High

    CVE-2010-2512

    Last Modified: 23 Jun 2010

    SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JaMbA
    Published:28 Jun 2010
    7.5
    High

    CVE-2010-2511

    Last Modified: 23 Jun 2010

    SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.

    Source:JaMbA
    Published:28 Jun 2010
    7.5
    High

    CVE-2010-2510

    Last Modified: 29 Jun 2010

    SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Source:Sangteamtham
    Published:28 Jun 2010
    4.3
    Medium

    CVE-2010-2509

    Last Modified: 29 Jun 2010

    Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.

    Source:Sangteamtham
    Published:28 Jun 2010
    7.5
    High

    CVE-2010-2508

    Last Modified: 24 Jun 2010

    SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Source:Sangteamtham
    Published:28 Jun 2010
    6.8
    Medium

    CVE-2010-2507

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:kaMtiEz
    Published:28 Jun 2010
    5
    Medium

    CVE-2010-2505

    Last Modified: 13 Jul 2010

    Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request.

    Source:fl0 fl0w
    Published:28 Jun 2010
    4.3
    Medium

    CVE-2010-2482

    Last Modified: 7 Aug 2010

    LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

    Source:Tomas Hoger
    Published:15 Jun 2010
    4.3
    Medium

    CVE-2010-2464

    Last Modified: 4 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.

    Source:jdc
    Published:25 Jun 2010
    4.3
    Medium

    CVE-2010-2463

    Last Modified: 28 Jul 2014

    Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

    Source:High-Tech Bridge SA
    Published:25 Jun 2010
    7.5
    High

    CVE-2010-2462

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.

    Source:L0rd CrusAd3r
    Published:25 Jun 2010
    7.5
    High

    CVE-2010-2461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.

    Source:L0rd CrusAd3r
    Published:25 Jun 2010
    7.5
    High

    CVE-2010-2460

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.

    Source:L0rd CrusAd3r
    Published:25 Jun 2010
    7.5
    High

    CVE-2010-2459

    Last Modified: 22 Jun 2010

    SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.

    Source:L0rd CrusAd3r
    Published:25 Jun 2010
    4.3
    Medium

    CVE-2010-2458

    Last Modified: 22 Jun 2010

    Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.

    Source:L0rd CrusAd3r
    Published:25 Jun 2010
    4.3
    Medium

    CVE-2010-2457

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Source:Sangteamtham
    Published:25 Jun 2010
    6.8
    Medium

    CVE-2010-2456

    Last Modified: 12 Nov 2010

    Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter ($lan_dir variable) or possibly (2) Sdb_type parameter. NOTE: this was originally reported as remote file inclusion, but this may be inaccurate.

    Source:Sn!pEr.S!Te Hacker
    Published:25 Jun 2010
    9.3
    Critical

    CVE-2010-2440

    Last Modified: 22 Jun 2010

    Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. NOTE: some of these details are obtained from third party information.

    Source:blake
    Published:24 Jun 2010